Live data from Hacker News

Drastic increase in Tor clients from Germany

metrics.torproject.org

201–210 of 262 posts

Re: Drastic increase in Tor clients from Germany

#201
post #187

Earlier quoted context omitted.

Why would it be so localized to one country? Does Germany have a unique enemy compared to other NATO countries?

My guess is that a certain router is getting infected with a botnet because ISPs usually hand out the same router to their customers. And ISPs are usually limited to a single country.

> My guess is that a certain router is getting infected with a botnet because ISPs usually hand out the same router to their customers.

This seems trivial to figure out with an analysis of the connecting IPs - which is absent on TOR's report page.

I'm also a bit confused why no one here on HN has asked about the connecting IP data (at this writing). Are these commercial IPs, dynamic (biz/residential) IPs or a mix? If they're mostly dynamic IPs, are they from more than one ISP?

TOR has country of origin data so it seems reasonable they'd also have network of origin.

All that said, I don't precisely know how TOR determines country of origin. Entry node data would seem to be the likely source. However I've long assumed that entry nodes are public supplied, like Relay and Exit nodes. Within that assumption it isn't clear to me how that data would flow to TOR - while maintaining anonymization of traffic.

Re: Drastic increase in Tor clients from Germany

#202
post #174
post #49

Earlier quoted context omitted.

I constantly use tor as a way to get a third view when debugging connection issues for customers and malware infected websites. If you ever experience the issue of a customer saying they can't connect, but when you test it it works perfectly fine, tor is great to verify if the issue might effect more customers. As a side effect of it being ipv4 only, you can also test issues when one protocol work but not the other (…

Tor hasn't been IPv4-only since a long time

True, but most exit nodes are IPv4-only, so in practice it works.

Re: Drastic increase in Tor clients from Germany

#203
post #192
post #187

Earlier quoted context omitted.

My guess is that a certain router is getting infected with a botnet because ISPs usually hand out the same router to their customers. And ISPs are usually limited to a single country.

That would be an explanation and probably by okhams razor be more likely. But wouldn't that ISP notice the difference in traffic patterns drastically and react? It is just unlikely (but far from impossible) that this is something 'normal' happening. My fear would be that someone still is trying to gather a critical mass of nodes to contact controll servers via TOR to cause mass havoc in a single country from within a…

I can't speak to German ISPs or anyone outside of these USA. But I believe that ISPs are absolutely the weakest link when it comes to malicious botnets and other types of widespread network-based compromises.

ISPs certainly have the tooling and the positioning to be able to detect C&C channels, outgoing DDOS attacks, and compromised customer premises equipment. But do they? And if they do detect any of it, do they take action? When is the last time you heard about an ISP disconnecting a paying customer because of the customer's compromised device(s)? When is the last time you even heard of an ISP notifying a customer about such a thing?

Two months ago, my router was compromised and joined to some sort of botnet in the capacity of a DNS resolver. I would never have been able to detect such WAN-side traffic if I hadn't had a special setup on my part. My ISP was the first to hear when I'd detected it, and I sincerely doubt that they receive many such reports, especially with logs as evidence.

Can you imagine receiving a phone call, "Hello, this is your ISP! You're pwned! Please follow through these remediation steps as I prompt you: ..." You'd undoubtedly think it was a phishing scam. Because ISPs just don't seem to care about abuse.

They will send you copyright strikes and prosecute you for BitTorrent, but it does't seem like they'd lift a finger to prevent the next big DDOS or spam factory originating from their own customers.

Re: Drastic increase in Tor clients from Germany

#206
post #114

From an average of significantly below 500k to almost 2.5M users. This drives up the global number of connecting users from approx. 3M to almost 5M. Hard to imagine that so many people in Germany suddenly switched to TOR, especially since there has not been any significant event lately that may have triggered such a decision (afaik)? My personal experience with TOR (as an administrator of various websites and service…

The interesting question is if there is a bot net spreading in Germany since the 17th of June. What would be the likelihood of that going undetected. If you like conspiracy theory, the rise in one country could point to state actors.

> The interesting question is if there is a bot net spreading in Germany since the 17th of June.

A minor addendum: Looking at the csv file, it looks to me like traffic began drifting above the mean about June 6. From there I see a ramp-up, growing at an increasing rate.

Re: Drastic increase in Tor clients from Germany

#207
post #18

Earlier quoted context omitted.

I use tor for exploring topics that I don't want to tie to my regular profile (ranging from professional software development, through health care issues, but also hobbies, fiction and nsfw content). Having these browsing in a separate profile and also IP address makes it much more relaxed to look for interesting stuff on the internet. (I am not really fond of advertisement that tries to sell me whatever I've visited…

Well, I’ve always tried to make my service available through Tor, but now that I faced an attack of 20,000 RPS distributed over all the exit nodes of the Tor network making requests to a computationally expensive (and non-cacheable) endpoint, and came out with 6x the hosting bill I usually get, I decided to block the entire network. Maybe there’s an alternative reality where people do the right thing, and in that wor…

Shouldn't you protect that endpoint, regardless of the traffic coming from tor or not? It is really cheap to get traffic through domestic VPN proxies, so a dedicated attacker will get to it anyway...

Re: Drastic increase in Tor clients from Germany

#208
post #18

Earlier quoted context omitted.

I use tor for exploring topics that I don't want to tie to my regular profile (ranging from professional software development, through health care issues, but also hobbies, fiction and nsfw content). Having these browsing in a separate profile and also IP address makes it much more relaxed to look for interesting stuff on the internet. (I am not really fond of advertisement that tries to sell me whatever I've visited…

Whenever I read something like this I look my access and sshd logs for abuse IPs and check if they are Tor exit nodes. The Tor traffic is always negligible like 100 failed ssh logins out of 170k are from Tor exit nodes. Or 670 out of 400k for my nginx access.log. Am I unique and everyone else sees vastly different numbers where blocking Tor exits makes a significant difference in the abuse they get?

I don't really care if somebody blocks a random port of sshd. I just don't understand why people are eager to block public https traffic, which is exposed to the public internet anyway.

Re: Drastic increase in Tor clients from Germany

#209
post #146

Earlier quoted context omitted.

EU? Basically researchers tries to get PII from people connected to Tor without consent of these people.

That's an interesting argument. Not sure it would hold up. I don't think an IP alone counts as PII, since the ISP would have to be queried to actually get any contact info.

IP addresses are PII under GDPR.

Re: Drastic increase in Tor clients from Germany

#210
post #114

From an average of significantly below 500k to almost 2.5M users. This drives up the global number of connecting users from approx. 3M to almost 5M. Hard to imagine that so many people in Germany suddenly switched to TOR, especially since there has not been any significant event lately that may have triggered such a decision (afaik)? My personal experience with TOR (as an administrator of various websites and service…

The interesting question is if there is a bot net spreading in Germany since the 17th of June. What would be the likelihood of that going undetected. If you like conspiracy theory, the rise in one country could point to state actors.

Off the top of my head - Germany hosts a disproportionate amount of sensitive data because it's the location of choice for cloud providers storing things for EU member countries. They have lots of fiber, lots of ISPs, plenty of datacenter space, a stable government, and data security laws that meet or exceed everyone else in the EU.
Post reply on HN