Drastic increase in Tor clients from Germany
metrics.torproject.org
metrics.torproject.org
Hard to imagine that so many people in Germany suddenly switched to TOR, especially since there has not been any significant event lately that may have triggered such a decision (afaik)?
My personal experience with TOR (as an administrator of various websites and services) is that it is a major source of unwanted/malicious traffic (spam, etc.) and most of it is automated. The big increase is probably not users but bots?
Just question about the accuracy without any context or reasons are not contributing to the argument.
(e.g., if you single-handedly double the network traffic, then an outside observer can figure out what ingress/egress traffic is yours)
And German federal government have a history for covert shitposting.
And German federal government have a history for covert shitposting.
Wow, I never heard this before. Can you provide some examples famous examples?The closest article I can quickly find is about Germany intelligence informants doing the same in meatspace though.
> There was a "risk that sources of the intelligence service (Office for the Protection of the Constitution) could goad each other on to undertake bigger actions;" in other words, the system threatened to create an "incendiary effect."
https://www.spiegel.de/international/germany/german-police-d...
I work in a German institution. I was recently hacked by such a botnet recently (lessons learned: use AuthorizedKeys, allow only one SSH user, proxy all http connections to a webhoster, and check your SSH and UFW logs often!)
It setup a virtual environment where it downloaded some kind of Tor node and ran some sort of code that used 100% of my CPU. My guess is crypto-mining. I purged the account, deleted everything before I could do forensics, but I checked the logs for the connections and they all came from Russia.
My fear would be that someone still is trying to gather a critical mass of nodes to contact controll servers via TOR to cause mass havoc in a single country from within a single country. Generally IMHO Germany would be a good target for destabilisation currently. But I think and hope this could just a bit of overinterpreting. Probably one would need a good statistic on the subnets the users come from.
I hope to be wrong but I am afraid you are overestimating the technical competency of the average ISP.
ISPs certainly have the tooling and the positioning to be able to detect C&C channels, outgoing DDOS attacks, and compromised customer premises equipment. But do they? And if they do detect any of it, do they take action? When is the last time you heard about an ISP disconnecting a paying customer because of the customer's compromised device(s)? When is the last time you even heard of an ISP notifying a customer about such a thing?
Two months ago, my router was compromised and joined to some sort of botnet in the capacity of a DNS resolver. I would never have been able to detect such WAN-side traffic if I hadn't had a special setup on my part. My ISP was the first to hear when I'd detected it, and I sincerely doubt that they receive many such reports, especially with logs as evidence.
Can you imagine receiving a phone call, "Hello, this is your ISP! You're pwned! Please follow through these remediation steps as I prompt you: ..." You'd undoubtedly think it was a phishing scam. Because ISPs just don't seem to care about abuse.
They will send you copyright strikes and prosecute you for BitTorrent, but it does't seem like they'd lift a finger to prevent the next big DDOS or spam factory originating from their own customers.
But I've never received a threatening letter about piracy. ISPs in my country simply don't send those.
I often used to poke holes in my firewall and run VPN or ssh servers that were discoverable using my dynamic DNS service. My ISP never got involved with that. Of course, that was a case of me running a server for my exclusive use, rather than some sort of public web or login server that would have randos sending traffic across my link.
The only somewhat professional player is the Deutsche Telekom, which was kinda the Bell of Germany and got privatized in the 90s, when the phone network was also opened to other players. They are more expensive though. Other than that, you might be lucky and have some small regional ISP that's competent enough. Otherwise there are just two other companies left that offer service nationwide, after a lot of mergers.
But it's possible they were just passing on abuse reports from the numerous targeted victims of this botnet who bothered to complain.
The intrusion point was a Linux system with a 3 letter password and ssh exposed on a nonstandard port. So if you're someone who still thinks the bad guys won't find your computer because you changed the port, know that that is very outdated thinking.
This seems trivial to figure out with an analysis of the connecting IPs - which is absent on TOR's report page.
I'm also a bit confused why no one here on HN has asked about the connecting IP data (at this writing). Are these commercial IPs, dynamic (biz/residential) IPs or a mix? If they're mostly dynamic IPs, are they from more than one ISP?
TOR has country of origin data so it seems reasonable they'd also have network of origin.
All that said, I don't precisely know how TOR determines country of origin. Entry node data would seem to be the likely source. However I've long assumed that entry nodes are public supplied, like Relay and Exit nodes. Within that assumption it isn't clear to me how that data would flow to TOR - while maintaining anonymization of traffic.
A minor addendum: Looking at the csv file, it looks to me like traffic began drifting above the mean about June 6. From there I see a ramp-up, growing at an increasing rate.
Germany hosts a disproportionate amount of sensitive data because it's the location of choice for cloud providers storing things for EU member countries.
Hat tip to this. My German teammate and I have discussed exactly this point. The Microsoft Azure cloud has a German specific cloud that targets exactly this market. Some marketing genius made billions for Microsoft with that idea.One weird thing to me: You are right about "lots of fiber" -- specifically Frankfurt Internet Exchange is (was?) the busiest in the world for a long time. Why does non-urban, non-commercial (retail) Internet access suck so hard in Germany? It is the topic of endless (but understandable) crying by German residents on HN!
To cut a very long story short, what should have happened a long time ago in Germany is to treat internet access at a reasonable speed (however that is determined) like access to electricity or the plain old telephone system: It's the law you get connected like everyone else at the price everyone else pays, even when you are in a very rural setting. Leaving that decision to commercial interests, has lead to very slow or unavailable rural internet infrastructure because either the price would be ridiculously high to become connected or the companies would lose money.
It's political failure, plain and simple.
Looking back in time, the original sin was committed in Germany in the early 80s when the SPD run government understood that fiber optic networks were the future for the telephone system and television distribution. They had a 30 year plan to convert West-Germany's telecom infrastructure to fiber. That was way before the internet, but would that plan have been enacted, Germany would have sat on a high speed fiber infrastructure in the 90s when the Internet exploded onto the scene.
Unfortunately the conservative CDU government under Kohl immediately scrapped that plan when they came into power and went for cable as the distribution medium for TV and the telephone system continued to operate on copper at least on the last mile. So here we are in the 2020s with crappy cable modems and crappy DSL connections. (Where available.)
Lack of competition and laws tailored to the privatized Deutsche Telekom: If I dig up the street to put fiber optics, they may join in for free. So may I, if they dig up streets - they just don't.
I'll probably migrate to some proof-of-work based schemes and some algorithms to detect anomalous requests, but it would require some engineering work on my part (for a free website FWIW), and the quickest way to mitigate it would be to block Tor.
As much as I deeply, deeply dislike captchas, ip blocking is far worse.
Have you tried mcaptcha? https://github.com/mCaptcha/mCaptcha
if you configure the graph to show more years you can see the similarities: https://metrics.torproject.org/userstats-relay-country.html?...
I read that Tor needs a certain percentage of non-malicious nodes to function, though I am not sure if that is applicable clients.
Of course, malicious clients can ruin it for everyone else in the form of DoS attacks but that's clearly not happening here.
In the latter case, you can do timing attacks to determine which traffic on the exit node belongs to whom on the entry node.
Especially now that there's a war on our borders, the spooks have a plethora of reasons to use to justify their invasiveness.
We just need to make sure to keep them accountable, which is the tricky part, as their work is always classified and our human and privacy rights often clash with their jobs, so unless any whistleblower comes through we might never know the extent of their rule breaking.
Not really the most subtle way about it though and likely to face some response.
I'd assume both have the capability to run a fairly accurate simulated network without anyone noticing so it's a bit strange.
Nothing illegal about it.
Even so, GDPR has research exemptions which would protect the academics doing research in the example being discussed.
IP logs are fully legal in the UE under GDPR and Tor deanonymization is just an IP log of connected users.
Also there is already plenty of research of this type out of the EU. It's quite common in infosec.
I personally don't see how it's unethical for either academics or governments to do this? Both have an interest in breaking tor, even when in the governments case where they both utilise it and want to know who else is using it.
The tor people themselves acknowledge the work in their blogs
https://blog.torproject.org/research-problem-measuring-safet...
https://www.researchgate.net/publication/314521450_Character...
It could be organic growth. There have apparently been a few wiretapping scandals this year; people may be using it to access Ukraine/Russia, and a bunch of laws passed last year that incentivize US companies to block EU traffic (to avoid fines for data leaks).
Any of those seem more plausible than a single actor renting a rack or dc in one country, and using tor to try to evade detection.
No wonder, that Tor users in Czechia rised over 60% since 2020, when government use totalitarian practices like state that they trying to fight against.
Also overall trust in government is historical low here. 74% citizens disapprove what government does here. [3] Which does not mean that we approve invasion on Ukraine at all. We host far more Ukrainian refugees as we should - over 500 000 which is 5% of Czechia population [4].
[1] https://www.mvcr.cz/soubor/krit-memo-putin-hlad-komunikacni-...
[2] https://en.wikipedia.org/wiki/Internet_censorship_and_survei...
[3] https://pro.morningconsult.com/trackers/global-leader-approv...
But also some accounts are just banned.
Banned accounts can still comment, but they start dead and have to be vouched first before showing to anybody who didn't enable showdead in their profile.
It's quite annoying, possibly NAFO or similar.
Hetzner (and other German entities) seem to operate quite a few relays though: https://metrics.torproject.org/rs.html#aggregate/as not sure if this might have something to do with it...
Jk, but if you change 711chan to Krautchan maybe it's true
Depending on how these numbers are obtained, there is a non-zero chance at least part of this increase is caused by us.. note that this number is not indicative of the amount of users or origins (i.e. physical source addresses), but only count directory requests.
"Drastic" has a negative connotation of intent behind it. For example, "drastic increase in police enforcement of laws in Germany" would make sense. In the case of the headline, it just rubs me the wrong way.
What English word would fit best I leave native speakers to comment.
This kind of censorship is just nannying, which I'm generally against.
Then again, given how inept people are at thinking for themselves, maybe a nanny state is what's best.
Actual it is far more defensible, as I already clarified earlier. Propaganda remains effective regardless if there is the ability to verify it or not - and that is assuming everything can and will be checked by every person, which isn't realistic.
> This kind of censorship is just nannying, which I'm generally against.
It's not nannying at all. It's basic national self defense. Pen is mightier than the sword and all that. Brainworms are an insidious contagion.
You didn't clarify, you just gave your opinion. One I disagree with.
> Propaganda remains effective regardless if there is the ability to verify it or not
So you claim. Even so, the correct approach is for the government to fight propaganda with corrective disclosures. Censorship is not the answer.
> It's not nannying at all. It's basic national self defense.
It is certainly the former, even if it is the latter also, something I'm skeptical of. The two are not mutually exclusive.
> Brainworms are an insidious contagion.
You fight them with truth, not censorship.
Moderation and removal is the correct action, so are you flatly incorrect. I'm not going to argue with the stubborn child that wants to put their fingers in the outlet. This isn't up for discussion.
The irony and lack of self-awareness in this statement is honestly astounding.
You hoenstly think your opinion is objetive fact, lol.
> Moderation and removal is the correct action, so are you flatly incorrect.
Because you say so? lol.
> I'm not going to argue with the stubborn child that wants to put their fingers in the outlet. This isn't up for discussion.
There is no discussion to be had with someone that asserts their opinion as fact but can't corroborate it as such. Such a person is indeed a stubborn child, and them calling others a stubborn child can be dismissed like any other nonsense a child may say in an emotional state.
https://de.wikipedia.org/wiki/Sperrungen_von_Internetinhalte...
Edit: parent poster has now changed his post after claiming there was no blocking in Germany
I wonder if anyone can see inside the right-wing chat networks and if they've been mentioning Tor.
Although in the raw CSV's the spike started around mid-June...
The right wing movements in Europe started around 2000 in Italy, Austria, the Netherlands and France. Germany was way behind.
In Germany the AfD won voters after Merkel let in too many refugees in 2015 against the will of many CDU voters.
The AfD is probably less extreme than MAGA and most European counterparts, including Scandinavian ones. But it is always easy to pile on Germany, isn't it?
(I don't vote for them, don't like them, but this is getting silly.)
https://en.wikipedia.org/wiki/1990_German_federal_election
No radical party was of any significance. If they were all Nazis, why didn't the NPD have 20%?
You are the one who rewrites history.
They vote AfD because the traditional parties have failed them and keep doubling down. The AfD would probably also fail them if in power, but that is the nature of protest votes.
Same story in France where Le Pen is currently leading the polls.
As opposed to the BRD, where for example the "Auswärtiges Amt" had more ex NSDAP party members after 1945 than before?
There definitely was denazification in the east, but the totalitarian enclosed and literally walled of mindset did not help with creating an open mind towards the world. Add to that high unemployment and poverty after 1990 and you get the usual extremists on both sides of the spectrum.
Poster didn't say it's rampant, just that "it is very much alive."
I'm German, I live in Berlin, I regularly spend time in eastern Germany, outside Berlin. I can sadly confirm this.
During the cold war and after, the US and anglosphere was mostly interested in the destruction of left ideology, labor unions, left parties etc. were all targeted. The right offers a safe outlet for people with those grievances, it doesn't threaten capital, so it was always allowed to linger in Germany not just in the east. It's deeply rooted in establishment and civil organizations, in university fraternities (schlagende verbindungen, the CSU etc.). The allied supported and used and bolstered far right groups all around Europe (Gladio, NSU, etc.) in their fight against socialism and people on the left. We still feel the effects to this day and state and federal police and intelligence still operate this way.
Protests in Germany you see police protecting far right groups from leftists, not the other way around. It's a necessary aspect of liberalism to allow the disenfranchised the outlet into right wing extremism.
The enlightenment was less influential in the rural estates of the ultra conservative east elbian Junkernklasse than it was in the more densely populated Rhineland regions. Fukuyama has a nice chapter on the matter in “The Origins of Political Order”.
On top of that you have the separation, and the dislike of the GDR to foster critical thinking and the economic collapse of the east after reunification that lead to a lot of brain drain.
The grandparent (quoted above) is generalising a population as having these negative aspects and suggesting that support for the AfD is only due to these reasons. It is a form of shallow dismissal based on bigotry. It doesn't seek to understand the population and properly why support for the AfD is rising. It's much easier (for the bigot) to write off people as having entrenched negative characteristics.
And I wouldn't normally say this but if you have a browse through the grandparent's comment history, the majority of their comments are of this ilk, including one comment about 2 months back that they received a warning from dang for.
Looks anorganic and if it is organic I bet for Netflix and co related.
My mobile data does incorrectly flag some things as 18+ though
But I think that’s a Vodaphone thing rather than a UK thing