Live data from Hacker News

Drastic increase in Tor clients from Germany

metrics.torproject.org

211–220 of 262 posts

Re: Drastic increase in Tor clients from Germany

#211

Earlier quoted context omitted.

That's an interesting argument. Not sure it would hold up. I don't think an IP alone counts as PII, since the ISP would have to be queried to actually get any contact info.

IP addresses are PII under GDPR.

Not by themselves, surely?

Even so, GDPR has research exemptions which would protect the academics doing research in the example being discussed.

Re: Drastic increase in Tor clients from Germany

#212

Clicking around and looking at the chart for random other countries shows a spike for Sweden too, whereas Finland has a different but interesting pattern all of its own.

Wonder if the fact that they’re related to NATO, who is at war, have anything to do with it.

Nato is not at war.

Re: Drastic increase in Tor clients from Germany

#213

Is someone trying to compromise the Tor network? I read that Tor needs a certain percentage of non-malicious nodes to function, though I am not sure if that is applicable clients.

I think you're thinking of blockchain

No, the problem also applies to Tor. If a malicious actor controls large parts of the network, there is a high probability that the attacker controls your entire circuit or at least your entry and exit node.

In the latter case, you can do timing attacks to determine which traffic on the exit node belongs to whom on the entry node.

Re: Drastic increase in Tor clients from Germany

#214
post #192

Earlier quoted context omitted.

That would be an explanation and probably by okhams razor be more likely. But wouldn't that ISP notice the difference in traffic patterns drastically and react? It is just unlikely (but far from impossible) that this is something 'normal' happening. My fear would be that someone still is trying to gather a critical mass of nodes to contact controll servers via TOR to cause mass havoc in a single country from within a…

I can't speak to German ISPs or anyone outside of these USA. But I believe that ISPs are absolutely the weakest link when it comes to malicious botnets and other types of widespread network-based compromises. ISPs certainly have the tooling and the positioning to be able to detect C&C channels, outgoing DDOS attacks, and compromised customer premises equipment. But do they? And if they do detect any of it, do they ta…

My ISP actually sent me an email that said that one of my devices have an open TCP 445 port and advised me to fix it. Apparently Windows opens it by default and it can be exploited by some malware.

But I've never received a threatening letter about piracy. ISPs in my country simply don't send those.

Re: Drastic increase in Tor clients from Germany

#215
post #192

Earlier quoted context omitted.

That would be an explanation and probably by okhams razor be more likely. But wouldn't that ISP notice the difference in traffic patterns drastically and react? It is just unlikely (but far from impossible) that this is something 'normal' happening. My fear would be that someone still is trying to gather a critical mass of nodes to contact controll servers via TOR to cause mass havoc in a single country from within a…

I can't speak to German ISPs or anyone outside of these USA. But I believe that ISPs are absolutely the weakest link when it comes to malicious botnets and other types of widespread network-based compromises. ISPs certainly have the tooling and the positioning to be able to detect C&C channels, outgoing DDOS attacks, and compromised customer premises equipment. But do they? And if they do detect any of it, do they ta…

In Germany, I doubt they have the tooling or staff anymore. For almost a decade we've been in a race to the bottom regarding pricing and as a result, service quality. I wouldn't be surprised if critical parts of the infrastructure are maintained by outsourced jobs from half around the world.

The only somewhat professional player is the Deutsche Telekom, which was kinda the Bell of Germany and got privatized in the 90s, when the phone network was also opened to other players. They are more expensive though. Other than that, you might be lucky and have some small regional ISP that's competent enough. Otherwise there are just two other companies left that offer service nationwide, after a lot of mergers.

Re: Drastic increase in Tor clients from Germany

#216
post #192

Earlier quoted context omitted.

That would be an explanation and probably by okhams razor be more likely. But wouldn't that ISP notice the difference in traffic patterns drastically and react? It is just unlikely (but far from impossible) that this is something 'normal' happening. My fear would be that someone still is trying to gather a critical mass of nodes to contact controll servers via TOR to cause mass havoc in a single country from within a…

I can't speak to German ISPs or anyone outside of these USA. But I believe that ISPs are absolutely the weakest link when it comes to malicious botnets and other types of widespread network-based compromises. ISPs certainly have the tooling and the positioning to be able to detect C&C channels, outgoing DDOS attacks, and compromised customer premises equipment. But do they? And if they do detect any of it, do they ta…

My parents home lan got caught up in a bot net and their isp was sending emails about it to their isp provided email address.

But it's possible they were just passing on abuse reports from the numerous targeted victims of this botnet who bothered to complain.

The intrusion point was a Linux system with a 3 letter password and ssh exposed on a nonstandard port. So if you're someone who still thinks the bad guys won't find your computer because you changed the port, know that that is very outdated thinking.

Re: Drastic increase in Tor clients from Germany

#217
post #187

Earlier quoted context omitted.

Why would it be so localized to one country? Does Germany have a unique enemy compared to other NATO countries?

My guess is that a certain router is getting infected with a botnet because ISPs usually hand out the same router to their customers. And ISPs are usually limited to a single country.

[deleted]

Re: Drastic increase in Tor clients from Germany

#218
post #112

Earlier quoted context omitted.

My claim is that researchers are unlikely to be operating the botnet

I don't think anyone claimed or implied otherwise?

The original comment raised the possibility that researchers or the government were responsible for the 2m new tor users

Re: Drastic increase in Tor clients from Germany

#219

Tor metrics don't really tell you much about the actual human users of the networks. They mostly tell you about current bot/etc usage. It's why inferred tor v3 datarates have been wildly inflated (10gbps) ever since support was turned on in the release binaries despite 99% of human people using tor v2 (at the time).

You've been posting about Onion v3 and "human people" for years at this point, nothing is going to happen. v2 onion addresses are not secure, plain HTTP is not secure unless you run it over Wireguard or IPSec with path filtering and use DNSSEC, and almost no one ever does that.

Re: Drastic increase in Tor clients from Germany

#220

Earlier quoted context omitted.

I can't speak to German ISPs or anyone outside of these USA. But I believe that ISPs are absolutely the weakest link when it comes to malicious botnets and other types of widespread network-based compromises. ISPs certainly have the tooling and the positioning to be able to detect C&C channels, outgoing DDOS attacks, and compromised customer premises equipment. But do they? And if they do detect any of it, do they ta…

My parents home lan got caught up in a bot net and their isp was sending emails about it to their isp provided email address. But it's possible they were just passing on abuse reports from the numerous targeted victims of this botnet who bothered to complain. The intrusion point was a Linux system with a 3 letter password and ssh exposed on a nonstandard port. So if you're someone who still thinks the bad guys won't…

I don't even know how to log in to my ISP provided email., so it goes without saying that I'm not reading it. I'm surpised that ISPs still offer email.
Post reply on HN