
Does anyone know where we can get more information about the stats behind this slide: https://twitter.com/AlecMuffett/status/730773970383982592 The slide says: 1:11,500 non-Tor IPs contained malicious requests 1:380 Tor exit nodes contained malicious requests The way it's worded, it sounds like they're saying "1/11500 of the non-Tor IP addresses we saw sent malicious requests, and 1/380 of the Tor exit node IP addresses we saw sent malicious requests", but I'm finding that hard to believe, since 1/380 of the Tor exit node IP addresses is ~3 IP addresses. It's unlikely that all malicious Tor traffic was confined to 3 exit nodes. (But interesting if true.) Were they perhaps being a little loose and really meant "1/11500 TCP connections coming from non-Tor IP addresses, and 1/380 TCP connections coming from Tor exit nodes, contained malicious requests"? Thanks, - Ian