I tried visiting Stack Exchange today using Tor Browser, and apparently my IP is blocked. I tried with several different circuits, and they're all blocked. Several people on IRC confirmed this as well.
I tried to contact them by e-mail and they didn't bother to respond, as is par for the course these days.
The full error message:
---
Access Denied
This IP address (185.220.101.37) has been blocked from access to our services. If you believe this to be in error, please contact us at team@stackexchange.com.
When contacting us, please include the following information in the email:
Method: block
XID: 820408900-HHN
IP: 185.220.101.37
X-Forwarded-For: 185.220.101.37
User-Agent: Mozilla/5.0 _Windows NT 10.0; rv:91.0_ Gecko/20100101 Firefox/91.0
Reason: Blocked.
Time: Tue, 08 Feb 2022 08:11:50 GMT
URL: tor.stackexchange.com/
Browser Location: https://tor.stackexchange.com/
https://meta.stackexchange.com/questions/376060/update-on-th...
For the past month Stack Overflow has been hit by weekly DDoS attacks that progressively grew in size and scope. In each incident, the attacker(s) have been changing their methodology and responding to our countermeasures. Initially we were able to detect and mitigate the attacks before any performance degradation could be noticed but the latest attacks ramped up very quickly and the site was brought down before we could react.
While we cannot go into specifics on each attack in order to maintain opsec and not tip off the attackers, we can say that each individual attack has been using different IP addresses and targeted different aspects of the site. During an outage, our top priority is always getting the site back up and running. After traffic has been stabilized, we perform a post mortem for the incident where we assess and improve upon the actions we have taken.
During the outage last Sunday, we noticed that a large amount of the DDoS traffic originated from Tor exit nodes. The decision to block Tor exit nodes did not come lightly, in fact Teresa, our CTO was on the call when we discussed remediation methods. Due to the persistent nature of the attack and our desire to bring the site back up as fast as possible we made the decision to block all DDoS traffic endpoints, including these Tor exit nodes.
We did not target, nor set out to block all traffic from Tor, that’s not something Stack has ever done. However, due to the shared nature of Tor exit nodes, some of them were also routing DDoS attacks to our sites and were blocked. We have tried removing these blocks between attacks but this action has resulted in further site outages as DDoS efforts continue to originate from these exit nodes. Unfortunately blocking the Tor exit nodes also blocks legitimate users from using them. An immediate solution for users who find themselves blocked is to access our site from other IP addresses, via home internet, work internet, or other VPN services.
We are continuing to evaluate the situation and will keep our community updated. Thank you for your patience and understanding.