Russian internet censorship machines are tracking Tor

[ad_1]

at the beginning In December, the Tor Project’s support email inbox began to receive an unusual number of messages from users stating that they were having problems accessing the digital anonymity service. Gustavo Gus, the head of the Tor project’s community team, said: “This is not just one or two, but a question raised by 10 people.” At the same time, the Open Observatory for Network Interference (OONI), which is responsible for measuring and tracking Internet censorship, is working. personnel, See signs This indicates that the Russian Internet Service Provider (ISP) is blocking the Tor network.

Tor is used by people all over the world to cover up their activities on the Internet, sometimes for illegal activities, but usually to escape the censorship of authoritarian or authoritarian countries.A sort of Study in 2020 It was found that 93% of Tor users access the network for the latter reason, not for illegal reasons.And in Russia, its population is Tor’s second largest user After the United States, people used the service to subvert government restrictions.

What happened in early December is important, although the people in the Tor project don’t yet know.The Russian media and telecommunications regulator Roskomnadzor has issued requests to ISPs across Russia to prevent users from accessing Entrusted website. In Russia’s dispersed Internet infrastructure world, ISPs are beginning to act quickly. And access to certain parts of the Tor network itself is limited.

On December 1, OONI noticed that 16% of Tor connections in Russia recorded some kind of anomaly. One day later, it was one-third. December 8, Back to 16%The exception seems to depend on which ISP and which user is trying to access Tor.Some people were sent Blocked page Not the Tor project website.Others seem to be subject to Man-in-the-middle attack When trying to connect, protect the data sent end-to-end over the Internet through their TLS connection.More people are still looking for their Connection reset repeatedly When the TLS handshake starts, try to block their access. OONI said that the latter method shows that Roskomnadzor uses deep packet inspection (DPI) to filter packets going to Tor, which shows that they have been sniffing traffic through the ISP. (Roskomnadzor has been contacted for comment on this matter.)

All three methods take advantage of some kind of IP blocking. OONI engineer Arturo Filastò said: “In fact, they will define a rule in the firewall configuration to drop all traffic to a certain destination.” “In some configurations, they may choose to inject reset packets to Actively terminate the connection to implement the block.”

However, the problems documented by OONI-and the complete prevention-are not evenly distributed among Russian ISPs. Since December 2, OONI has tracked 333 unique networks in Russia. Forty-one of them blocked Tor in some way, although Filastò cautioned against saying that 12% of ISPs were blocked because there are 4,671 registered autonomous system numbers (ASNs) in Russia and they are controlled by ISPs. All of these serve different numbers of users. On some ISPs, the situation is more complicated, such as VEON, where some users experience congestion on Tor, while others do not. Filastò said: “This may be because the launch of the block is not done in the same way in all infrastructures.”

[ad_2]

Source link