tor-relay overhead

About what will happen if you keep an intermediate Tor-node on your IP address and how long it will take to β€œlaunder” it.

Since the caring RKN began to protect us from information objectionable to him, he has used various means of circumventing "care". First of all, the Tor browser, but for visiting trackers it is somewhat inconvenient - each time you need to enter a password, first of all, launch it second and wait until it connects, and indeed unnecessary actions.

Due to the fact that FreeBSD has always had a home file washer-torrent downloader, as soon as the Internet ceased to be dial-up, a solution was implemented with automatic distribution of the proxy server address via DHCP, Squid + Privoxy + Tor itself.

Tor was configured by a relay to be an Exit-node. Everything works great.

There were some oddities:

  • jd.ru does not open until unbound starts making all requests not directly to the root servers and further down the chain, but, say, to 8.8.8.8. I thought something was wrong with the setting, although I sat down for Google a couple of times and couldn’t find anything for me, what was wrong.
  • Sberbank did not work regularly, neither the application, nor the website, and, accordingly, the browser-based Internet bank. The IP address was dynamic, you never know which client messed up something, or the provider itself.
  • Most often, I could not get on otzovik.ru, complained about incorrect activity from my address.

If the problem with jd was not acute at all, then with the savings bank it was solved by juggling the session with a different address. Although Rostelecom has opt82, the new address was easily obtained by changing the poppy to poppy + 1 on the network card in ifconfig. Or the problem was solved by switching to mobile Internet.

And then I changed the provider, which gives subscribers both white and gray addresses, and in view of the fact that white is needed, and the static one costs only 50 rubles, I took it. And then the question arose with the Savings Bank - it stopped working again. The provider's technical support jerking resulted in a new address. Sber worked and died again. Banks.ru has a review that confirmed my guess. Sber indiscriminately blocks all addresses that appear in Tor, even if it is an intermediate node.

For the sake of laughter, I tried a dozen more banks directly from the Tor browser - they all worked, only Sberbank was paranoid. But again, mobile operators helped out, although there was some inconvenience.

A letter to the mail to the response center remained unanswered, about what kind of activity there is from my address. As well as a letter to the Emex address.

So Emex became the reason for the transfer of the node to a non-public side, from the mobile phone to check the suppliers of auto parts, compare prices with competitors, and even when there are a bunch of analogues from the phone, it is generally inconvenient to the extreme.

I did not want to break the scheme with transparent proxying of objectionable sites at all. Non-publicity resulted in a strong drop in traffic through it (look at mid-July):

tor-relay overhead

The otzovik came to life the fastest of all, I didn’t follow jd, I collected it about a month later, and emex almost one and a half after the address disappeared from all tor lists, although it was the one that was needed the most.

PS: hide node from all Tor lists = become Bridge
There is one bit in the config: BridgeRelay 1

Source: habr.com

Add a comment