8 ms·
From an average of significantly below 500k to almost 2.5M users. This drives up the global number of connecting users from approx. 3M to almost 5M. Hard to im
by curiousfab 3y ago
From an average of significantly below 500k to almost 2.5M users.
This drives up the global number of connecting users from approx. 3M to almost 5M.
Hard to imagine that so many people in Germany suddenly switched to TOR, especially since there has not been any significant event lately that may have triggered such a decision (afaik)?
My personal experience with TOR (as an administrator of various websites and services) is that it is a major source of unwanted/malicious traffic (spam, etc.) and most of it is automated. The big increase is probably not users but bots?
- mistrial9 3y agodo you believe these numbers?
- deleted 3y ago[deleted]
- j16sdiz 3y agoIt would be much helpful if you could provide one or two reasons why the number could be wrong.... or maybe make some comments on the methodology, etc.. Just question about the accuracy without any context or reasons are not contributing to the argument.
- deleted 3y ago[deleted]
- riedel 3y agoThe interesting question is if there is a bot net spreading in Germany since the 17th of June. What would be the likelihood of that going undetected. If you like conspiracy theory, the rise in one country could point to state actors.
- ballenf 3y agoWhy would it be so localized to one country? Does Germany have a unique enemy compared to other NATO countries?
- mantas 3y agoMaybe German state itself is the actor.
- hedora 3y agoWhat state actor doesn’t understand statistical deanoymization attacks against tor? (e.g., if you single-handedly double the network traffic, then an outside observer can figure out what ingress/egress traffic is yours)
- mantas 3y agoWhy pay attention to this if you can simply blame another state actor? And German federal government have a history for covert shitposting.
- throwaway2037 3y agoAnd German federal government have a history for covert shitposting. Wow, I never heard this before. Can you provide some examples famous examples?
- mantas 3y agoI remember there was a series of articles several years ago that German intelligence officers generated a lot activity in far-right websites. To the point that frequently it was mostly undercover „extremists“ discussing between themselves. The closest article I can quickly find is about Germany intelligence informants doing the same in meatspace though. > There was a "risk that sources of the intelligence service (Office for the Protection of the Constitution) could goad each other on to undertake bigger actions;" in other words, the system threatened to create an "incendiary effect." https://www.spiegel.de/international/germany/german-police-document-says-informants-fuelled-far-right-extremism-a-865461.html https://www.spiegel.de/international/germany/german-police-d...
- throwaway290 3y agoNote that the growth is not just in Germany. Ireland, Sweden, Switzerland also show jumps (however in absolute terms they are still much smaller). I would not rule out it's people or bots connecting from third country/countries through VPNs based in Europe... for whatever reason.
- doubleorseven 3y agoVPSs in germany are much cheaper. But I'm guessing this increase is paid with crypto or debit cards so pin pointing it to a specific provider like hetzner is hard
- rurban 3y agoHetzner used by criminals would be my guess.
- ncr100 3y agoIs it a bug in a client that accidentally spawns sub-clients?
- theonlybutlet 3y agoAny UX changes to something like Brave browser perhaps? Making it easier to use tor mode. Although this is a big jump.
- supriyo-biswas 3y agoI faced a recent distributed attack averaging 20,000 RPS[1] around the same time which makes me think that there might be a bot. I wonder if there’s a network of website operators similar to NANOG or the RIPE NCC mailing lists where I could compare my own experience with those of other operators. [1] https://news.ycombinator.com/item?id=36561930 https://news.ycombinator.com/item?id=36561930
- lionkor 3y agoIf there isn't, lets make one. We could self host it, lock it down to invite-only.
- hartator 3y agoWhy not CAPTCHA protect these pages instead of blocking tor? Same attack can go through regular web.
- supriyo-biswas 3y agoI already have per-IP ratelimiting, and I'm against using captchas have bad UX (including the much-hailed Turnstile). I'll probably migrate to some proof-of-work based schemes and some algorithms to detect anomalous requests, but it would require some engineering work on my part (for a free website FWIW), and the quickest way to mitigate it would be to block Tor.
- thissitesucks__ 3y ago[dead]
- hedora 3y agoIP blocking blocks most of the people on our local ISP. They are small, and use CGNAT, so one owned windows machine across town breaks sites like yours for everyone, and the root cause is extremely difficult to debug for end users. As much as I deeply, deeply dislike captchas, ip blocking is far worse.
- aaron695 3y ago[dead]