5 ms·
Netflow is a great example of the dual use aspects of tech between surveillance and defense. Making Netflow data more widely available looks like it is going to
by zmanian 10y ago
Netflow is a great example of the dual use aspects of tech between surveillance and defense. Making Netflow data more widely available looks like it is going to be essential for defending that Internet but at the same time Netflow data can threaten the anonymity of Tor users.[0][1]
[0] https://blog.torproject.org/blog/traffic-correlation-using-netflows https://blog.torproject.org/blog/traffic-correlation-using-n...
[1] https://gitweb.torproject.org/torspec.git/tree/proposals/251-netflow-padding.txt https://gitweb.torproject.org/torspec.git/tree/proposals/251...
- mordocai 10y agoOf course, I'm not sure if cloudflare could care any less about tor users. They see a lot of attack traffic from tor so this probably isn't something they are concerned about. I can't really blame them from a business perspective, but I avoid cloudflare due to it.
- dom0 10y ago> They see a lot of attack traffic from tor This was debunked.
- brainfire 10y agoWhere/how?
- mordocai 10y agoI don't believe this is actually arguable. People use tor to attempt to anonymize their (generally non-ddos) attacks. I don't believe tor can support the type of ddos the OP is talking about, of course. If you could provide the source of this debunk it'd be appreciated.
- ryanlol 10y agoThis is ridiculous. Anyone can grep their access logs for signs of obvious attacks and very quickly verify that very few, if any, of them originated from Tor exits.
- xxdesmus 10y ago"This was debunked." Where exactly? No one claimed Tor was sending DDoS attacks -- plenty of other malicious traffic comes out of Tor however.
- tptacek 10y agoThis is true, but it is a fundamental fact of the Internet, and has been since before Roger Dingledine first started presenting Tor to people at Black Hat. The major ISPs are all instrumented with Netflow, they're all collecting it, and they've all got tools (both in-house and from vendors) to analyze it. So if you're going to try to deploy something like Tor, the table stakes are that you're secure against wide-scale Netflow instrumentation. If Netflow is an existential threat to your privacy tool, you don't have a privacy tool that is ready for deployment.
- toast0 10y agoFor ddos attribution, you generally only need a very small sample rate, and only headers. You might be able to use that against tor connections, but only when you're very lucky.