On Donnerstag, 18. August 2022 19:22:44 CEST Toralf Förster wrote:
On 8/18/22 18:19, lists@for-privacy.net wrote:
D767979FE4C99D310A46EC49037E9FE7E3F64E9D is a particularly frequent naughty boy.
;-) It is very, very unlikely that there is a naughty relay in AS680. That relay most likely does DNS-, BW- or network healing test in the Tor network. https://metrics.torproject.org/rs.html#search/as:AS680 (German university or research institutes)
Do you know more about those tests ? That relay produces many wrong ORStatus.CLOSED events:
So I don't know exactly. If someone is really screwing things up, it might be a student who hacked a server. I'll take Sebastian in CC, maybe he knows more about it.
$> grep D767979FE4C99 /tmp/orstatus.9051 | uniq -c 896 TLS_ERROR D767979FE4C99D310A46EC49037E9FE7E3F64E9D 141.20.103.33 443 v4 0.4.5.10
$> grep D767979FE4C99 /tmp/orstatus.29051 | uniq -c 965 TLS_ERROR D767979FE4C99D310A46EC49037E9FE7E3F64E9D 141.20.103.33 443 v4 0.4.5.10
The data were collected using [1] over the past 20 hours at [2].
[1] D767979FE4C99D310A46EC49037E9FE7E3F64E9D [2] 65.21.94.13
@Sebastian Do you know more about the relay in the DFN?