United Arab Emirates goes from 10k Tor users to 250k in days
metrics.torproject.org
metrics.torproject.org
This is a important difference, because if there is active DPI that is shutting down a connection before handshake can happen, it will inflate the numbers massively.
I suspect what actually is happening is a ISP in UAE has deployed a DPI system that can detect the Tor TLS signature
If your theory is correct, then the title is slightly misleading.
I'm not very familiar with TOR, but does this reaffirm what OP is asking, that this might be DPI causing re-connections for TOR in UAE? If so is this a new policy of banning TOR, or is this just a recent ramp up in existing policy?
Another example that comes to mind is the Colorado newspaper headline that crime has "doubled" in the last decade. That leads a person down the train of thought that crime is out of control. In reality, it grew in proportion to the population. The headline, "Crime grows in proportion with population" doesn't evoke gasps and sales of your paper.
And for Turkey: https://metrics.torproject.org/userstats-relay-country.html?...
o In the case of Turkey, they had more than 10k direct users, the DPI-based censorship yielded a 50k spike, that's a 1:5 ratio, whereas in the case of the UAE it's a freaking 1:30 ratio and it doesn't stop from increasing.
o In the case of Turkey, the spike was followed by a spike in bridge use, most using the obfs4 pluggable transport. There's however no such apparent spike for UAE, in fact it's only a nearly constant 300 obfs4 users https://metrics.torproject.org/userstats-bridge-combined.htm...
Wait a week more and we'll see if the same noisy zig-zag pattern appears in unbridged connections that showed up in Turkey. That's the smoking gun.
The wind will come. You must adapt and accept. And if you are against the wind, you must change.
(1) They want to emphasize that there are lots of reasons to use Tor other than political dissidence and that Tor use should be normal or common for lots of people in lots of situations.
(2) They feel like the role of tools like Tor in facilitating political dissidence is overstated and that you were implying that Tor will be crucial or extremely powerful in political conflict situations, rather than, say, hopefully somewhat useful.
edit: (3) They feel like you're overstating how effective political dissidence can be (because having public opinion turn against a government doesn't mean that the government will lose power).
That is my point.
That's an idealistic sentiment that's unfortunately not actually true. There are abundant examples if you look at politics or gambling.
Politics works on a heavily skewed sample of power-hungry people. Politicians are nothing like their people. Most are among the top 1%, which is a weird bunch: they are visible, powerful, don't have the same incentives, and don't live under the same social pressures as the rest of us.
Moreover, they may wish to route traffic through nodes they control.
I understand your point, but then again, I don't see why a botnet would route it's traffic through the UAE either.
[0] : http://imgur.com/a/mjYsP
[1] : http://gizmodo.com/the-anonymous-internet-is-under-attack-12...
Just on the start the spike, there are many events. Though I don't know how to find information on those events.
[0]: https://research.torproject.org/techreports/detector-2011-09...
"Sybil attack" is a rather large category of attacks and I'm curious about the specifics of this particular one. In particular, certain vulnerabilities can still be prohibitively expensive for use in dragnet-surveillance.
So far though, the overwhelming majority of attacks on Tor users comes from things that aren't Tor itself --- e.g. Firefox vulnerabilities, timing side-channels on when the user was home, etc. Additionally, if you're not doing anything illegal, you're less likely to be targeted on Tor. Not that this is to say "if you're not doing something illegal you have nothing to hide!", just that your adversaries are likely not powerful or motivated enough to target you on Tor if what you're doing isn't illegal. Even in places like China, where every attempt to block Tor is made, they typically don't spend much effort in targeting those who do try to use Tor. This means if your motivation for Tor is to do things like stop web site trackers, it's not only a good option, it's probably the best available.
I think it might be a botnet or something similar, although that's just conjecture at this point.
Why would a botnet be so centralized in the UAE? Seems like the opposite of what you'd want if you could help it, so maybe they can't help it?
Some kind of state-sponsored test/attack against the Tor network seems like the best explanation to me.
I was pulling 800k/sec the other day, pretty surprised.
Some circuits are still slow. But I remember not that long ago (18 months?) it was a miserable expereince
Basically open source volunteer projects fail pretty hard until an economic incentive is added.
On another note, I2P has attempted several times to add a cryptocurrency to its protocol layer.