Hacker News new | ask | show | jobs
by sterwill 1348 days ago
Years ago, I ran a tor relay (not exit node!) on my stable home internet connection. I forgot all about it for months and months, and then when I was trying to update a home insurance claim, I kept getting weird site errors. Pages would half-load, I'd get 500 errors submitting forms, etc. I wasn't _using_ tor at all, just normal Firefox like always.

I peeked at the failed AJAX calls and I saw that the site was denying my traffic because I was classified as a high risk endpoint. The name of their WAF/filtering vendor was in the error responses or headers, so I found a free way to query that company's threat database for my home IP. There it was, my IP was marked high risk because it was associated with a tor relay. It's a silly threat correlation, in my opinion, but it was enough of an annoyance that I stopped running the relay so I didn't have to worry about flaky firewalls.

The ironic thing was, I could have probably fired up Tor Browser and tried new exit nodes until I found a fresh one their system didn't know about, just to finish updating my claim! I actually just tethered my laptop to my phone, I think.

PS I forgot to ask: does anyone know if Snowflake is as detectable as a normal bridge or relay node? If so, there's the risk that your home connection gets a risk/reputation strike against like mine did.

1 comments

Cool story - thanks for sharing.

I've got a spare laptop and started a TOR relay (no exit) recently - I'll be on the look out for these kind of errors