4 ms·
I block tor from many of my servers. I started noticing that whenever I had an issue with someone attacking a server the source traced back to an exit node. Wha
by vabmit 10y ago
I block tor from many of my servers. I started noticing that whenever I had an issue with someone attacking a server the source traced back to an exit node. What I found when I looked at the traffic coming from the exit nodes was that the vast majority of it was malicious. There was a massive amount of automated password guessing, exploit attempts, and attempt to connect to botnet controllers/backdoors.
I'm all for anonymity. However, until the tor project puts some effort into outbound traffic filtering for exit nodes it is too much of a time sink and headache not to just blackhole it all on servers that either do not serve public content or where anonymity really isn't needed/justifiable.
I put the code I use to block tor exit nodes in the public domain. You can download it here: https://github.com/vab/torblock https://github.com/vab/torblock
- maxt 10y agoThere's underblocking and overblocking. Underblocking is allowing TOR traffic through, but also letting TOR traffic flood your servers. It's obvious that if you have a flood of nefarious traffic like this then you should throttle the TOR traffic. Overblocking is outright blocking TOR with no reason other than because you can, and it leaves many legitimate users frustrated and feeling like the site just self-censored itself. It would be suitable in these cases to strike a happy medium and allow some TOR traffic through, but throttle suspicious-looking requests like mini 'swarms' of TOR exit IPs hitting the site all at once, which I think HN does, because some TOR idens work, whilst others do not.