9 ms·
Tor’s history of D/DoS attacks and future strategies for mitigation
- favflam 3y agoHas anyone tried using TOR as a replacement for Cloudflare DDOS protection? There is a single hop mode on hidden services.
- genpfault 3y ago> There is a single hop mode on hidden services. These[0][1][2]? [0]: https://blog.torproject.org/whats-new-tor-0298/ https://blog.torproject.org/whats-new-tor-0298/ [1]: https://2019.www.torproject.org/docs/tor-manual.html.en#HiddenServiceSingleHopMode https://2019.www.torproject.org/docs/tor-manual.html.en#Hidd... [2]: https://2019.www.torproject.org/docs/tor-manual.html.en#HiddenServiceNonAnonymousMode https://2019.www.torproject.org/docs/tor-manual.html.en#Hidd...
- favflam 3y agoYes, this feature. It seems like a cheap way to put a bunch of servers between yourself and connecting users with built-in rate limiting.
- ThreeHopsAhead 3y ago[dead]
- ThrowawayTestr 3y agoYes, kiwifarms still exists on the deep web.
- LinuxBender 3y agoI've run it in NonAnonymous mode as an experiment. Not to replace a CDN for DDoS protection but to replace the CDN as a way to anonymize where the server is because people play games to try to cancel hosting accounts when they get mad about topics being discussed. When they can't control the narrative they will start emailing abuse@ making false claims and some hosting providers are lazy. From the DDoS aspect, people could send Tor to 100% CPU but the httpd server wasn't even passing 1% CPU. This was long ago however so this observation is likely outdated. early days of v3 Nobody was able to decloak the server even being in NonAnonymous mode but the bigger issue was the ability to reach the server. At least at the time not many people had a browser that could talk to .onion sites. I don't know how many people use Brave or the Tor Browser these days so maybe now it would be less of an issue now. Maybe I will try it again soon. It's easy to send people to the Tor Onion version of your site using the Onion-Location header [1] to see how many people would be able to reach the .onion side of your site. [1] - https://community.torproject.org/onion-services/advanced/onion-location/ https://community.torproject.org/onion-services/advanced/oni...
- theblazehen 3y agoI've done a POC before where the main site was a tor hidden service, and I had cheap VPSs acting as a clearnet reverse proxy to it
- _factor 3y agoThese are likely nation state actors who have the ability to fund these attacks. I wouldn’t be surprised if they’re using advanced techniques to slow down the network and track the routes as they traverse. I would be wary of anonymity while using tor during one of these attacks.
- TechBro8615 3y agoEh, the techniques don't need to be that advanced or even expensive, and there are plenty of markets with motivation to DDOS their competitors. The government might even prefer that the markets stay up, so they can continue monitoring them and honeypotting criminals using them.
- Arch-TK 3y agoI wish people stopped using discourse. Sending pictures of pieces of hand written paper over email would be a more user friendly and usable interface than this javascript mess.
- hombre_fatal 3y agoI prefer it over every forum I’ve used, especially on mobile.
- vaylian 3y agoOne of the design goals of Discourse was that it should work well on mobile phones. I guess most other forum software is either from the time of before widespread smartphone use or it doesn't consider mobile users. With that being said, I actually don't like discourse's UI and prefer more classical forums like PHPbb.
- simias 3y agoDiscourse goes a bit overboard with the javascript and all the bells and whistles but I don't understand how anybody could prefer PHPbb over it, other than familiarity. That being said I always found PHPbb abysmal to use, even in the early 2000, so clearly I'm biased. My main issue with Discourse is that I prefer HN/Reddit-like threading for replies rather than linear comments, but PHPbb does the same and there are pros and cons for both formats anyway.
- yieldcrv 3y agoWhat are anyones thoughts on the proof of work solution? Aside from energy use
- cf141q5325 3y agoThe problem is, that it still requires an address (be it tor or IP). Even if you run the script locally, there is still a need to communicate input and output. So people can just ddos that page. Works great for combating human spam though. You tend to behave better if your login took half a day to get and expires quickly when not used. Plus build in cool down time after getting banned.
- Lk7Of3vfJS2n 3y agoBehaving better isn't the only outcome. Another outcome is leaving the service permanently.
- cf141q5325 3y agoImpact from moderation always goes both ways. The more you insert yourself, the higher the chances that your own stupidity warps the entire communication channel for the worse leading to shrinkage and echo chambers. And people dont vanish, chances are they are already attempting the next tower in babel a few ips over and get up to who knows what. The merits of proof of work should be discussed for the specific scenario. If it allows for reputationless discussions and throwaway accounts, how high is the cost really? In comparison to banevasion problems, moderation overhead and the resulting attack surface requiring more resources while deteriorating the channel? Otherwise impact less emergency breaks for idiots might be reasonable solution. Its not much different from timed bans.
- Lk7Of3vfJS2n 3y agoI'm not sure I understood everything you said. How do you determine a user is an idiot or not when good ideas look like bad ideas initially? Experts can have blind spots. The option for reputationless discussion should always remain open in my opinion. > how high is the cost really? The cost can be proportional to the proof of work. Everything has a cost. How about determining the cost and providing means to pay for it? Paying works for many things in the world. It works for ads, for example. Why must the cost be annoying a human by requiring reputation instead of a monetary cost? How is annoying a human a better solution than letting people pay? Do you really think pissing people off will stop them from expressing what they want? It might be more likely that people will express what they want, nobody will hear them, and they'll leave, taking good ideas with them. Just as there is a cost to moderation, there is a cost to losing good ideas. How about letting a free market decide?
- cf141q5325 3y agoI think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.
- Run_DOS_Run 3y agoDon't forget OVH. Their DDoS-protection is included in every server.
- peterhadlaw 3y agoWhat do you mean every server? Pardon my ignorance, first time I am hearing about these folks.
- tw04 3y agoOVH is a hosting provider, you rent physical or virtual servers from them for a monthly fee. They protect their entire network with DDoS mitigation. https://www.ovhcloud.com/en/security/anti-ddos/ddos-attack-mitigation/ https://www.ovhcloud.com/en/security/anti-ddos/ddos-attack-m...
- patrec 3y agoIf cloudflare won't touch you, chances are neither will OVH.
- malikNF 3y agoAt-least in my experience, OVH was the only hosting company where their network engineers spoke to me when we had a ddos problem. Had a situation where one of my servers were getting ddosed we tried multiple providers both cloud and dedicated, but the attack was not getting stopped by anyone, the customer service was useless on most other places its either we get null routed, or hours of back and forth with customer service without any solution. We moved our servers to OVH the customer service rep directed us to an engineer within a few minutes. I remember we had to send a few packet captures during an attack to one of their network engineers and, not only did they block the attack in a few hours, the engineer in charge explained exactly what happened was such a nice learning experience, that one interaction with them will always make me recommend them.
- yieldcrv 3y agoI’ve heard passing mention of people switching to i2p because they feel the design choices of the Tor project are questionable - suggesting compromise. But these were vague assertions, is there more reading or ability to substantiate this?
- cassepipe 3y agoI was curious so I went and found this : https://geti2p.net/en/comparison/tor https://geti2p.net/en/comparison/tor
- shrimp_emoji 3y ago``` Benefits of I2P over Tor ... Java, not C (ewww) ``` Excuse me?
- owenmarshall 3y agoI feel like “written in a memory-safe language” is a fair selling point, especially when we are talking about a tool designed to accept completely untrusted data from the network and keep you safe from attackers with significant resources.
- chasil 3y agoAll of the "boring crypto" has been written in C. https://cr.yp.to/talks/2015.10.05/slides-djb-20151005-a4.pdf https://cr.yp.to/talks/2015.10.05/slides-djb-20151005-a4.pdf Unfortunately, Java encryption libraries are far from boring. https://www.bleepingcomputer.com/news/security/bouncy-castle-crypto-authentication-bypass-vulnerability-revealed/ https://www.bleepingcomputer.com/news/security/bouncy-castle... https://www.cvedetails.com/vulnerability-list/vendor_id-7637/Bouncycastle.html https://www.cvedetails.com/vulnerability-list/vendor_id-7637...
- Avamander 3y agoPeople have done a lot of things, the track record so far has shown that to be a terrible idea.
- mcdonje 3y agoAnother tor page says ddos attacks primarily use UDP packets, which tor doesn't allow: https://support.torproject.org/abuse/what-about-ddos/ https://support.torproject.org/abuse/what-about-ddos/ So, is this an attack using a different method? And what about mitigating attacks on other networks/sites that originate from tor? The site I linked only said "attackers who control enough bandwidth to launch an effective DDoS attack can do it just fine without Tor." They didn't say anything about mitigating the use of tor by attackers. And what they're saying about attacks not being possible on the network is clearly wrong.
- beardog 3y agoThis is for protecting against attacks against the Tor network and onion services. Not for preventing people using Tor to conduct ddos attacks on normal websites which is what your linked page discusses
- DoItToMe81 3y agoThere have been cases of darknet markets employing enormous botnets to layer 7 DDoS their rivals, by constantly requesting data from the site through seemingly legitimate requests. Considering that Proof of Work is one of the primary things they're looking into, it's probably something similar to this.