#28898 new defect

Huge drop of users in UAE

Reported by: anadahz Owned by: dcf
Component: Obfuscation/Censorship analysis Version:
Severity: Normal Keywords: ae, censorship, block
comment:1 Changed 4 weeks ago by dcf

comment:2 Changed 4 weeks ago by dcf

It looks to me more like it's the end of some weirdness that began in 2017. The states from the UAE have been weird for a long time and we don't know why. My guess is that this is not a blocking event or a loss of real users, but rather something else artificial. Here is the decrease with more context:

These are the relevant doc/MetricsTimeline entries (I'm about to go refactor these):

start date end date places protocols description links
2017-01-15 2017-03-01 ae <OR> relay Huge increase in relay users (400k+). An anonymous contributor suggests that it may be a botnet, based on the large number of hosts with an open SMB port in the UAE. graph metrics-team thread reddit thread comment about botnet
2017-03-01 2017-07-01 ae <OR> relay Another increase in relay users, with a slower rate of growth than the previous one. graph
2017-07-01 ae <OR> relay Sudden drop in relay users. graph
2017-07-01 2017-08-30 ae <OR> relay Slow increase in relay users. graph
2017-09-01 ae <OR> relay Relay users remain volatile but flatten their rate of growth. graph

For a while, there was also a weird increase in obfs3 users in the UAE.

start date end date places protocols description links
2017-02-06 ~2017-08-01 ae obfs3 Increase in obfs3 users from the UAE, from 5K to 100K. Other transports not affected. transport graph UAE bridge graph ticket
