Smarter retry logic: fewer false OFFLINE badges
The most annoying failure mode of any status list is the false positive: a site you can open in seconds shows a red OFFLINE badge, and you wonder what the checker is even doing. We heard you. The checker heard you. The checker changed.
What was wrong
The old logic treated one failed probe as evidence. But tor is not a straight wire - circuits rotate, introduction points get congested, and a single timeout frequently means nothing at all. One data point is noise; the old checker was quoting noise. What changed
Now every failed probe gets retried on a completely fresh circuit before anything is marked offline. Only repeated failures across separate sweeps - each taking a different route through the network - keep the red badge up. The trade-off is honesty about latency: a genuinely dead site takes slightly longer to flip red. We think that is the right side to err on. A badge that cries wolf is worse than a badge that waits a few minutes for certainty. The faq has the full methodology, and the on-demand status checker uses the same retry discipline for single lookups.