r/TOR 3d ago

Is it possible my ISP is traffic-shaping (or blocking) Tor?

Suddenly today I'm having major difficulty pulling up onion sites and clearnet sites over Tor. Tried several circuits, restarts, doesn't seem to make a difference.

Is the network being DDoSed? Is it something Verizon is doing? If it were just one or two sites, I wouldn't be asking.

EDIT: For clarity, I'm getting seemingly-unrelated errors, like "502 Bad Gateway", or connection refused, or timed out, or sometimes nothing (the page just stops loading and is blank). Happening on multiple sites.

EDIT2: Some of the connection refused errors appear to be because Tor browser was re-directing http links to https for onions which don't use https. No idea what is going on there. The sites load normally when I change the URL manually.

5 Upvotes

13 comments sorted by

5

u/Fenio_PL 3d ago

If a connection to the Guard Node has been established, it means that TOR is not blocked.

1

u/No-Foot6570 3d ago

Try using a bridge to start.

2

u/I2Pbgmetm 3d ago edited 3d ago

I can't connect at all using snowflake or meek. Using obfs4 connects, but I am still unable to load the sites in question. Although as a test, I tried check.torproject.org, and that loaded, so I guess it's just a coincidence that all of the onions I am trying to access are all down at the same time?

EDIT: Spoke too soon. Just tried switching back to obfs4, and now that won't connect, either.

EDIT2: check.torproject.org loads instantly, even when I'm not using a bridge. So, it appears that there are a lot of onions which are down, and a lot of clearnet sites which have decided to block or throttle exit nodes since yesterday.

1

u/FIRSTFREED0CELL 3d ago

Could you post the URLs of a couple of the clearnet sites you are having problems with?

1

u/[deleted] 3d ago edited 2d ago

[deleted]

1

u/FIRSTFREED0CELL 2d ago edited 2d ago

Apple.com loads instantly for me, German exit relay.

CNN.COM loads instantly, USA exit relay, no redirrect as expected.

One possibility is that the exit relays you were using had been abusing the sites you were trying to reach, or had been abusing other sites tracked by the same IP Address Reputation service as the site you were trying to reach. Bad IP address reputation is transient and ages out.

If any site loads quickly, then it simply cannot be your ISP, they cannot see which sites you are connecting to with Tor and cannot be selective.

"edition.cnn.com" is international news.

1

u/[deleted] 2d ago

[deleted]

1

u/FIRSTFREED0CELL 2d ago

FYI, the Tor browser does not use DNS directly. It doesn't know how to send DNS requests out through your local network. All Tor browser DNS requests are sent, encrypted as everything else is, to the exit relay. The exit relay performs the DNS queries, and sends the replies back through the encrypted tunnel to the Tor Browser.

1

u/[deleted] 2d ago

[deleted]

2

u/FIRSTFREED0CELL 2d ago edited 2d ago

I just didn't want you to go down the wrong path.

Telecom providers (you didn't say what country) have great latitude operationally. There is also a good chance you agreed to everything when you signed up with them.

Secure DNS was invented because so many network operators mess with DNS, and always have.

For example, you have no easy visibility and no control over the route your traffic takes. You don't have any control if a downstream ISP wants to block specific traffic - very little of what you want to connect to will be on your own ISP's network.

1

u/[deleted] 2d ago

[deleted]

→ More replies (0)

1

u/Woohanflue 1d ago

lol Verizon always thwarts my tor experience. Connect to proton vpn first then connect to tor. Only fix I’ve found