4 ms·
* Tor will cause IDS and firewall alerts. This could lead to traffic being blocked. * Tor HS are not particularly resilient and have relatively high latency.
by tshtf 10y ago
* Tor will cause IDS and firewall alerts. This could lead to traffic being blocked.
* Tor HS are not particularly resilient and have relatively high latency.
* The addresses of Tor hidden services can be determined by an attacker (Malicious HSDir operators).
* The Tor network is already over capacity, and isn't intended or ready for commercial use. Carefully considering using a free community service for a commercial product.
* If you do ultimately use Tor, consider running Tor relays or donating to the foundation.
- merqurio 10y agoGreat feedback! A couple of questions as we are new to * What are the risks of unmasking a hidden Tor * Planning a schedule to turn on tor will be a good solution for the resiliency problem ? Thanks !
- tshtf 10y agoWith the hidden service address, an attacker can access whichever ports are exposed by the hidden service. Turning Tor off and on is a relatively expensive operation for the Tor network. It wouldn't particularly help resilience.
- merqurio 10y agoThanks tshtf! I will keep learning on Tor before making any decision. Personally I think it can be great to go with Tor, having a great excuse to support it too.
- rendx 10y agoI have used Tor extensively in many situations and across many organizations and simply using it never "caused IDS and firewall alerts". Can you give examples? What do you mean by "not particularly resilient", compared to other remote management solutions? Tor is very good at handling temporarily broken connections, change of networks etc. -- much better than many other solutions like openVPN. Addresses of onion services in the current design can be discovered, true. Again, this is not different from many other remote management solutions. You can (and should in this scenario) use authenticated onion services, which means that unless you know a secret you cannot access any service behind an onion. See "HidServAuth" in the Tor manual. "The Tor network is already over capacity" -- what makes you think that? Here's a graph roughly comparing available vs. used bandwidth: https://metrics.torproject.org/bandwidth.html https://metrics.torproject.org/bandwidth.html