Tor usage doubles in under a week, and no one knows why
arstechnica.com
arstechnica.com
initially i assumed a conspiracy to flood the network or conduct research when I read about abnormal spikes for india and brazil but actually looking at the graphs the huge spikes are across most nations.
for reference i checked the source code for the graphs page and how the data is compiled and the only data available for user count is country so at the moment there is no way to do pattern analysis for tor version or the like to definitively point to the pirate browser.
Anyone know how to get the same info for Yandex to cross-check?
[1] http://www.google.com/trends/explore?q=tor#q=tor&date=today%...
[2] http://www.google.com/trends/explore?q=tor#q=tor&geo=RU&date...
An NSA attack would be possible, but seriously they would get 1 out of 100 targeted users. I don't think its worth the effort and I think they're not so stupid. Then again they are severely more stupid than what we use to think... so everything is possible. My money is on the botnet theory though.
Don't underestimate someone because you dislike what they do.
Stupid is disparaging an entity that has engineered around entire industry and international infrastructure to accomplish their goals.
But yea, botnet sounds like its right on the money. When does the NSA's Utah data center go online?
the 'stupid' part is that any random contract sysadmin could pull huge amounts of data without setting off any alarms. I mean, this isn't some tiny VPS provider, where you might expect all the admins to have root. This is the fucking NSA. they should have tight control and logging over who accesses what, and if they have a master key, the folks with access to that master key ought to be fully vetted employees, and there ought to be few of those people.
Sure, it's hard to design a system where your sysadmins don't have full access, but not nearly as hard as everything else they've done.
This is what I find so shocking about the leak. We all knew that the government was spying on us. The shocking part is that they don't have any better security than I have when it comes to storing that data.
I mean, this is the leak we know of... how much do you want to bet that someone else has already used this data for personal gain, without the public or even the NSA finding out?
It's one thing to keep all my internet history, and use it for investigations... it's quite another to keep all that data where any random contractor can come in and fish through it without setting off alarms.
No matter what you think about the rightness or wrongness of the spying itself, I think we can all agree that if they must collect data, they must also secure that data, and this leak proves that they have not done so.
"Witness the firepower of this fully armed and operational battle station."
Now the clever guy is the guy that can get that access without access to the resources of the NSA.
Here's a list of hypotheses:
1. The recent Russian censorship crackdown.
2. Botnets using Tor to search for vulnerable systems and to hide the C&C server.
3. US publicity following the recent NSA news events.
4. The Pirate Browser's use of Tor.
5. An OP (client) based vulnerability in the network.
If you have upstream collection on the backbones, then you might be able to fingerprint hidden services with staggered connection floods (watermarking.) Also, you may be able to do stream watermarking on the OP->Hidden Service traffic through the Tor cell delay side channel. That seems very possible.
Edit: Another possibility just occurred to me. You could use the OP clients to overload the relays you don't control, driving traffic to the attacker's hostile relays.
Something in my gut says that's not right though... Mostly because this is so very amateurish, with no slow ramp up of nodes, etc. Then again, the Freedom Host takedown wasn't exactly a model of subtlety either.
Botnets have started to use Tor in a major way for C&C. Of all the above, (2) seems most likely.
If someone really wants to find out, stand up a couple exit nodes on EC2 and watch the exit traffic pcap. That might be a bit dodgy in light of ECPA, but after all it's just metadata, right? ;)
Ideally it would be someone who has had such set up from before the spike, so that there is a baseline for computing the increase.
Also, an arbitrary set of exit nodes is obviously not guaranteed to capture the spike. In fact there might be no spike at all in exit traffic (quote:) "So while there are a bunch of new Tor clients running, it would seem they're not doing much."
Huh, didn't notice that. Should have seen it from the network bandwidth graph. It's even more odd in some ways than the OP spike.
I've got a fairly good understanding of the mechanics of the Tor network having studied it down to the packet level, modified the source for academic experiments, etc. I can't think of any reason that would compromise anonymity where it would help to have a whole bunch of mostly idle OPs idling on the network.
Maybe a botnet C&C with low bandwidth staggered command orders, or maybe it's infrastructure building for something that hasn't been activated yet. Or of course the more mundane explanation that lots of people downloaded the clients after the recent publicity, and don't really use the browser bundles.
http://www.welivesecurity.com/2013/07/24/the-rise-of-tor-bas...
https://lists.torproject.org/pipermail/tor-dev/2011-October/...
[1] https://metrics.torproject.org/direct-users.png?start=2013-0...
[2] https://metrics.torproject.org/direct-users.png?start=2013-0...
https://metrics.torproject.org/users.html?graph=direct-users...
[1] https://metrics.torproject.org/direct-users.png?start=2013-0...
I can't imaging the Pirate Browser thing would be immediately so popular across so many different cultures, even in countries without net censorship.
I will wager that some somewhat popular high-bandwidth application (bittorrent client?) has integrated tor in some way, and they released the version with that integration about a week ago.
According to https://metrics.torproject.org/users.html?graph=direct-users... the number of users double, to 1.2 million, in just 2 weeks.
Any chance that is why usage has jumped?
Also, this news has nothing to do with a jump in relays.
Perhaps it's due to https://en.wikipedia.org/wiki/PirateBrowser
I'd wager it's a mix of publicity post NSA debacle and more botnets coming online.
Maybe many others experienced the same? At list I have had enough. Obama is tracing me no more!
What annoys me more is the people using AWS to send us bad traffic.
edit: fixed typos
I thought that this might be what is going on, but since the increase seems to be clients and not new nodes I assume that this is not the case, however the paper is kinda cool anyways.
https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&c...
Somehow, they don't realize that the NSA's upstream program is exactly that. They've been intercepting any Internet traffic they can get their hands on all the way back to 2003. Tor is not safe.
BUT the increase wasn't til Aug 19 - https://metrics.torproject.org/users.html?graph=direct-users...
haven't these people learnt anything?
But this is hardly the first time someone has noticed malware spreading exponentially over the network. Correlation to current newsworthy events may be completely accidental.
I do not believe in jumping to conclusions here. It could be location reporting bias or malware attempting to not piss off (or implicate) certain parts of IP space. But compare Greece https://metrics.torproject.org/users.html?graph=direct-users... to Israel https://metrics.torproject.org/users.html?graph=direct-users...
http://www.forbes.com/sites/andygreenberg/2013/08/14/meet-th...