7 ms·
*They still have a Tor Hidden Service, that's it though
by intunderflow 4y ago
*They still have a Tor Hidden Service, that's it though
- tony-allan 4y agoI suspect that a TOR service is easy to DDOS. Anyone know if that's true?
- prvit 4y agoYes, Tor services are particularly easy to DoS and there's pretty much nothing the DoS recipient can do about it.
- noasaservice 4y agoWell, other than deregistering the onion address from dHT and quit :) I'm glad their little "community" is being seen off into the void. Good riddance.
- tsujamin 4y agolooks like it took down a related nz neo-nazi site too > The ban may have also inadvertently blocked a New Zealand-based neo-nazi group called Action Zealandia. > The Action Zealandia website, which is believed to be hosted by a website run by Moon, is also offline. (https://www.newshub.co.nz/home/technology/2022/09/infamous-kiwifarms-website-blocked-by-cyber-security-firm-over-escalating-threats.html https://www.newshub.co.nz/home/technology/2022/09/infamous-k...)
- ogurechny 4y agoComments like these really make me see it as another Internet Battle of one group of dedicated assholes against the other group of dedicated assholes.
- LinuxBender 4y agoIf they have the time and are willing to put in the effort, they can create a myriad of Tor onion servers that are just nginx proxy-cache nodes that forward over a VPN mesh to their application servers. The end-users would have to be aware of all the onion cache servers somehow or their application would have to load balance people across them and keep some unannounced and cycle some in and out.
- prvit 4y agoThis isn't meaningfully different from using onionbalance, the attackers will still be at a significant advantage.
- LinuxBender 4y agoI know what you mean and somewhat agree. I don't know much about KF but I assume they probably have subforums and groups of people within those forums. What I have seen people do in the past is set up what I described above and then share half of the random cache nodes with the general public and then share specific nodes with sub-groups of people keeping the site accessible to the regular or trusted users. The public cache nodes can have stricter limits on how many requests are forwarded over the VPN. Perhaps this is not compatible with KF's model. I've never seen their site aside from the CF error message.
- Krisando 4y agoYou can DDoS TOR it self, but not a specific service easily.
- prvit 4y agoComplete nonsense. You can easily DoS a specific service by flooding it with rendezvous requests.
- heartbeats 4y agoThat's far from "easy" - if it were so simple, people would be able to extort big money from drug markets for doing it.
- prvit 4y agoPeople are extorting big money from drug markets doing this... It's very easy, anyone with basic grasp of C can modify the Tor client to do this.
- Krisando 4y agoAs I understand, KF have been under attack for quite some time including employing techniques here discussed on this post. https://blog.torproject.org/cooking-onions-reclaiming-onionbalance/ https://blog.torproject.org/cooking-onions-reclaiming-onionb... If it was easy, I wouldn't expect them to still be online on TOR after all this time.
- prvit 4y agoOnionbalance doesn’t solve anything, the attack remains asymmetric so you’ll have to spend significantly more on hardware than the attacker is. > If it was easy, I wouldn't expect them to still be online on TOR after all this time. You seriously overestimate how many people care enough to DDoS kiwifarms.
- Krisando 4y ago
- zxcvbn4038 4y agoTor services get DDOS’d all of the time - you generally have a single host somewhere that is the first hop in relaying traffic back to the service and that is easy to overwhelm. There is a hackish way to have several of those hosts but I think it tops out at a dozen. You lose a lot of audience going to Tor so might not be worth it.
- heartbeats 4y agoNo, that's not true. The first hop (last from the service's PoV) is basically randomly selected. Unless you restrict it, there will be thousands of possible IPs.
- worldofmatthew 4y agoEach hidden service has its own circuits to the Tor network. You can't their side of the connection.
- zxcvbn4038 4y agoYes but only one rendezvous point unless you do the hackish stuff. There are a lot of options for scaling the hidden service itself, but the rendezvous point is out of your control (and should be) so that is where the real constraint is.
- worldofmatthew 4y ago32 hosts officially but there are ways of protecting onion websites (caching reverse proxies with some sort of challenge) that protects drug market places that have governments trying to DDOS them offline. Not to mention that Tor has been working on anti-DDOS (From what I remember that will be based on proof-of-work) which will massively increase the cost of DDOS attacks against hidden services.
- ShowalkKama 4y agoheh it's quite a bit different but there are ways to avoid ddos (see dread, recon & co with endgame and onionbalance)