4 ms·
Thanks to CloudFlare for working with Tor on these issues. The browsing experience for us legit Tor users is much better than it used to be. I hope that eventu
by na412 8y ago
Thanks to CloudFlare for working with Tor on these issues. The browsing experience for us legit Tor users is much better than it used to be.
I hope that eventually, .onion services can get DV certs so their proxy can serve that cert if the user connects directly, bypassing the need to connect through an exit node for the first connection.
One thing I'm curious about:
> While bad actors can still establish a fresh circuit by repeating the rendezvous protocol, doing so involves a cryptographic key exchange that costs time and computation.
Is there some way for the destination .onion service to scale the difficulty of this rendezvous challenge, so this proof-of-work scheme can continue to work? It would be sad if they get to the point where it's no longer an effective rate limit and have to go back to serving CAPTCHAs for every new circuit.
- jgrahamc 8y agoI really doubt we'll go back to using CAPTCHA for that. We'd already (ages and ages ago) dropped the use of CAPTCHA for connections from the Tor Browser. Today's announcement is a further refinement of all the work we've been doing to make using Tor smooth with Cloudflare domains.
- na412 8y agoGood to hear. For what it's worth, I haven't seen a CAPTCHA browsing cloudflare sites for a long time (months?), until just today I've gotten two (out of several tens of CF-backed sites visited). Could be related to these changes, not sure.