On 11/02/2011 05:54 PM, Gozu-san wrote:
Is it really possible that over 100 fools would have downloaded a purported Tor security update from Hard Candy in one day? In the middle of an attack by OpDarknet? Seriously?
Mozilla stats https://addons.mozilla.org/en-US/statistics/addon/2275 seem to suggest that there were 3000 Torbutton downloads and 171000 active Torbutton users on a typical day (earlier in the year before it was removed).
190 users falling for some professional social engineering and downloading a signed code update hosted on a compromised web server seems realistic to me. I'd guess at an estimate of the overall site popularity, probably fewer than 2000 regular visitors.
- Marsh _______________________________________________ tor-talk mailing list tor-talk@xxxxxxxxxxxxxxxxxxxx https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk