[HN Gopher] Drastic increase in Tor clients from Germany
___________________________________________________________________
Drastic increase in Tor clients from Germany
Author : akyuu
Score : 248 points
Date : 2023-07-02 10:29 UTC (12 hours ago)
(HTM) web link (metrics.torproject.org)
(TXT) w3m dump (metrics.torproject.org)
| RobotToaster wrote:
| China has the great firewall, the UK has Hadrian's firewall, I
| guess this is the Berlin firewall.
| circuit10 wrote:
| As someone from the UK I've never seen anything blocked on my
| home Internet (except actual scam sites but you can turn that
| off, and yes that's from my ISP and not the browser)
|
| My mobile data does incorrectly flag some things as 18+ though
| wonderwonder wrote:
| Are you required to provide doxxing personal information
| proving your age on these sites or can you browse
| anonymously?
| circuit10 wrote:
| Only on my mobile data. They're not actually 18+ sites
| though, for example someone's blog that was posted here is
| blocked and it seems the Tor site is too
|
| But I think that's a Vodaphone thing rather than a UK thing
| wonderwonder wrote:
| So private companies are able to decide the websites
| their customers are allowed to access?
| infinityio wrote:
| No - the law that may end up requiring that is a proposal
| that is at least several months from being enacted [0],
| although it's been gaining momentum for several years - so
| unfortunately is looking like it might actually happen
|
| [0] https://www.bbc.co.uk/news/technology-6606560
| wonderwonder wrote:
| Is there concern in the press with the state having
| access to this data and using it to leverage individuals?
| concordDance wrote:
| I've seen a lot of things blocked, e.g. sci-hub
| wsintra2022 wrote:
| Sky and Virgin Media would often block sites I was trying to
| access, before I bought a vpn service. So yes the UK ISPs do
| block sites.
| rotanibmocy2 wrote:
| Ugh I have news for you
| RobotToaster wrote:
| Plenty of high seas sites are blocked.
| iguana_lawyer wrote:
| Looking at the chart it seems to line up with the war in Ukraine.
| Germany was a target of Prigozhin's Internet Research Agency
| (troll farms). I wonder if we will see a drop in Tor usage now
| that his coup has failed and his organization is being dissolved.
| viraptor wrote:
| I think you're missing the last week of that chart. The huge
| influx happened very recently, not months ago.
| wiz21c wrote:
| yet maybe ukraine's services are using tor for some of their
| communications ?
| fefe23 wrote:
| Could these be attempts at data mining for unmasking Tor users?
| wood_spirit wrote:
| Back in 2017 the German BND was revealed to have a history with
| that: https://netzpolitik.org/2017/secret-documents-reveal-
| german-...
| ChuckNorris89 wrote:
| I would be shocked if any intelligence service in the world
| wouldn't have their hands in that, even in the most respected
| democracies. Infiltrating "underground" networks and
| communities, and breaking encryption, is literally their job.
|
| Especially now that there's a war on our borders, the spooks
| have a plethora of reasons to use to justify their
| invasiveness.
|
| We just need to make sure to keep them accountable, which is
| the tricky part, as their work is always classified and our
| human and privacy rights often clash with their jobs, so
| unless any whistleblower comes through we might never know
| the extent of their rule breaking.
| Grimburger wrote:
| Seems most likely, either by academics or government.
|
| Not really the most subtle way about it though and likely to
| face some response.
|
| I'd assume both have the capability to run a fairly accurate
| simulated network without anyone noticing so it's a bit
| strange.
| reaperman wrote:
| Could it be someone using Hetzner?
| Blahah wrote:
| I doubt it's either of those - it would be extremely
| unethical and illegal for academics to do, and governments
| don't need to take this approach because they have a bunch of
| systemic attacks that are less obvious. Perhaps someone with
| a botnet looking to sell unmasking, which has been popping up
| as a service recently. Or trying to use it against a specific
| DWM or vendor.
| Grimburger wrote:
| Mentioned it because there's been many papers which
| specifically used the live network to do such a thing
| already. Some researchers have spun up large numbers of
| relays in the past to conduct their work.
|
| I personally don't see how it's unethical for either
| academics or governments to do this? Both have an interest
| in breaking tor, even when in the governments case where
| they both utilise it and want to know who else is using it.
|
| The tor people themselves acknowledge the work in their
| blogs
|
| https://blog.torproject.org/research-problem-measuring-
| safet...
|
| https://www.researchgate.net/publication/314521450_Characte
| r...
| PrimeMcFly wrote:
| > it would be extremely unethical and illegal for academics
| to do
|
| Nothing illegal about it.
| carstenhag wrote:
| Hugely depends on the country. Don't assume the law you
| know, to apply here
| PrimeMcFly wrote:
| Can you give just one example of a country with a law
| making it illegal for academics conducting research to
| attempt to demask tor users?
| deely3 wrote:
| EU? Basically researchers tries to get PII from people
| connected to Tor without consent of these people.
| PrimeMcFly wrote:
| That's an interesting argument. Not sure it would hold
| up. I don't think an IP alone counts as PII, since the
| ISP would have to be queried to actually get any contact
| info.
| thissitesucks__ wrote:
| [dead]
| addandsubtract wrote:
| IP addresses are PII under GDPR.
| PrimeMcFly wrote:
| Not by themselves, surely?
|
| Even so, GDPR has research exemptions which would protect
| the academics doing research in the example being
| discussed.
| [deleted]
| Blahah wrote:
| There is, because it's a botnet
| PrimeMcFly wrote:
| That would likely make researching and demasking the
| entities involved explicitly _legal_.
| Blahah wrote:
| My claim is that researchers are unlikely to be operating
| the botnet
| PrimeMcFly wrote:
| I don't think anyone claimed or implied otherwise?
| Blahah wrote:
| The original comment raised the possibility that
| researchers or the government were responsible for the 2m
| new tor users
| flangola7 wrote:
| What is unmasking? What does it have to do with a botnet
| hattmall wrote:
| Revealing the identities of tor users or hidden services.
| One way to do it is by controlling a large share of the
| network.
| kobieyc wrote:
| Yes but this clients, not nodes. So this actor does not
| control a large share of the network, they just use a
| large share of the network.
| topynate wrote:
| It's not clear to me how you'd do that with clients, rather
| than relays.
| hattmall wrote:
| DDOS a hidden service and track the request spike through
| your exit nodes. I think this is how the original silk road
| was investigated.
| thissitesucks__ wrote:
| [dead]
| yunohn wrote:
| It's quite an interesting spike, though I doubt that such an
| operation would be so obviously.
| treprinum wrote:
| Would regularly changing circuits/identities mitigate this?
| E.g., pressing ctrl/cmd + shift + L every few minutes?
| frankfrankfrank wrote:
| [dead]
| V__ wrote:
| There is no way these are organic users. Could it be, that some
| VPN is using Germany as an entrypoint?
| sparkling wrote:
| Why? VPN users mostly care about the Exit IP country, not the
| Entry IP country.
| hedora wrote:
| Some VPNs have a "then connect to tor" option for extra
| anonymity against malicious tor entrypoints and against your
| local ISP seeing that you are browsing tor [hosted sites].
| FinnKuhn wrote:
| Could be that someone is using a Cloud Provider in Germany, for
| example Hetzner
| sparkling wrote:
| Doubt it. Hetzners smallest machine is something like
| $4/month, additional IPv4 addresses come with extra cost.
| They have quite tight service quotas, and this 2M additional
| IPs would be almost their entire IPv4 pool.
| moooo99 wrote:
| I don't know about the details, but I know Hetzner has
| quite a backstory with their servers being abused by
| spammers. I don't know how the state is today, but maybe
| it's not as unlikely as it seems?
| withinboredom wrote:
| If they even think you are spamming, you get banned.
| Pretty much closed to individuals (according to Reddit,
| if they don't even like the way your ID looks, you're
| banned) while businesses get more leeway to do things.
| moooo99 wrote:
| I didn't realize they're that strict. I have an
| individual account with them I occasionally use and
| didn't encounter any issues with ID (I can't even recall
| being ID'd tbh). That being said, I am located in Germany
| and have a German billing address, so maybe international
| customers have more issues?
| CryptoBanker wrote:
| They're not closed to individuals. I've run two VPSs on
| Hetzner cloud for 2 years now...
| reaperman wrote:
| No one I know has had issues like that. They also don't
| spam, but Hetzner is generally considered in ny circles
| to be a pretty newbie-friendly service especially for
| people looking to use basic baremetal machines. Maybe
| we've just gotten lucky, or maybe we all hail from the
| right geographies.
| withinboredom wrote:
| Those machines are pretty nice though. Great for "base
| load" (handling the scale you almost never go below).
| abdullahkhalids wrote:
| I have an account with them for my website/email. No
| problems. Even asked them to open up the IP for SMTP
| requests and they asked how many emails I wanted to send
| per month, and I told them it was my personal email and
| less than 100/month. They happily granted me access.
| FinnKuhn wrote:
| Hetzner was just an example, because they are a well known.
| Interestingly a similar sudden increase of German Tor users
| also happend in 2017:
| https://www.chip.de/news/Raetselhafter-Nutzeranstieg-Zahl-
| de...
|
| Hetzner (and other German entities) seem to operate quite a
| few relays though:
| https://metrics.torproject.org/rs.html#aggregate/as not
| sure if this might have something to do with it...
| jacooper wrote:
| They don't operate the relays themselves, rather users
| install relays on hetzner vpses/servers.
| curiousfab wrote:
| From an average of significantly below 500k to almost 2.5M users.
| This drives up the global number of connecting users from approx.
| 3M to almost 5M.
|
| Hard to imagine that so many people in Germany suddenly switched
| to TOR, especially since there has not been any significant event
| lately that may have triggered such a decision (afaik)?
|
| My personal experience with TOR (as an administrator of various
| websites and services) is that it is a major source of
| unwanted/malicious traffic (spam, etc.) and most of it is
| automated. The big increase is probably not users but bots?
| supriyo-biswas wrote:
| I faced a recent distributed attack averaging 20,000 RPS[1]
| around the same time which makes me think that there might be a
| bot. I wonder if there's a network of website operators similar
| to NANOG or the RIPE NCC mailing lists where I could compare my
| own experience with those of other operators.
|
| [1] https://news.ycombinator.com/item?id=36561930
| hartator wrote:
| Why not CAPTCHA protect these pages instead of blocking tor?
| Same attack can go through regular web.
| supriyo-biswas wrote:
| I already have per-IP ratelimiting, and I'm against using
| captchas have bad UX (including the much-hailed Turnstile).
|
| I'll probably migrate to some proof-of-work based schemes
| and some algorithms to detect anomalous requests, but it
| would require some engineering work on my part (for a free
| website FWIW), and the quickest way to mitigate it would be
| to block Tor.
| thissitesucks__ wrote:
| [dead]
| hedora wrote:
| IP blocking blocks most of the people on our local ISP.
| They are small, and use CGNAT, so one owned windows
| machine across town breaks sites like yours for everyone,
| and the root cause is extremely difficult to debug for
| end users.
|
| As much as I deeply, deeply dislike captchas, ip blocking
| is far worse.
| sweetjuly wrote:
| IP blocks also just don't work on IPv6. Unless you're
| prepared to block entire by ASN, an adversary can cheaply
| just buy up a lot of address space and churn through
| them. It gets even messier when dealing with real ISP
| networks because some hand out /40s for residential
| customers whereas others give just a /56.
| RobotToaster wrote:
| >I'll probably migrate to some proof-of-work based
| schemes and some algorithms to detect anomalous requests,
| but it would require some engineering work on my part
|
| Have you tried mcaptcha?
| https://github.com/mCaptcha/mCaptcha
| lionkor wrote:
| If there isn't, lets make one. We could self host it, lock it
| down to invite-only.
| mistrial9 wrote:
| do you believe these numbers?
| [deleted]
| j16sdiz wrote:
| It would be much helpful if you could provide one or two
| reasons why the number could be wrong.... or maybe make some
| comments on the methodology, etc..
|
| Just question about the accuracy without any context or
| reasons are not contributing to the argument.
| passers wrote:
| [flagged]
| ilyt wrote:
| [flagged]
| passers wrote:
| [flagged]
| [deleted]
| [deleted]
| [deleted]
| [deleted]
| riedel wrote:
| The interesting question is if there is a bot net spreading in
| Germany since the 17th of June. What would be the likelihood of
| that going undetected. If you like conspiracy theory, the rise
| in one country could point to state actors.
| WarOnPrivacy wrote:
| > The interesting question is if there is a bot net spreading
| in Germany since the 17th of June.
|
| A minor addendum: Looking at the csv file, it looks to me
| like traffic began drifting above the mean about June 6. From
| there I see a ramp-up, growing at an increasing rate.
| layer8 wrote:
| That's when the Kakhovka dam was destroyed, shortly after
| the Ukrainian counteroffensive began.
| tw04 wrote:
| Off the top of my head - Germany hosts a disproportionate
| amount of sensitive data because it's the location of choice
| for cloud providers storing things for EU member countries.
| They have lots of fiber, lots of ISPs, plenty of datacenter
| space, a stable government, and data security laws that meet
| or exceed everyone else in the EU.
| ballenf wrote:
| Why would it be so localized to one country? Does Germany
| have a unique enemy compared to other NATO countries?
| aeyes wrote:
| My guess is that a certain router is getting infected with
| a botnet because ISPs usually hand out the same router to
| their customers. And ISPs are usually limited to a single
| country.
| riedel wrote:
| That would be an explanation and probably by okhams razor
| be more likely. But wouldn't that ISP notice the
| difference in traffic patterns drastically and react? It
| is just unlikely (but far from impossible) that this is
| something 'normal' happening.
|
| My fear would be that someone still is trying to gather a
| critical mass of nodes to contact controll servers via
| TOR to cause mass havoc in a single country from within a
| single country. Generally IMHO Germany would be a good
| target for destabilisation currently. But I think and
| hope this could just a bit of overinterpreting. Probably
| one would need a good statistic on the subnets the users
| come from.
| eitland wrote:
| > That would be an explanation and probably by okhams
| razor be more likely. But wouldn't that ISP notice the
| difference in traffic patterns drastically and react?
|
| I hope to be wrong but I am afraid you are overestimating
| the technical competency of the average ISP.
| NoZebra120vClip wrote:
| I can't speak to German ISPs or anyone outside of these
| USA. But I believe that ISPs are absolutely the weakest
| link when it comes to malicious botnets and other types
| of widespread network-based compromises.
|
| ISPs certainly have the tooling and the positioning to be
| able to detect C&C channels, outgoing DDOS attacks, and
| compromised customer premises equipment. But do they? And
| if they do detect any of it, do they take action? When is
| the last time you heard about an ISP disconnecting a
| paying customer because of the customer's compromised
| device(s)? When is the last time you even heard of an ISP
| notifying a customer about such a thing?
|
| Two months ago, my router was compromised and joined to
| some sort of botnet in the capacity of a DNS resolver. I
| would never have been able to detect such WAN-side
| traffic if I hadn't had a special setup on my part. My
| ISP was the first to hear when I'd detected it, and I
| sincerely doubt that they receive many such reports,
| especially with logs as evidence.
|
| Can you imagine receiving a phone call, "Hello, this is
| your ISP! You're pwned! Please follow through these
| remediation steps as I prompt you: ..." You'd undoubtedly
| think it was a phishing scam. Because ISPs just don't
| seem to care about abuse.
|
| They will send you copyright strikes and prosecute you
| for BitTorrent, but it does't seem like they'd lift a
| finger to prevent the next big DDOS or spam factory
| originating from their own customers.
| zirgs wrote:
| My ISP actually sent me an email that said that one of my
| devices have an open TCP 445 port and advised me to fix
| it. Apparently Windows opens it by default and it can be
| exploited by some malware.
|
| But I've never received a threatening letter about
| piracy. ISPs in my country simply don't send those.
| NoZebra120vClip wrote:
| Many ISPs have clauses in their TOS that prohibit running
| any server of any kind. So it may be the case that your
| ISP regularly runs sweeps to detect customers who are
| running servers, and this warning may be a side effect of
| that sweep.
|
| I often used to poke holes in my firewall and run VPN or
| ssh servers that were discoverable using my dynamic DNS
| service. My ISP never got involved with that. Of course,
| that was a case of me running a server for my exclusive
| use, rather than some sort of public web or login server
| that would have randos sending traffic across my link.
| ZalorCakeLord wrote:
| My ISP will send letters or emails, but only if they get
| a complaint from the company in question. Usually what
| ends up happening is a company watches a torrent, and
| takes down a list of all the ip addresses downloading it.
| They then send boilerplate complaints to the isps
| associated with said ip addresses, who are legally
| required to do _something_ about it. My little brother
| got in trouble this way lmao, they sent a letter to our
| house about it.
| iforgotpassword wrote:
| In Germany, I doubt they have the tooling or staff
| anymore. For almost a decade we've been in a race to the
| bottom regarding pricing and as a result, service
| quality. I wouldn't be surprised if critical parts of the
| infrastructure are maintained by outsourced jobs from
| half around the world.
|
| The only somewhat professional player is the Deutsche
| Telekom, which was kinda the Bell of Germany and got
| privatized in the 90s, when the phone network was also
| opened to other players. They are more expensive though.
| Other than that, you might be lucky and have some small
| regional ISP that's competent enough. Otherwise there are
| just two other companies left that offer service
| nationwide, after a lot of mergers.
| Fatnino wrote:
| My parents home lan got caught up in a bot net and their
| isp was sending emails about it to their isp provided
| email address.
|
| But it's possible they were just passing on abuse reports
| from the numerous targeted victims of this botnet who
| bothered to complain.
|
| The intrusion point was a Linux system with a 3 letter
| password and ssh exposed on a nonstandard port. So if
| you're someone who still thinks the bad guys won't find
| your computer because you changed the port, know that
| that is very outdated thinking.
| SoftTalker wrote:
| I don't even know how to log in to my ISP provided
| email., so it goes without saying that I'm not reading
| it. I'm surpised that ISPs still offer email.
| [deleted]
| WarOnPrivacy wrote:
| > My guess is that a certain router is getting infected
| with a botnet because ISPs usually hand out the same
| router to their customers.
|
| This seems trivial to figure out with an analysis of the
| connecting IPs - which is absent on TOR's report page.
|
| I'm also a bit confused why no one here on HN has asked
| about the connecting IP data (at this writing). Are these
| commercial IPs, dynamic (biz/residential) IPs or a mix?
| If they're mostly dynamic IPs, are they from more than
| one ISP?
|
| TOR has country of origin data so it seems reasonable
| they'd also have network of origin.
|
| All that said, I don't precisely know how TOR determines
| country of origin. Entry node data would seem to be the
| likely source. However I've long assumed that entry nodes
| are public supplied, like Relay and Exit nodes. Within
| that assumption it isn't clear to me how that data would
| flow to TOR - while maintaining anonymization of traffic.
| mantas wrote:
| Maybe German state itself is the actor.
| tetris11 wrote:
| My bet is Russia.
|
| I work in a German institution. I was recently hacked by
| such a botnet recently (lessons learned: use
| AuthorizedKeys, allow only one SSH user, proxy all http
| connections to a webhoster, and check your SSH and UFW
| logs often!)
|
| It setup a virtual environment where it downloaded some
| kind of Tor node and ran some sort of code that used 100%
| of my CPU. My guess is crypto-mining. I purged the
| account, deleted everything before I could do forensics,
| but I checked the logs for the connections and they all
| came from Russia.
| hedora wrote:
| What state actor doesn't understand statistical
| deanoymization attacks against tor?
|
| (e.g., if you single-handedly double the network traffic,
| then an outside observer can figure out what
| ingress/egress traffic is yours)
| mantas wrote:
| Why pay attention to this if you can simply blame another
| state actor?
|
| And German federal government have a history for covert
| shitposting.
| theonlybutlet wrote:
| Any UX changes to something like Brave browser perhaps? Making
| it easier to use tor mode. Although this is a big jump.
| [deleted]
| throwaway290 wrote:
| Note that the growth is not just in Germany. Ireland, Sweden,
| Switzerland also show jumps (however in absolute terms they are
| still much smaller). I would not rule out it's people or bots
| connecting from third country/countries through VPNs based in
| Europe... for whatever reason.
| ncr100 wrote:
| Is it a bug in a client that accidentally spawns sub-clients?
| doubleorseven wrote:
| VPSs in germany are much cheaper. But I'm guessing this
| increase is paid with crypto or debit cards so pin pointing
| it to a specific provider like hetzner is hard
| rurban wrote:
| Hetzner used by criminals would be my guess.
| aaron695 wrote:
| [dead]
| netsharc wrote:
| Maybe related to the Proto-Nazi party AfD winning a district a
| few days ago. And this 5 day old news story:
| https://www.politico.eu/article/germany-far-right-afd-securi...
| "Germany's far-right AfD placed under security service
| surveillance" - "The party is now treated as a 'suspected case'
| for far-right extremism".
|
| I wonder if anyone can see inside the right-wing chat networks
| and if they've been mentioning Tor.
|
| Although in the raw CSV's the spike started around mid-June...
| oaiey wrote:
| That is not sufficient in total numbers. That would be in the
| press that a whole part of the population goes Tor. They would
| never be quiet enough about it.
|
| Looks anorganic and if it is organic I bet for Netflix and co
| related.
| 0xDEF wrote:
| As a Danish person who has been to Eastern Germany (outside
| Berlin) I'm really not surprised by the rise of the AfD. It's
| common to see people on social media praise Germans for de-
| Nazification and criticize the Japanese for not confronting
| their past in the same way. Those people have clearly not
| interacted with Eastern Germans. In Eastern Germany the
| underlying neuroticism, persecution complex, and willingness to
| believe in every conspiracy theory, things that were
| foundational for the rise of Nazism, is very much still alive.
| hgadx wrote:
| [flagged]
| gmerc wrote:
| Please you are whitewashing history. Hoyerswerda gruesst.
| This shit was happening already in the 90s right after
| reunification and in the context of OP - it's not
| surprising at all, eastern germany had a very different
| take on denazificaiton.
| hutzlibu wrote:
| "eastern germany had a very different take on
| denazificaiton."
|
| As opposed to the BRD, where for example the "Auswartiges
| Amt" had more ex NSDAP party members after 1945 than
| before?
|
| There definitely was denazification in the east, but the
| totalitarian enclosed and literally walled of mindset did
| not help with creating an open mind towards the world.
| Add to that high unemployment and poverty after 1990 and
| you get the usual extremists on both sides of the
| spectrum.
| gmerc wrote:
| You will notice I did not say Western Germany was great
| at it. Different.
| hutzlibu wrote:
| I noticed, but in the context it seems to imply a worse
| take.
| nbryc wrote:
| [flagged]
| gmerc wrote:
| Because at the time that SED follow up was still binding
| the Nazi vote.
| virtualritz wrote:
| I don't know why this is getting down voted.
|
| Poster didn't say it's rampant, just that "it is very much
| alive."
|
| I'm German, I live in Berlin, I regularly spend time in
| eastern Germany, outside Berlin. I can sadly confirm this.
| joeythedolphin wrote:
| Can you say more about East Germany and what is going on
| there for them to be open to conspiracy theories, neurotic
| thoughts, etc?
| lyu07282 wrote:
| Disenfranchisement, after reunification they were left
| with little generational wealth, liberalism spiraled them
| deeper into a hopeless situation, no jobs, no economic
| future, impoverishment. Under liberalism the only
| alternative offered to them is the far right.
|
| During the cold war and after, the US and anglosphere was
| mostly interested in the destruction of left ideology,
| labor unions, left parties etc. were all targeted. The
| right offers a safe outlet for people with those
| grievances, it doesn't threaten capital, so it was always
| allowed to linger in Germany not just in the east. It's
| deeply rooted in establishment and civil organizations,
| in university fraternities (schlagende verbindungen, the
| CSU etc.). The allied supported and used and bolstered
| far right groups all around Europe (Gladio, NSU, etc.) in
| their fight against socialism and people on the left. We
| still feel the effects to this day and state and federal
| police and intelligence still operate this way.
|
| Protests in Germany you see police protecting far right
| groups from leftists, not the other way around. It's a
| necessary aspect of liberalism to allow the
| disenfranchised the outlet into right wing extremism.
| niemandhier wrote:
| The german lands east of the river Elbe have been
| different from the western parts of Germany for more than
| a 1000 years. In the historical record you see a pretty
| sharp change in marriage patterns,land ownership and
| political structure when crossing the Elbe.
|
| The enlightenment was less influential in the rural
| estates of the ultra conservative east elbian
| Junkernklasse than it was in the more densely populated
| Rhineland regions. Fukuyama has a nice chapter on the
| matter in "The Origins of Political Order".
|
| On top of that you have the separation, and the dislike
| of the GDR to foster critical thinking and the economic
| collapse of the east after reunification that lead to a
| lot of brain drain.
| suction wrote:
| [dead]
| Jibbedeyeah wrote:
| [flagged]
| RobotToaster wrote:
| Hardly surprising, treuhand left east Germany extremely poor.
| nebalee wrote:
| The unification wasn't exactly free. The immense costs for
| the most part were shouldered by western citizens through
| the Solidaritatszuschlag. The total price tag is estimated
| to be between 0.95 and 2 trillion Euro (https://de.wikipedi
| a.org/wiki/Kosten_der_deutschen_Einheit#R...).
| joeythedolphin wrote:
| It could be INTERPOL
| concordDance wrote:
| Does anyone understand the mass flagging and downvotes going on
| in this comment section? I'm very confused as I've never seen
| anything like it.
| chippy wrote:
| I'm guessing that there is some automatic system that works on
| certain words in comments. Flame detection has been mentioned
| before. Probably in combination with account age or karma. I
| also imagine that users vouching for these might offset the
| behaviour.
| MrStonedOne wrote:
| If the number of comments in a post or subthread exceeds the
| upvotes, this leads to the flame detector activating.
|
| But also some accounts are just banned.
|
| Banned accounts can still comment, but they start dead and
| have to be vouched first before showing to anybody who didn't
| enable showdead in their profile.
| maze-le wrote:
| Just the usual political flamewar that happens here from time
| to time, not sure why it escalates on some threads and not on
| others though.
| Andrex wrote:
| Probably the posters involved. Blessing and a (minor) curse
| that HN doesn't use avatars. Harder to avoid commenters you
| know you don't like.
| [deleted]
| systemvoltage wrote:
| [flagged]
| nebalee wrote:
| > Germany is blocking news from French riots.
|
| What are you on about? The riots in France are on pretty much
| every news site in Germany.
| systemvoltage wrote:
| [flagged]
| systemvoltage wrote:
| More here: https://www.reddit.com/r/2westerneurope4u/commen
| ts/14nx7v5/t...
| RobotToaster wrote:
| If you click the timestamp there should be a "vouch" button for
| comments to restore them.
|
| It's quite annoying, possibly NAFO or similar.
| 19h wrote:
| ,,These estimates are derived from the number of directory
| requests counted on directory authorities and mirrors."
|
| Depending on how these numbers are obtained, there is a non-zero
| chance at least part of this increase is caused by us.. note that
| this number is not indicative of the amount of users or origins
| (i.e. physical source addresses), but only count directory
| requests.
| Havoc wrote:
| Plausible options seem to be malware, another attempt to crack
| tor by enforcement or some sort of app that added tor browsing
| tarcon wrote:
| From around September 2022 to March 2023 media in Germany
| promoted the Snowflake Browser Extension
| (https://addons.mozilla.org/de/firefox/addon/torproject-snowf...)
| to help Iranians circumvent censorship. Is this a possible
| explanation?
| Jibbedeyeah wrote:
| [flagged]
| Moldoteck wrote:
| [flagged]
| VWWHFSfQ wrote:
| [flagged]
| snacktaster wrote:
| It's amusing to me that you're getting crushed on here for
| blocking/ "defederating" known IPs that you don't want traffic
| from, but I would bet that these same people would champion
| your right to do the same if you were blocking a spammy
| mastadon or lemmy instance that you didn't like!
| computerfriend wrote:
| It's not hypocritical. They have every right to block Tor
| traffic. I don't want them to do it, but also don't want them
| to lose the right to do it.
| belorn wrote:
| I constantly use tor as a way to get a third view when
| debugging connection issues for customers and malware infected
| websites. If you ever experience the issue of a customer saying
| they can't connect, but when you test it it works perfectly
| fine, tor is great to verify if the issue might effect more
| customers. As a side effect of it being ipv4 only, you can also
| test issues when one protocol work but not the other (there are
| alternative tools but tor is by far easiest at hand).
| tg180 wrote:
| Tor hasn't been IPv4-only since a long time
| teddyh wrote:
| True, but most exit nodes are IPv4-only, so in practice it
| works.
| jeroenhd wrote:
| The traffic my servers receive from China, India, South
| America, Africa, and Eastern Europe, and the UK is also almost
| exclusively boys and exploit scanners.
|
| You can block whatever IP addresses you like but the bot to
| user ratio of any given IP address is absolutely terrible. Tor
| concentrates a lot of traffic into a few exit nodes but by this
| logic most small countries should be blocked from most
| websites.
| isoos wrote:
| I use tor for exploring topics that I don't want to tie to my
| regular profile (ranging from professional software
| development, through health care issues, but also hobbies,
| fiction and nsfw content). Having these browsing in a separate
| profile and also IP address makes it much more relaxed to look
| for interesting stuff on the internet. (I am not really fond of
| advertisement that tries to sell me whatever I've visited in
| the past month, on unrelated pages.)
|
| It saddens me that the default response is ban, increasingly so
| for services that need account, but even just reading a webpage
| can become tedious or impossible :(
|
| Please, do not ruin this option, because even though you may
| not use it today, you may need it in the future.
|
| Note: I also use tor for low volume crawling. When high volume
| is needed, it is more favorable to subscribe for domestic VPN
| proxies, so you may be blocking tor, but you won't block those
| ranges, and the robots will get their content anyway.
| bauruine wrote:
| Whenever I read something like this I look my access and sshd
| logs for abuse IPs and check if they are Tor exit nodes. The
| Tor traffic is always negligible like 100 failed ssh logins
| out of 170k are from Tor exit nodes. Or 670 out of 400k for
| my nginx access.log. Am I unique and everyone else sees
| vastly different numbers where blocking Tor exits makes a
| significant difference in the abuse they get?
| isoos wrote:
| I don't really care if somebody blocks a random port of
| sshd. I just don't understand why people are eager to block
| public https traffic, which is exposed to the public
| internet anyway.
| supriyo-biswas wrote:
| Well, I've always tried to make my service available through
| Tor, but now that I faced an attack of 20,000 RPS distributed
| over all the exit nodes of the Tor network making requests to
| a computationally expensive (and non-cacheable) endpoint, and
| came out with 6x the hosting bill I usually get, I decided to
| block the entire network.
|
| Maybe there's an alternative reality where people do the
| right thing, and in that world I wouldn't have to block Tor,
| but I don't live in that world.
| isoos wrote:
| Shouldn't you protect that endpoint, regardless of the
| traffic coming from tor or not? It is really cheap to get
| traffic through domestic VPN proxies, so a dedicated
| attacker will get to it anyway...
| ilyt wrote:
| There is no reason to allow Tor IPs on most sites sadly. The
| abuse it is used for far exceeds legitimate traffic
| VWWHFSfQ wrote:
| > Please, do not ruin this option
|
| I don't believe that I'm the one that ruined this option for
| you. Small web hosts simply don't have the capacity, budget,
| or patience to deal with the 95% garbage originating from
| these IP addresses. Tragedy of the commons, I guess.
| justinclift wrote:
| Probably depends on what kind of service you're providing.
|
| I (a legitimate user) get blocked on websites when using Tor
| quite a lot. It's a pita. :(
|
| That being said, there's no chance in hell I'd ever put a CC or
| similar private info though a Tor based network connection.
| Just in case... ;)
| CaptainFever wrote:
| > That being said, there's no chance in hell I'd ever put a
| CC or similar private info though a Tor based network
| connection. Just in case... ;)
|
| For HTTPS sites, why?
| justinclift wrote:
| Paranoia. :)
| Santosh83 wrote:
| Have used Tor for accessing the Z-library and several other
| cases where sites where blocked or taken down. Not all of Tor
| is dark web shadiness or bots.
| ipaddr wrote:
| How would you know if they are legitimate if you block them.
| 31337Logic wrote:
| Wow, that's terrible, for reasons already explained to you
| below. Please reconsider.
| VWWHFSfQ wrote:
| No the IP blocks are very effective. I don't believe that I
| have any obligation whatsoever to allow criminal groups on
| the other side of the world to spam burp suite scans over Tor
| against my websites nonstop.
| wood_spirit wrote:
| Clicking around and looking at the chart for random other
| countries shows a spike for Sweden too, whereas Finland has a
| different but interesting pattern all of its own.
| chronicsonic wrote:
| Wonder if the fact that they're related to NATO, who is at war,
| have anything to do with it.
| lost_tourist wrote:
| I can think of a country currently at war that has a much
| more aggressive and longer history of being a bad actor on
| the internet than NATO countries...
| hnarn wrote:
| Nato is not at war.
| HumanOstrich wrote:
| Can you elaborate on this a bit?
| sdsd wrote:
| The obvious explanation is that German ISP's blocked 711chan, so
| the onion service is the only way for them to access the site.
|
| Jk, but if you change 711chan to Krautchan maybe it's true
| Havoc wrote:
| Sudden 2 mill extra isn't organic Chan users
| ulrischa wrote:
| Germany is blocking a lot of websites ( i.e. rt.com)
| dhoe wrote:
| But that's been happening for some time already, while this
| spike is recent.
| Xeophon wrote:
| Russian-run sites like RT are banned through the whole EU.
| However, such spikes cannot be seen in other EU countries such
| as France.
| mr_mitm wrote:
| I can open rt.com just fine in Germany. (Not using my ISP's
| DNS server though. It's true that rt.com won't resolve when
| using it.)
| beebeepka wrote:
| Lies. I just tried rt.com on my home connection and it opened
| without a problem
| the_mitsuhiko wrote:
| Might also depend on how it's enforced. The blocks in Austria
| basically do not exist because they are only done by carrier
| DNS servers. Use 1.1.1.1 or 8.8.8.8 and you would not know.
| lxgr wrote:
| The vast majority of people use their ISP's DNS server,
| though.
| the_mitsuhiko wrote:
| I don't think that is relevant here. If in one country
| you need a VPN to bypass blocking but others you only
| need a different DNS server I would expect most users to
| go for the latter if given a choice.
| commandnotfound wrote:
| I just opened rt.com on my home connection with no tor or VPN
| and everything worked. I'm physically in the Czech Republic
| if that matters.
| ChatGTP wrote:
| I just read on Al-Jazeera that Putin is back in control,
| that's why :)
| jd_paton wrote:
| Source? I'm in NL and I can access it just fine. I use
| Cloudflare for DNS though
| mkl95 wrote:
| I would say this is the best solution. I live in another EU
| country where ISPs also block it via DNS.
| PrimeMcFly wrote:
| No excuse for that censorship honestly.
| flangola7 wrote:
| Eliminating enemy propaganda is extremely common and a
| long running practice. It's less censorship and more self
| defense.
| PrimeMcFly wrote:
| Looking at it from that perspective it makes a kind of
| sense, although I think it is less defensible in modern
| day with the internet.
| [deleted]
| cynicalsecurity wrote:
| [flagged]
| sparkling wrote:
| If you think your citizens are vulnerable to being tricked by
| Russian propaganda, you have a much bigger problem than
| Russian propaganda.
| tuukkah wrote:
| Democracy is not immune to the post-truth attacks. Part of
| it is the existence of Western helpful fools who launder
| the Russian propaganda.
| 0xDEF wrote:
| Not really. I preferred the approach of pre-Musk twitter that
| clearly labeled it as Russian state media. Also banning it
| had little effect. The war propaganda coming out of Russia
| was hilariously incompetent.
|
| The real insidious anti-Ukrainian propaganda is coming from
| pro-Russian Westerners, pre-dominantly the American populist
| right.
| hutzlibu wrote:
| And NATO or ukrainian propaganda?
|
| Because that is also a thing, even though not as blatant.
|
| The problem with banning information, is that it is easy to
| abuse this and it creates a martyr effect. I rather would
| like people be able to judge information by themself and not
| decide for them.
| timeon wrote:
| NATO or Ukraine are not invading any European country.
| hutzlibu wrote:
| NATO member Turkey is regulary doing raids in Syria and
| they also annected territory there. And they did not
| really take it from evil Assad, but from the kurds.
|
| And when 47% of americans believed, that Hussein was
| responsible for 9/11, than this is also the result of
| propaganda to create support for a illegal war.
|
| https://en.m.wikipedia.org/wiki/Opinion_polls_about_9/11_
| con...
| duozerk wrote:
| > Because that is also a thing, even though not as blatant.
|
| It's far more blatant; like the retraction of the articles
| - years after their publication - that pointed out the CIA
| involvement in the regime change in Ukraine in 2014, or the
| ones outlining the influence of banderites in the same
| government; along with like 90%
| (https://theprint.in/tech/60-80-of-twitter-accounts-
| posting-o...) of the war bots on twitter being pro-ukraine,
| not pro-russia.
|
| We're (assuming you're in a Western country like me) just
| seeing it from the inside, so it looks less blatant.
| 0xDEF wrote:
| The "90% of bots are pro-Ukraine" bullshit report only
| looked at a handful of hashtags during the first few
| weeks of the war.
|
| Anyone who has been on twitter knows that pro-Russian
| disinfo is far more widespread. There are literally viral
| tweets blaming Ukraine for creating COVID-19.
| duozerk wrote:
| Looking into it you appear to be right, thanks; that
| single study is almost exclusively _the_ single source of
| all similar articles, too. Admittedly I don 't use
| twitter, so I don't have first hand experience in this.
|
| It's still pretty obvious that there is a propaganda
| effort from NATO as well, and one that seems to work a
| lot more than Russia's on western audiences.
|
| > There are literally viral tweets blaming Ukraine for
| creating COVID-19.
|
| lmao that's so insane it almost sounds like a bit
| hutzlibu wrote:
| "There are literally viral tweets blaming Ukraine for
| creating COVID-19.
|
| lmao that's so insane it almost sounds like a bit "
|
| Ah well, people exposed to propaganda can believe all
| kinds of weird stuff. For example many (43%!) US people
| believed, that Hussein was responsible for 9/11:
| "Do you think Saddam Hussein's regime in Iraq was
| directly involved in planning, financing, or carrying out
| the terrorist attacks of September 11th, 2001?"
| September 2003 responses: 47% Yes"
|
| https://en.m.wikipedia.org/wiki/Opinion_polls_about_9/11_
| con...
| _kbh_ wrote:
| > lmao that's so insane it almost sounds like a bit
|
| It sounds like a bit but the Russians have some wild
| state based propaganda stuff like that Ukraine was using
| mutant super soldiers, that Ukraine had black magic witch
| battalions and that Ukraine was breading pigeons that
| where modified to spread viruses to kill Russians.
| hutzlibu wrote:
| But I also see russian propaganda, so I can compare and
| confirm it is not at all on the same level.
|
| But if I would not been able anymore to see the russian
| point of view, then I would start to suspect they have a
| point I am not allowed to see, to keep me under control.
| But now I can see it and so I can see that their point is
| just russian nationalism/empire thinking with zero
| interest of truth, just power. Full of literal lies. So
| yes, you also can find lies and manipulation in western
| reporting. But I have a hard time understanding why
| anyone can think it is the same.
| aqme28 wrote:
| Is tor really the go-to workaround for this and not just a VPN?
| reaperman wrote:
| VPN seems like it would be vastly preferable for performance
| and reliability.
| BasedAnon wrote:
| Sure but Tor is free
| jandrese wrote:
| Yeah, but few VPNs are free, and the ones that are tend to
| be slow and unreliable due to overloading.
| reaperman wrote:
| This comprises 40% of all global Tor users. I'm not sure
| it's reasonable to assume they all wouldn't have the
| budget for Mullvad.
| Zetobal wrote:
| - it's dns blocked -
| [deleted]
| sparkling wrote:
| Uhm...
|
| https://de.wikipedia.org/wiki/Sperrungen_von_Internetinhalte.
| ..
|
| Edit: parent poster has now changed his post after claiming
| there was no blocking in Germany
| jacooper wrote:
| I've noticed VPN severs in Germany to be busier than usual too.
| superkuh wrote:
| Tor metrics don't really tell you much about the actual human
| users of the networks. They mostly tell you about current bot/etc
| usage. It's why inferred tor v3 datarates have been wildly
| inflated (10gbps) ever since support was turned on in the release
| binaries despite 99% of human people using tor v2 (at the time).
| Vecr wrote:
| You've been posting about Onion v3 and "human people" for years
| at this point, nothing is going to happen. v2 onion addresses
| are not secure, plain HTTP is not secure unless you run it over
| Wireguard or IPSec with path filtering and use DNSSEC, and
| almost no one ever does that.
| brucethemoose2 wrote:
| Is someone trying to compromise the Tor network?
|
| I read that Tor needs a certain percentage of non-malicious nodes
| to function, though I am not sure if that is applicable clients.
| TheNorthman wrote:
| It's not applicable to clients. A clients traffic never touches
| another client, only the nodes.
|
| Of course, malicious clients can ruin it for everyone else in
| the form of DoS attacks but that's clearly not happening here.
| chezelenkoooo wrote:
| I think you're thinking of blockchain
| thissitesucks__ wrote:
| [dead]
| kadoban wrote:
| Sybil attacks are more general than just in cryptocurrencies.
| They actually apply to Tor as well, just not to _this_ part
| of Tor.
| r4indeer wrote:
| No, the problem also applies to Tor. If a malicious actor
| controls large parts of the network, there is a high
| probability that the attacker controls your entire circuit or
| at least your entry and exit node.
|
| In the latter case, you can do timing attacks to determine
| which traffic on the exit node belongs to whom on the entry
| node.
| golergka wrote:
| Have something changed in how German police goes after drug
| dealers? It's the most important use case for Tor anyway.
| [deleted]
| carstenhag wrote:
| No new law or something was passed, so if at all, it's a
| technique/method that won't be published.
| tyiz wrote:
| [flagged]
| ruune wrote:
| Sounds interesting, do you have a link or something for me?
| jandrese wrote:
| [flagged]
| spuz wrote:
| That site doesn't seem to have any stories about Germany
| moooo99 wrote:
| Honestly, the most notable political prosecution I could
| think of right now is police in Bavaria prosecuting
| climate activists under anti terror laws in anticipation
| of a possible crime.
| nebalee wrote:
| The most notable recent _political_ prosecution would be
| the Lina E. trial:
| https://en.wikipedia.org/wiki/Trial_of_Lina_E.
| elikoga wrote:
| [flagged]
| swader999 wrote:
| You're kind of making their point.
| troft wrote:
| [flagged]
| hedora wrote:
| Most of the comments suggest strange conspiracy theories, but the
| traffic is an exponential ramp (drive into 2023). Also, there has
| been rapid growth in some neighboring countries.
|
| It could be organic growth. There have apparently been a few
| wiretapping scandals this year; people may be using it to access
| Ukraine/Russia, and a bunch of laws passed last year that
| incentivize US companies to block EU traffic (to avoid fines for
| data leaks).
|
| Any of those seem more plausible than a single actor renting a
| rack or dc in one country, and using tor to try to evade
| detection.
| wonderwonder wrote:
| [flagged]
| Zeratoss wrote:
| Please don't believe any old propaganda you here about Germany.
| You can browse "anti-immigrarion" Websites as much as you want
| FinnKuhn wrote:
| Interestingly a similarly drastic increase in German Tor clients
| also happend back in 2017:
| https://www.chip.de/news/Raetselhafter-Nutzeranstieg-Zahl-de...
|
| if you configure the graph to show more years you can see the
| similarities: https://metrics.torproject.org/userstats-relay-
| country.html?...
___________________________________________________________________
(page generated 2023-07-02 23:01 UTC)