We have a growing set of graphs for how many users we're seeing from Egypt connecting to the public Tor relays.

In the past day or so our graph dived. How can we distinguish an attack on Tor in particular from an attack on connectivity in general?

We should find a good data source that measures overall flows in/out of various countries. Then we can graph both curves on top of each other and have a better intuition about what's really going on.

Yes, it would be interesting to add external data into our user graphs. But unless we incorporate the external data into our statistics, e.g., by feeding them into the censorship detector, there's no big gain here. Putting our user number graphs and external graphs next to each other gives us the same information, maybe not as conveniently as in a single graph.

I'm reducing priority to minor. This is something we should work on later this year.

This isn't something I'm working on, nor something I'll be working on soon. Unassigning.

Closing tickets in Metrics/Analysis that have been created 5+ years ago and not seen progress recently, except for the ones that "nickm-cares" about.

