[HN Gopher] Drastic increase in Tor clients from Germany
       ___________________________________________________________________
        
       Drastic increase in Tor clients from Germany
        
       Author : akyuu
       Score  : 248 points
       Date   : 2023-07-02 10:29 UTC (12 hours ago)
        
 (HTM) web link (metrics.torproject.org)
 (TXT) w3m dump (metrics.torproject.org)
        
       | RobotToaster wrote:
       | China has the great firewall, the UK has Hadrian's firewall, I
       | guess this is the Berlin firewall.
        
         | circuit10 wrote:
         | As someone from the UK I've never seen anything blocked on my
         | home Internet (except actual scam sites but you can turn that
         | off, and yes that's from my ISP and not the browser)
         | 
         | My mobile data does incorrectly flag some things as 18+ though
        
           | wonderwonder wrote:
           | Are you required to provide doxxing personal information
           | proving your age on these sites or can you browse
           | anonymously?
        
             | circuit10 wrote:
             | Only on my mobile data. They're not actually 18+ sites
             | though, for example someone's blog that was posted here is
             | blocked and it seems the Tor site is too
             | 
             | But I think that's a Vodaphone thing rather than a UK thing
        
               | wonderwonder wrote:
               | So private companies are able to decide the websites
               | their customers are allowed to access?
        
             | infinityio wrote:
             | No - the law that may end up requiring that is a proposal
             | that is at least several months from being enacted [0],
             | although it's been gaining momentum for several years - so
             | unfortunately is looking like it might actually happen
             | 
             | [0] https://www.bbc.co.uk/news/technology-6606560
        
               | wonderwonder wrote:
               | Is there concern in the press with the state having
               | access to this data and using it to leverage individuals?
        
           | concordDance wrote:
           | I've seen a lot of things blocked, e.g. sci-hub
        
           | wsintra2022 wrote:
           | Sky and Virgin Media would often block sites I was trying to
           | access, before I bought a vpn service. So yes the UK ISPs do
           | block sites.
        
           | rotanibmocy2 wrote:
           | Ugh I have news for you
        
           | RobotToaster wrote:
           | Plenty of high seas sites are blocked.
        
       | iguana_lawyer wrote:
       | Looking at the chart it seems to line up with the war in Ukraine.
       | Germany was a target of Prigozhin's Internet Research Agency
       | (troll farms). I wonder if we will see a drop in Tor usage now
       | that his coup has failed and his organization is being dissolved.
        
         | viraptor wrote:
         | I think you're missing the last week of that chart. The huge
         | influx happened very recently, not months ago.
        
           | wiz21c wrote:
           | yet maybe ukraine's services are using tor for some of their
           | communications ?
        
       | fefe23 wrote:
       | Could these be attempts at data mining for unmasking Tor users?
        
         | wood_spirit wrote:
         | Back in 2017 the German BND was revealed to have a history with
         | that: https://netzpolitik.org/2017/secret-documents-reveal-
         | german-...
        
           | ChuckNorris89 wrote:
           | I would be shocked if any intelligence service in the world
           | wouldn't have their hands in that, even in the most respected
           | democracies. Infiltrating "underground" networks and
           | communities, and breaking encryption, is literally their job.
           | 
           | Especially now that there's a war on our borders, the spooks
           | have a plethora of reasons to use to justify their
           | invasiveness.
           | 
           | We just need to make sure to keep them accountable, which is
           | the tricky part, as their work is always classified and our
           | human and privacy rights often clash with their jobs, so
           | unless any whistleblower comes through we might never know
           | the extent of their rule breaking.
        
         | Grimburger wrote:
         | Seems most likely, either by academics or government.
         | 
         | Not really the most subtle way about it though and likely to
         | face some response.
         | 
         | I'd assume both have the capability to run a fairly accurate
         | simulated network without anyone noticing so it's a bit
         | strange.
        
           | reaperman wrote:
           | Could it be someone using Hetzner?
        
           | Blahah wrote:
           | I doubt it's either of those - it would be extremely
           | unethical and illegal for academics to do, and governments
           | don't need to take this approach because they have a bunch of
           | systemic attacks that are less obvious. Perhaps someone with
           | a botnet looking to sell unmasking, which has been popping up
           | as a service recently. Or trying to use it against a specific
           | DWM or vendor.
        
             | Grimburger wrote:
             | Mentioned it because there's been many papers which
             | specifically used the live network to do such a thing
             | already. Some researchers have spun up large numbers of
             | relays in the past to conduct their work.
             | 
             | I personally don't see how it's unethical for either
             | academics or governments to do this? Both have an interest
             | in breaking tor, even when in the governments case where
             | they both utilise it and want to know who else is using it.
             | 
             | The tor people themselves acknowledge the work in their
             | blogs
             | 
             | https://blog.torproject.org/research-problem-measuring-
             | safet...
             | 
             | https://www.researchgate.net/publication/314521450_Characte
             | r...
        
             | PrimeMcFly wrote:
             | > it would be extremely unethical and illegal for academics
             | to do
             | 
             | Nothing illegal about it.
        
               | carstenhag wrote:
               | Hugely depends on the country. Don't assume the law you
               | know, to apply here
        
               | PrimeMcFly wrote:
               | Can you give just one example of a country with a law
               | making it illegal for academics conducting research to
               | attempt to demask tor users?
        
               | deely3 wrote:
               | EU? Basically researchers tries to get PII from people
               | connected to Tor without consent of these people.
        
               | PrimeMcFly wrote:
               | That's an interesting argument. Not sure it would hold
               | up. I don't think an IP alone counts as PII, since the
               | ISP would have to be queried to actually get any contact
               | info.
        
               | thissitesucks__ wrote:
               | [dead]
        
               | addandsubtract wrote:
               | IP addresses are PII under GDPR.
        
               | PrimeMcFly wrote:
               | Not by themselves, surely?
               | 
               | Even so, GDPR has research exemptions which would protect
               | the academics doing research in the example being
               | discussed.
        
               | [deleted]
        
               | Blahah wrote:
               | There is, because it's a botnet
        
               | PrimeMcFly wrote:
               | That would likely make researching and demasking the
               | entities involved explicitly _legal_.
        
               | Blahah wrote:
               | My claim is that researchers are unlikely to be operating
               | the botnet
        
               | PrimeMcFly wrote:
               | I don't think anyone claimed or implied otherwise?
        
               | Blahah wrote:
               | The original comment raised the possibility that
               | researchers or the government were responsible for the 2m
               | new tor users
        
             | flangola7 wrote:
             | What is unmasking? What does it have to do with a botnet
        
               | hattmall wrote:
               | Revealing the identities of tor users or hidden services.
               | One way to do it is by controlling a large share of the
               | network.
        
               | kobieyc wrote:
               | Yes but this clients, not nodes. So this actor does not
               | control a large share of the network, they just use a
               | large share of the network.
        
         | topynate wrote:
         | It's not clear to me how you'd do that with clients, rather
         | than relays.
        
           | hattmall wrote:
           | DDOS a hidden service and track the request spike through
           | your exit nodes. I think this is how the original silk road
           | was investigated.
        
             | thissitesucks__ wrote:
             | [dead]
        
         | yunohn wrote:
         | It's quite an interesting spike, though I doubt that such an
         | operation would be so obviously.
        
         | treprinum wrote:
         | Would regularly changing circuits/identities mitigate this?
         | E.g., pressing ctrl/cmd + shift + L every few minutes?
        
         | frankfrankfrank wrote:
         | [dead]
        
       | V__ wrote:
       | There is no way these are organic users. Could it be, that some
       | VPN is using Germany as an entrypoint?
        
         | sparkling wrote:
         | Why? VPN users mostly care about the Exit IP country, not the
         | Entry IP country.
        
           | hedora wrote:
           | Some VPNs have a "then connect to tor" option for extra
           | anonymity against malicious tor entrypoints and against your
           | local ISP seeing that you are browsing tor [hosted sites].
        
         | FinnKuhn wrote:
         | Could be that someone is using a Cloud Provider in Germany, for
         | example Hetzner
        
           | sparkling wrote:
           | Doubt it. Hetzners smallest machine is something like
           | $4/month, additional IPv4 addresses come with extra cost.
           | They have quite tight service quotas, and this 2M additional
           | IPs would be almost their entire IPv4 pool.
        
             | moooo99 wrote:
             | I don't know about the details, but I know Hetzner has
             | quite a backstory with their servers being abused by
             | spammers. I don't know how the state is today, but maybe
             | it's not as unlikely as it seems?
        
               | withinboredom wrote:
               | If they even think you are spamming, you get banned.
               | Pretty much closed to individuals (according to Reddit,
               | if they don't even like the way your ID looks, you're
               | banned) while businesses get more leeway to do things.
        
               | moooo99 wrote:
               | I didn't realize they're that strict. I have an
               | individual account with them I occasionally use and
               | didn't encounter any issues with ID (I can't even recall
               | being ID'd tbh). That being said, I am located in Germany
               | and have a German billing address, so maybe international
               | customers have more issues?
        
               | CryptoBanker wrote:
               | They're not closed to individuals. I've run two VPSs on
               | Hetzner cloud for 2 years now...
        
               | reaperman wrote:
               | No one I know has had issues like that. They also don't
               | spam, but Hetzner is generally considered in ny circles
               | to be a pretty newbie-friendly service especially for
               | people looking to use basic baremetal machines. Maybe
               | we've just gotten lucky, or maybe we all hail from the
               | right geographies.
        
               | withinboredom wrote:
               | Those machines are pretty nice though. Great for "base
               | load" (handling the scale you almost never go below).
        
               | abdullahkhalids wrote:
               | I have an account with them for my website/email. No
               | problems. Even asked them to open up the IP for SMTP
               | requests and they asked how many emails I wanted to send
               | per month, and I told them it was my personal email and
               | less than 100/month. They happily granted me access.
        
             | FinnKuhn wrote:
             | Hetzner was just an example, because they are a well known.
             | Interestingly a similar sudden increase of German Tor users
             | also happend in 2017:
             | https://www.chip.de/news/Raetselhafter-Nutzeranstieg-Zahl-
             | de...
             | 
             | Hetzner (and other German entities) seem to operate quite a
             | few relays though:
             | https://metrics.torproject.org/rs.html#aggregate/as not
             | sure if this might have something to do with it...
        
               | jacooper wrote:
               | They don't operate the relays themselves, rather users
               | install relays on hetzner vpses/servers.
        
       | curiousfab wrote:
       | From an average of significantly below 500k to almost 2.5M users.
       | This drives up the global number of connecting users from approx.
       | 3M to almost 5M.
       | 
       | Hard to imagine that so many people in Germany suddenly switched
       | to TOR, especially since there has not been any significant event
       | lately that may have triggered such a decision (afaik)?
       | 
       | My personal experience with TOR (as an administrator of various
       | websites and services) is that it is a major source of
       | unwanted/malicious traffic (spam, etc.) and most of it is
       | automated. The big increase is probably not users but bots?
        
         | supriyo-biswas wrote:
         | I faced a recent distributed attack averaging 20,000 RPS[1]
         | around the same time which makes me think that there might be a
         | bot. I wonder if there's a network of website operators similar
         | to NANOG or the RIPE NCC mailing lists where I could compare my
         | own experience with those of other operators.
         | 
         | [1] https://news.ycombinator.com/item?id=36561930
        
           | hartator wrote:
           | Why not CAPTCHA protect these pages instead of blocking tor?
           | Same attack can go through regular web.
        
             | supriyo-biswas wrote:
             | I already have per-IP ratelimiting, and I'm against using
             | captchas have bad UX (including the much-hailed Turnstile).
             | 
             | I'll probably migrate to some proof-of-work based schemes
             | and some algorithms to detect anomalous requests, but it
             | would require some engineering work on my part (for a free
             | website FWIW), and the quickest way to mitigate it would be
             | to block Tor.
        
               | thissitesucks__ wrote:
               | [dead]
        
               | hedora wrote:
               | IP blocking blocks most of the people on our local ISP.
               | They are small, and use CGNAT, so one owned windows
               | machine across town breaks sites like yours for everyone,
               | and the root cause is extremely difficult to debug for
               | end users.
               | 
               | As much as I deeply, deeply dislike captchas, ip blocking
               | is far worse.
        
               | sweetjuly wrote:
               | IP blocks also just don't work on IPv6. Unless you're
               | prepared to block entire by ASN, an adversary can cheaply
               | just buy up a lot of address space and churn through
               | them. It gets even messier when dealing with real ISP
               | networks because some hand out /40s for residential
               | customers whereas others give just a /56.
        
               | RobotToaster wrote:
               | >I'll probably migrate to some proof-of-work based
               | schemes and some algorithms to detect anomalous requests,
               | but it would require some engineering work on my part
               | 
               | Have you tried mcaptcha?
               | https://github.com/mCaptcha/mCaptcha
        
           | lionkor wrote:
           | If there isn't, lets make one. We could self host it, lock it
           | down to invite-only.
        
         | mistrial9 wrote:
         | do you believe these numbers?
        
           | [deleted]
        
           | j16sdiz wrote:
           | It would be much helpful if you could provide one or two
           | reasons why the number could be wrong.... or maybe make some
           | comments on the methodology, etc..
           | 
           | Just question about the accuracy without any context or
           | reasons are not contributing to the argument.
        
             | passers wrote:
             | [flagged]
        
               | ilyt wrote:
               | [flagged]
        
               | passers wrote:
               | [flagged]
        
               | [deleted]
        
               | [deleted]
        
               | [deleted]
        
               | [deleted]
        
         | riedel wrote:
         | The interesting question is if there is a bot net spreading in
         | Germany since the 17th of June. What would be the likelihood of
         | that going undetected. If you like conspiracy theory, the rise
         | in one country could point to state actors.
        
           | WarOnPrivacy wrote:
           | > The interesting question is if there is a bot net spreading
           | in Germany since the 17th of June.
           | 
           | A minor addendum: Looking at the csv file, it looks to me
           | like traffic began drifting above the mean about June 6. From
           | there I see a ramp-up, growing at an increasing rate.
        
             | layer8 wrote:
             | That's when the Kakhovka dam was destroyed, shortly after
             | the Ukrainian counteroffensive began.
        
           | tw04 wrote:
           | Off the top of my head - Germany hosts a disproportionate
           | amount of sensitive data because it's the location of choice
           | for cloud providers storing things for EU member countries.
           | They have lots of fiber, lots of ISPs, plenty of datacenter
           | space, a stable government, and data security laws that meet
           | or exceed everyone else in the EU.
        
           | ballenf wrote:
           | Why would it be so localized to one country? Does Germany
           | have a unique enemy compared to other NATO countries?
        
             | aeyes wrote:
             | My guess is that a certain router is getting infected with
             | a botnet because ISPs usually hand out the same router to
             | their customers. And ISPs are usually limited to a single
             | country.
        
               | riedel wrote:
               | That would be an explanation and probably by okhams razor
               | be more likely. But wouldn't that ISP notice the
               | difference in traffic patterns drastically and react? It
               | is just unlikely (but far from impossible) that this is
               | something 'normal' happening.
               | 
               | My fear would be that someone still is trying to gather a
               | critical mass of nodes to contact controll servers via
               | TOR to cause mass havoc in a single country from within a
               | single country. Generally IMHO Germany would be a good
               | target for destabilisation currently. But I think and
               | hope this could just a bit of overinterpreting. Probably
               | one would need a good statistic on the subnets the users
               | come from.
        
               | eitland wrote:
               | > That would be an explanation and probably by okhams
               | razor be more likely. But wouldn't that ISP notice the
               | difference in traffic patterns drastically and react?
               | 
               | I hope to be wrong but I am afraid you are overestimating
               | the technical competency of the average ISP.
        
               | NoZebra120vClip wrote:
               | I can't speak to German ISPs or anyone outside of these
               | USA. But I believe that ISPs are absolutely the weakest
               | link when it comes to malicious botnets and other types
               | of widespread network-based compromises.
               | 
               | ISPs certainly have the tooling and the positioning to be
               | able to detect C&C channels, outgoing DDOS attacks, and
               | compromised customer premises equipment. But do they? And
               | if they do detect any of it, do they take action? When is
               | the last time you heard about an ISP disconnecting a
               | paying customer because of the customer's compromised
               | device(s)? When is the last time you even heard of an ISP
               | notifying a customer about such a thing?
               | 
               | Two months ago, my router was compromised and joined to
               | some sort of botnet in the capacity of a DNS resolver. I
               | would never have been able to detect such WAN-side
               | traffic if I hadn't had a special setup on my part. My
               | ISP was the first to hear when I'd detected it, and I
               | sincerely doubt that they receive many such reports,
               | especially with logs as evidence.
               | 
               | Can you imagine receiving a phone call, "Hello, this is
               | your ISP! You're pwned! Please follow through these
               | remediation steps as I prompt you: ..." You'd undoubtedly
               | think it was a phishing scam. Because ISPs just don't
               | seem to care about abuse.
               | 
               | They will send you copyright strikes and prosecute you
               | for BitTorrent, but it does't seem like they'd lift a
               | finger to prevent the next big DDOS or spam factory
               | originating from their own customers.
        
               | zirgs wrote:
               | My ISP actually sent me an email that said that one of my
               | devices have an open TCP 445 port and advised me to fix
               | it. Apparently Windows opens it by default and it can be
               | exploited by some malware.
               | 
               | But I've never received a threatening letter about
               | piracy. ISPs in my country simply don't send those.
        
               | NoZebra120vClip wrote:
               | Many ISPs have clauses in their TOS that prohibit running
               | any server of any kind. So it may be the case that your
               | ISP regularly runs sweeps to detect customers who are
               | running servers, and this warning may be a side effect of
               | that sweep.
               | 
               | I often used to poke holes in my firewall and run VPN or
               | ssh servers that were discoverable using my dynamic DNS
               | service. My ISP never got involved with that. Of course,
               | that was a case of me running a server for my exclusive
               | use, rather than some sort of public web or login server
               | that would have randos sending traffic across my link.
        
               | ZalorCakeLord wrote:
               | My ISP will send letters or emails, but only if they get
               | a complaint from the company in question. Usually what
               | ends up happening is a company watches a torrent, and
               | takes down a list of all the ip addresses downloading it.
               | They then send boilerplate complaints to the isps
               | associated with said ip addresses, who are legally
               | required to do _something_ about it. My little brother
               | got in trouble this way lmao, they sent a letter to our
               | house about it.
        
               | iforgotpassword wrote:
               | In Germany, I doubt they have the tooling or staff
               | anymore. For almost a decade we've been in a race to the
               | bottom regarding pricing and as a result, service
               | quality. I wouldn't be surprised if critical parts of the
               | infrastructure are maintained by outsourced jobs from
               | half around the world.
               | 
               | The only somewhat professional player is the Deutsche
               | Telekom, which was kinda the Bell of Germany and got
               | privatized in the 90s, when the phone network was also
               | opened to other players. They are more expensive though.
               | Other than that, you might be lucky and have some small
               | regional ISP that's competent enough. Otherwise there are
               | just two other companies left that offer service
               | nationwide, after a lot of mergers.
        
               | Fatnino wrote:
               | My parents home lan got caught up in a bot net and their
               | isp was sending emails about it to their isp provided
               | email address.
               | 
               | But it's possible they were just passing on abuse reports
               | from the numerous targeted victims of this botnet who
               | bothered to complain.
               | 
               | The intrusion point was a Linux system with a 3 letter
               | password and ssh exposed on a nonstandard port. So if
               | you're someone who still thinks the bad guys won't find
               | your computer because you changed the port, know that
               | that is very outdated thinking.
        
               | SoftTalker wrote:
               | I don't even know how to log in to my ISP provided
               | email., so it goes without saying that I'm not reading
               | it. I'm surpised that ISPs still offer email.
        
               | [deleted]
        
               | WarOnPrivacy wrote:
               | > My guess is that a certain router is getting infected
               | with a botnet because ISPs usually hand out the same
               | router to their customers.
               | 
               | This seems trivial to figure out with an analysis of the
               | connecting IPs - which is absent on TOR's report page.
               | 
               | I'm also a bit confused why no one here on HN has asked
               | about the connecting IP data (at this writing). Are these
               | commercial IPs, dynamic (biz/residential) IPs or a mix?
               | If they're mostly dynamic IPs, are they from more than
               | one ISP?
               | 
               | TOR has country of origin data so it seems reasonable
               | they'd also have network of origin.
               | 
               | All that said, I don't precisely know how TOR determines
               | country of origin. Entry node data would seem to be the
               | likely source. However I've long assumed that entry nodes
               | are public supplied, like Relay and Exit nodes. Within
               | that assumption it isn't clear to me how that data would
               | flow to TOR - while maintaining anonymization of traffic.
        
             | mantas wrote:
             | Maybe German state itself is the actor.
        
               | tetris11 wrote:
               | My bet is Russia.
               | 
               | I work in a German institution. I was recently hacked by
               | such a botnet recently (lessons learned: use
               | AuthorizedKeys, allow only one SSH user, proxy all http
               | connections to a webhoster, and check your SSH and UFW
               | logs often!)
               | 
               | It setup a virtual environment where it downloaded some
               | kind of Tor node and ran some sort of code that used 100%
               | of my CPU. My guess is crypto-mining. I purged the
               | account, deleted everything before I could do forensics,
               | but I checked the logs for the connections and they all
               | came from Russia.
        
               | hedora wrote:
               | What state actor doesn't understand statistical
               | deanoymization attacks against tor?
               | 
               | (e.g., if you single-handedly double the network traffic,
               | then an outside observer can figure out what
               | ingress/egress traffic is yours)
        
               | mantas wrote:
               | Why pay attention to this if you can simply blame another
               | state actor?
               | 
               | And German federal government have a history for covert
               | shitposting.
        
         | theonlybutlet wrote:
         | Any UX changes to something like Brave browser perhaps? Making
         | it easier to use tor mode. Although this is a big jump.
        
         | [deleted]
        
         | throwaway290 wrote:
         | Note that the growth is not just in Germany. Ireland, Sweden,
         | Switzerland also show jumps (however in absolute terms they are
         | still much smaller). I would not rule out it's people or bots
         | connecting from third country/countries through VPNs based in
         | Europe... for whatever reason.
        
           | ncr100 wrote:
           | Is it a bug in a client that accidentally spawns sub-clients?
        
           | doubleorseven wrote:
           | VPSs in germany are much cheaper. But I'm guessing this
           | increase is paid with crypto or debit cards so pin pointing
           | it to a specific provider like hetzner is hard
        
             | rurban wrote:
             | Hetzner used by criminals would be my guess.
        
         | aaron695 wrote:
         | [dead]
        
       | netsharc wrote:
       | Maybe related to the Proto-Nazi party AfD winning a district a
       | few days ago. And this 5 day old news story:
       | https://www.politico.eu/article/germany-far-right-afd-securi...
       | "Germany's far-right AfD placed under security service
       | surveillance" - "The party is now treated as a 'suspected case'
       | for far-right extremism".
       | 
       | I wonder if anyone can see inside the right-wing chat networks
       | and if they've been mentioning Tor.
       | 
       | Although in the raw CSV's the spike started around mid-June...
        
         | oaiey wrote:
         | That is not sufficient in total numbers. That would be in the
         | press that a whole part of the population goes Tor. They would
         | never be quiet enough about it.
         | 
         | Looks anorganic and if it is organic I bet for Netflix and co
         | related.
        
         | 0xDEF wrote:
         | As a Danish person who has been to Eastern Germany (outside
         | Berlin) I'm really not surprised by the rise of the AfD. It's
         | common to see people on social media praise Germans for de-
         | Nazification and criticize the Japanese for not confronting
         | their past in the same way. Those people have clearly not
         | interacted with Eastern Germans. In Eastern Germany the
         | underlying neuroticism, persecution complex, and willingness to
         | believe in every conspiracy theory, things that were
         | foundational for the rise of Nazism, is very much still alive.
        
           | hgadx wrote:
           | [flagged]
        
             | gmerc wrote:
             | Please you are whitewashing history. Hoyerswerda gruesst.
             | This shit was happening already in the 90s right after
             | reunification and in the context of OP - it's not
             | surprising at all, eastern germany had a very different
             | take on denazificaiton.
        
               | hutzlibu wrote:
               | "eastern germany had a very different take on
               | denazificaiton."
               | 
               | As opposed to the BRD, where for example the "Auswartiges
               | Amt" had more ex NSDAP party members after 1945 than
               | before?
               | 
               | There definitely was denazification in the east, but the
               | totalitarian enclosed and literally walled of mindset did
               | not help with creating an open mind towards the world.
               | Add to that high unemployment and poverty after 1990 and
               | you get the usual extremists on both sides of the
               | spectrum.
        
               | gmerc wrote:
               | You will notice I did not say Western Germany was great
               | at it. Different.
        
               | hutzlibu wrote:
               | I noticed, but in the context it seems to imply a worse
               | take.
        
               | nbryc wrote:
               | [flagged]
        
               | gmerc wrote:
               | Because at the time that SED follow up was still binding
               | the Nazi vote.
        
           | virtualritz wrote:
           | I don't know why this is getting down voted.
           | 
           | Poster didn't say it's rampant, just that "it is very much
           | alive."
           | 
           | I'm German, I live in Berlin, I regularly spend time in
           | eastern Germany, outside Berlin. I can sadly confirm this.
        
             | joeythedolphin wrote:
             | Can you say more about East Germany and what is going on
             | there for them to be open to conspiracy theories, neurotic
             | thoughts, etc?
        
               | lyu07282 wrote:
               | Disenfranchisement, after reunification they were left
               | with little generational wealth, liberalism spiraled them
               | deeper into a hopeless situation, no jobs, no economic
               | future, impoverishment. Under liberalism the only
               | alternative offered to them is the far right.
               | 
               | During the cold war and after, the US and anglosphere was
               | mostly interested in the destruction of left ideology,
               | labor unions, left parties etc. were all targeted. The
               | right offers a safe outlet for people with those
               | grievances, it doesn't threaten capital, so it was always
               | allowed to linger in Germany not just in the east. It's
               | deeply rooted in establishment and civil organizations,
               | in university fraternities (schlagende verbindungen, the
               | CSU etc.). The allied supported and used and bolstered
               | far right groups all around Europe (Gladio, NSU, etc.) in
               | their fight against socialism and people on the left. We
               | still feel the effects to this day and state and federal
               | police and intelligence still operate this way.
               | 
               | Protests in Germany you see police protecting far right
               | groups from leftists, not the other way around. It's a
               | necessary aspect of liberalism to allow the
               | disenfranchised the outlet into right wing extremism.
        
               | niemandhier wrote:
               | The german lands east of the river Elbe have been
               | different from the western parts of Germany for more than
               | a 1000 years. In the historical record you see a pretty
               | sharp change in marriage patterns,land ownership and
               | political structure when crossing the Elbe.
               | 
               | The enlightenment was less influential in the rural
               | estates of the ultra conservative east elbian
               | Junkernklasse than it was in the more densely populated
               | Rhineland regions. Fukuyama has a nice chapter on the
               | matter in "The Origins of Political Order".
               | 
               | On top of that you have the separation, and the dislike
               | of the GDR to foster critical thinking and the economic
               | collapse of the east after reunification that lead to a
               | lot of brain drain.
        
           | suction wrote:
           | [dead]
        
           | Jibbedeyeah wrote:
           | [flagged]
        
           | RobotToaster wrote:
           | Hardly surprising, treuhand left east Germany extremely poor.
        
             | nebalee wrote:
             | The unification wasn't exactly free. The immense costs for
             | the most part were shouldered by western citizens through
             | the Solidaritatszuschlag. The total price tag is estimated
             | to be between 0.95 and 2 trillion Euro (https://de.wikipedi
             | a.org/wiki/Kosten_der_deutschen_Einheit#R...).
        
       | joeythedolphin wrote:
       | It could be INTERPOL
        
       | concordDance wrote:
       | Does anyone understand the mass flagging and downvotes going on
       | in this comment section? I'm very confused as I've never seen
       | anything like it.
        
         | chippy wrote:
         | I'm guessing that there is some automatic system that works on
         | certain words in comments. Flame detection has been mentioned
         | before. Probably in combination with account age or karma. I
         | also imagine that users vouching for these might offset the
         | behaviour.
        
           | MrStonedOne wrote:
           | If the number of comments in a post or subthread exceeds the
           | upvotes, this leads to the flame detector activating.
           | 
           | But also some accounts are just banned.
           | 
           | Banned accounts can still comment, but they start dead and
           | have to be vouched first before showing to anybody who didn't
           | enable showdead in their profile.
        
         | maze-le wrote:
         | Just the usual political flamewar that happens here from time
         | to time, not sure why it escalates on some threads and not on
         | others though.
        
           | Andrex wrote:
           | Probably the posters involved. Blessing and a (minor) curse
           | that HN doesn't use avatars. Harder to avoid commenters you
           | know you don't like.
        
           | [deleted]
        
         | systemvoltage wrote:
         | [flagged]
        
           | nebalee wrote:
           | > Germany is blocking news from French riots.
           | 
           | What are you on about? The riots in France are on pretty much
           | every news site in Germany.
        
             | systemvoltage wrote:
             | [flagged]
        
             | systemvoltage wrote:
             | More here: https://www.reddit.com/r/2westerneurope4u/commen
             | ts/14nx7v5/t...
        
         | RobotToaster wrote:
         | If you click the timestamp there should be a "vouch" button for
         | comments to restore them.
         | 
         | It's quite annoying, possibly NAFO or similar.
        
       | 19h wrote:
       | ,,These estimates are derived from the number of directory
       | requests counted on directory authorities and mirrors."
       | 
       | Depending on how these numbers are obtained, there is a non-zero
       | chance at least part of this increase is caused by us.. note that
       | this number is not indicative of the amount of users or origins
       | (i.e. physical source addresses), but only count directory
       | requests.
        
       | Havoc wrote:
       | Plausible options seem to be malware, another attempt to crack
       | tor by enforcement or some sort of app that added tor browsing
        
       | tarcon wrote:
       | From around September 2022 to March 2023 media in Germany
       | promoted the Snowflake Browser Extension
       | (https://addons.mozilla.org/de/firefox/addon/torproject-snowf...)
       | to help Iranians circumvent censorship. Is this a possible
       | explanation?
        
       | Jibbedeyeah wrote:
       | [flagged]
        
         | Moldoteck wrote:
         | [flagged]
        
       | VWWHFSfQ wrote:
       | [flagged]
        
         | snacktaster wrote:
         | It's amusing to me that you're getting crushed on here for
         | blocking/ "defederating" known IPs that you don't want traffic
         | from, but I would bet that these same people would champion
         | your right to do the same if you were blocking a spammy
         | mastadon or lemmy instance that you didn't like!
        
           | computerfriend wrote:
           | It's not hypocritical. They have every right to block Tor
           | traffic. I don't want them to do it, but also don't want them
           | to lose the right to do it.
        
         | belorn wrote:
         | I constantly use tor as a way to get a third view when
         | debugging connection issues for customers and malware infected
         | websites. If you ever experience the issue of a customer saying
         | they can't connect, but when you test it it works perfectly
         | fine, tor is great to verify if the issue might effect more
         | customers. As a side effect of it being ipv4 only, you can also
         | test issues when one protocol work but not the other (there are
         | alternative tools but tor is by far easiest at hand).
        
           | tg180 wrote:
           | Tor hasn't been IPv4-only since a long time
        
             | teddyh wrote:
             | True, but most exit nodes are IPv4-only, so in practice it
             | works.
        
         | jeroenhd wrote:
         | The traffic my servers receive from China, India, South
         | America, Africa, and Eastern Europe, and the UK is also almost
         | exclusively boys and exploit scanners.
         | 
         | You can block whatever IP addresses you like but the bot to
         | user ratio of any given IP address is absolutely terrible. Tor
         | concentrates a lot of traffic into a few exit nodes but by this
         | logic most small countries should be blocked from most
         | websites.
        
         | isoos wrote:
         | I use tor for exploring topics that I don't want to tie to my
         | regular profile (ranging from professional software
         | development, through health care issues, but also hobbies,
         | fiction and nsfw content). Having these browsing in a separate
         | profile and also IP address makes it much more relaxed to look
         | for interesting stuff on the internet. (I am not really fond of
         | advertisement that tries to sell me whatever I've visited in
         | the past month, on unrelated pages.)
         | 
         | It saddens me that the default response is ban, increasingly so
         | for services that need account, but even just reading a webpage
         | can become tedious or impossible :(
         | 
         | Please, do not ruin this option, because even though you may
         | not use it today, you may need it in the future.
         | 
         | Note: I also use tor for low volume crawling. When high volume
         | is needed, it is more favorable to subscribe for domestic VPN
         | proxies, so you may be blocking tor, but you won't block those
         | ranges, and the robots will get their content anyway.
        
           | bauruine wrote:
           | Whenever I read something like this I look my access and sshd
           | logs for abuse IPs and check if they are Tor exit nodes. The
           | Tor traffic is always negligible like 100 failed ssh logins
           | out of 170k are from Tor exit nodes. Or 670 out of 400k for
           | my nginx access.log. Am I unique and everyone else sees
           | vastly different numbers where blocking Tor exits makes a
           | significant difference in the abuse they get?
        
             | isoos wrote:
             | I don't really care if somebody blocks a random port of
             | sshd. I just don't understand why people are eager to block
             | public https traffic, which is exposed to the public
             | internet anyway.
        
           | supriyo-biswas wrote:
           | Well, I've always tried to make my service available through
           | Tor, but now that I faced an attack of 20,000 RPS distributed
           | over all the exit nodes of the Tor network making requests to
           | a computationally expensive (and non-cacheable) endpoint, and
           | came out with 6x the hosting bill I usually get, I decided to
           | block the entire network.
           | 
           | Maybe there's an alternative reality where people do the
           | right thing, and in that world I wouldn't have to block Tor,
           | but I don't live in that world.
        
             | isoos wrote:
             | Shouldn't you protect that endpoint, regardless of the
             | traffic coming from tor or not? It is really cheap to get
             | traffic through domestic VPN proxies, so a dedicated
             | attacker will get to it anyway...
        
           | ilyt wrote:
           | There is no reason to allow Tor IPs on most sites sadly. The
           | abuse it is used for far exceeds legitimate traffic
        
           | VWWHFSfQ wrote:
           | > Please, do not ruin this option
           | 
           | I don't believe that I'm the one that ruined this option for
           | you. Small web hosts simply don't have the capacity, budget,
           | or patience to deal with the 95% garbage originating from
           | these IP addresses. Tragedy of the commons, I guess.
        
         | justinclift wrote:
         | Probably depends on what kind of service you're providing.
         | 
         | I (a legitimate user) get blocked on websites when using Tor
         | quite a lot. It's a pita. :(
         | 
         | That being said, there's no chance in hell I'd ever put a CC or
         | similar private info though a Tor based network connection.
         | Just in case... ;)
        
           | CaptainFever wrote:
           | > That being said, there's no chance in hell I'd ever put a
           | CC or similar private info though a Tor based network
           | connection. Just in case... ;)
           | 
           | For HTTPS sites, why?
        
             | justinclift wrote:
             | Paranoia. :)
        
         | Santosh83 wrote:
         | Have used Tor for accessing the Z-library and several other
         | cases where sites where blocked or taken down. Not all of Tor
         | is dark web shadiness or bots.
        
         | ipaddr wrote:
         | How would you know if they are legitimate if you block them.
        
         | 31337Logic wrote:
         | Wow, that's terrible, for reasons already explained to you
         | below. Please reconsider.
        
           | VWWHFSfQ wrote:
           | No the IP blocks are very effective. I don't believe that I
           | have any obligation whatsoever to allow criminal groups on
           | the other side of the world to spam burp suite scans over Tor
           | against my websites nonstop.
        
       | wood_spirit wrote:
       | Clicking around and looking at the chart for random other
       | countries shows a spike for Sweden too, whereas Finland has a
       | different but interesting pattern all of its own.
        
         | chronicsonic wrote:
         | Wonder if the fact that they're related to NATO, who is at war,
         | have anything to do with it.
        
           | lost_tourist wrote:
           | I can think of a country currently at war that has a much
           | more aggressive and longer history of being a bad actor on
           | the internet than NATO countries...
        
           | hnarn wrote:
           | Nato is not at war.
        
           | HumanOstrich wrote:
           | Can you elaborate on this a bit?
        
       | sdsd wrote:
       | The obvious explanation is that German ISP's blocked 711chan, so
       | the onion service is the only way for them to access the site.
       | 
       | Jk, but if you change 711chan to Krautchan maybe it's true
        
         | Havoc wrote:
         | Sudden 2 mill extra isn't organic Chan users
        
       | ulrischa wrote:
       | Germany is blocking a lot of websites ( i.e. rt.com)
        
         | dhoe wrote:
         | But that's been happening for some time already, while this
         | spike is recent.
        
         | Xeophon wrote:
         | Russian-run sites like RT are banned through the whole EU.
         | However, such spikes cannot be seen in other EU countries such
         | as France.
        
           | mr_mitm wrote:
           | I can open rt.com just fine in Germany. (Not using my ISP's
           | DNS server though. It's true that rt.com won't resolve when
           | using it.)
        
           | beebeepka wrote:
           | Lies. I just tried rt.com on my home connection and it opened
           | without a problem
        
           | the_mitsuhiko wrote:
           | Might also depend on how it's enforced. The blocks in Austria
           | basically do not exist because they are only done by carrier
           | DNS servers. Use 1.1.1.1 or 8.8.8.8 and you would not know.
        
             | lxgr wrote:
             | The vast majority of people use their ISP's DNS server,
             | though.
        
               | the_mitsuhiko wrote:
               | I don't think that is relevant here. If in one country
               | you need a VPN to bypass blocking but others you only
               | need a different DNS server I would expect most users to
               | go for the latter if given a choice.
        
           | commandnotfound wrote:
           | I just opened rt.com on my home connection with no tor or VPN
           | and everything worked. I'm physically in the Czech Republic
           | if that matters.
        
             | ChatGTP wrote:
             | I just read on Al-Jazeera that Putin is back in control,
             | that's why :)
        
           | jd_paton wrote:
           | Source? I'm in NL and I can access it just fine. I use
           | Cloudflare for DNS though
        
             | mkl95 wrote:
             | I would say this is the best solution. I live in another EU
             | country where ISPs also block it via DNS.
        
               | PrimeMcFly wrote:
               | No excuse for that censorship honestly.
        
               | flangola7 wrote:
               | Eliminating enemy propaganda is extremely common and a
               | long running practice. It's less censorship and more self
               | defense.
        
               | PrimeMcFly wrote:
               | Looking at it from that perspective it makes a kind of
               | sense, although I think it is less defensible in modern
               | day with the internet.
        
           | [deleted]
        
         | cynicalsecurity wrote:
         | [flagged]
        
           | sparkling wrote:
           | If you think your citizens are vulnerable to being tricked by
           | Russian propaganda, you have a much bigger problem than
           | Russian propaganda.
        
             | tuukkah wrote:
             | Democracy is not immune to the post-truth attacks. Part of
             | it is the existence of Western helpful fools who launder
             | the Russian propaganda.
        
           | 0xDEF wrote:
           | Not really. I preferred the approach of pre-Musk twitter that
           | clearly labeled it as Russian state media. Also banning it
           | had little effect. The war propaganda coming out of Russia
           | was hilariously incompetent.
           | 
           | The real insidious anti-Ukrainian propaganda is coming from
           | pro-Russian Westerners, pre-dominantly the American populist
           | right.
        
           | hutzlibu wrote:
           | And NATO or ukrainian propaganda?
           | 
           | Because that is also a thing, even though not as blatant.
           | 
           | The problem with banning information, is that it is easy to
           | abuse this and it creates a martyr effect. I rather would
           | like people be able to judge information by themself and not
           | decide for them.
        
             | timeon wrote:
             | NATO or Ukraine are not invading any European country.
        
               | hutzlibu wrote:
               | NATO member Turkey is regulary doing raids in Syria and
               | they also annected territory there. And they did not
               | really take it from evil Assad, but from the kurds.
               | 
               | And when 47% of americans believed, that Hussein was
               | responsible for 9/11, than this is also the result of
               | propaganda to create support for a illegal war.
               | 
               | https://en.m.wikipedia.org/wiki/Opinion_polls_about_9/11_
               | con...
        
             | duozerk wrote:
             | > Because that is also a thing, even though not as blatant.
             | 
             | It's far more blatant; like the retraction of the articles
             | - years after their publication - that pointed out the CIA
             | involvement in the regime change in Ukraine in 2014, or the
             | ones outlining the influence of banderites in the same
             | government; along with like 90%
             | (https://theprint.in/tech/60-80-of-twitter-accounts-
             | posting-o...) of the war bots on twitter being pro-ukraine,
             | not pro-russia.
             | 
             | We're (assuming you're in a Western country like me) just
             | seeing it from the inside, so it looks less blatant.
        
               | 0xDEF wrote:
               | The "90% of bots are pro-Ukraine" bullshit report only
               | looked at a handful of hashtags during the first few
               | weeks of the war.
               | 
               | Anyone who has been on twitter knows that pro-Russian
               | disinfo is far more widespread. There are literally viral
               | tweets blaming Ukraine for creating COVID-19.
        
               | duozerk wrote:
               | Looking into it you appear to be right, thanks; that
               | single study is almost exclusively _the_ single source of
               | all similar articles, too. Admittedly I don 't use
               | twitter, so I don't have first hand experience in this.
               | 
               | It's still pretty obvious that there is a propaganda
               | effort from NATO as well, and one that seems to work a
               | lot more than Russia's on western audiences.
               | 
               | > There are literally viral tweets blaming Ukraine for
               | creating COVID-19.
               | 
               | lmao that's so insane it almost sounds like a bit
        
               | hutzlibu wrote:
               | "There are literally viral tweets blaming Ukraine for
               | creating COVID-19.
               | 
               | lmao that's so insane it almost sounds like a bit "
               | 
               | Ah well, people exposed to propaganda can believe all
               | kinds of weird stuff. For example many (43%!) US people
               | believed, that Hussein was responsible for 9/11:
               | "Do you think Saddam Hussein's regime in Iraq was
               | directly involved in planning, financing, or carrying out
               | the terrorist attacks of September 11th, 2001?"
               | September 2003 responses: 47% Yes"
               | 
               | https://en.m.wikipedia.org/wiki/Opinion_polls_about_9/11_
               | con...
        
               | _kbh_ wrote:
               | > lmao that's so insane it almost sounds like a bit
               | 
               | It sounds like a bit but the Russians have some wild
               | state based propaganda stuff like that Ukraine was using
               | mutant super soldiers, that Ukraine had black magic witch
               | battalions and that Ukraine was breading pigeons that
               | where modified to spread viruses to kill Russians.
        
               | hutzlibu wrote:
               | But I also see russian propaganda, so I can compare and
               | confirm it is not at all on the same level.
               | 
               | But if I would not been able anymore to see the russian
               | point of view, then I would start to suspect they have a
               | point I am not allowed to see, to keep me under control.
               | But now I can see it and so I can see that their point is
               | just russian nationalism/empire thinking with zero
               | interest of truth, just power. Full of literal lies. So
               | yes, you also can find lies and manipulation in western
               | reporting. But I have a hard time understanding why
               | anyone can think it is the same.
        
         | aqme28 wrote:
         | Is tor really the go-to workaround for this and not just a VPN?
        
           | reaperman wrote:
           | VPN seems like it would be vastly preferable for performance
           | and reliability.
        
             | BasedAnon wrote:
             | Sure but Tor is free
        
             | jandrese wrote:
             | Yeah, but few VPNs are free, and the ones that are tend to
             | be slow and unreliable due to overloading.
        
               | reaperman wrote:
               | This comprises 40% of all global Tor users. I'm not sure
               | it's reasonable to assume they all wouldn't have the
               | budget for Mullvad.
        
         | Zetobal wrote:
         | - it's dns blocked -
        
           | [deleted]
        
           | sparkling wrote:
           | Uhm...
           | 
           | https://de.wikipedia.org/wiki/Sperrungen_von_Internetinhalte.
           | ..
           | 
           | Edit: parent poster has now changed his post after claiming
           | there was no blocking in Germany
        
       | jacooper wrote:
       | I've noticed VPN severs in Germany to be busier than usual too.
        
       | superkuh wrote:
       | Tor metrics don't really tell you much about the actual human
       | users of the networks. They mostly tell you about current bot/etc
       | usage. It's why inferred tor v3 datarates have been wildly
       | inflated (10gbps) ever since support was turned on in the release
       | binaries despite 99% of human people using tor v2 (at the time).
        
         | Vecr wrote:
         | You've been posting about Onion v3 and "human people" for years
         | at this point, nothing is going to happen. v2 onion addresses
         | are not secure, plain HTTP is not secure unless you run it over
         | Wireguard or IPSec with path filtering and use DNSSEC, and
         | almost no one ever does that.
        
       | brucethemoose2 wrote:
       | Is someone trying to compromise the Tor network?
       | 
       | I read that Tor needs a certain percentage of non-malicious nodes
       | to function, though I am not sure if that is applicable clients.
        
         | TheNorthman wrote:
         | It's not applicable to clients. A clients traffic never touches
         | another client, only the nodes.
         | 
         | Of course, malicious clients can ruin it for everyone else in
         | the form of DoS attacks but that's clearly not happening here.
        
         | chezelenkoooo wrote:
         | I think you're thinking of blockchain
        
           | thissitesucks__ wrote:
           | [dead]
        
           | kadoban wrote:
           | Sybil attacks are more general than just in cryptocurrencies.
           | They actually apply to Tor as well, just not to _this_ part
           | of Tor.
        
           | r4indeer wrote:
           | No, the problem also applies to Tor. If a malicious actor
           | controls large parts of the network, there is a high
           | probability that the attacker controls your entire circuit or
           | at least your entry and exit node.
           | 
           | In the latter case, you can do timing attacks to determine
           | which traffic on the exit node belongs to whom on the entry
           | node.
        
       | golergka wrote:
       | Have something changed in how German police goes after drug
       | dealers? It's the most important use case for Tor anyway.
        
         | [deleted]
        
         | carstenhag wrote:
         | No new law or something was passed, so if at all, it's a
         | technique/method that won't be published.
        
       | tyiz wrote:
       | [flagged]
        
         | ruune wrote:
         | Sounds interesting, do you have a link or something for me?
        
           | jandrese wrote:
           | [flagged]
        
             | spuz wrote:
             | That site doesn't seem to have any stories about Germany
        
               | moooo99 wrote:
               | Honestly, the most notable political prosecution I could
               | think of right now is police in Bavaria prosecuting
               | climate activists under anti terror laws in anticipation
               | of a possible crime.
        
               | nebalee wrote:
               | The most notable recent _political_ prosecution would be
               | the Lina E. trial:
               | https://en.wikipedia.org/wiki/Trial_of_Lina_E.
        
         | elikoga wrote:
         | [flagged]
        
           | swader999 wrote:
           | You're kind of making their point.
        
       | troft wrote:
       | [flagged]
        
       | hedora wrote:
       | Most of the comments suggest strange conspiracy theories, but the
       | traffic is an exponential ramp (drive into 2023). Also, there has
       | been rapid growth in some neighboring countries.
       | 
       | It could be organic growth. There have apparently been a few
       | wiretapping scandals this year; people may be using it to access
       | Ukraine/Russia, and a bunch of laws passed last year that
       | incentivize US companies to block EU traffic (to avoid fines for
       | data leaks).
       | 
       | Any of those seem more plausible than a single actor renting a
       | rack or dc in one country, and using tor to try to evade
       | detection.
        
       | wonderwonder wrote:
       | [flagged]
        
         | Zeratoss wrote:
         | Please don't believe any old propaganda you here about Germany.
         | You can browse "anti-immigrarion" Websites as much as you want
        
       | FinnKuhn wrote:
       | Interestingly a similarly drastic increase in German Tor clients
       | also happend back in 2017:
       | https://www.chip.de/news/Raetselhafter-Nutzeranstieg-Zahl-de...
       | 
       | if you configure the graph to show more years you can see the
       | similarities: https://metrics.torproject.org/userstats-relay-
       | country.html?...
        
       ___________________________________________________________________
       (page generated 2023-07-02 23:01 UTC)