Live data from Hacker News

Proof-of-Work Defense for Onion Services

blog.torproject.org

51–60 of 159 posts

Re: Proof-of-Work Defense for Onion Services

#51
post #36

Really interesting! Digging into the proposal [1]: > make it harder for attackers to overload the service with introduction request > We hope that this proposal can help us defend against the script-kiddie attacker and small botnets. Sets expectations: does not counter large botnets. > We hope that this proposal will allow the motivated user to always connect A user who really wants to connect can get through durring…

So now you have the drawbacks of both as well, in that the guy who has the most compute to use as a toaster can DoS everyone else. Plus, PoW is nothing but wasted, needless computation . Computing is not free . Every watt spent doing anything PoW is just that much more intensification of our current climate crisis. As someone with temps of 109 with heat index of 120 coming in the next few days, with all due respect,…

[flagged]

Re: Proof-of-Work Defense for Onion Services

#52
post #43
post #26

Earlier quoted context omitted.

Regardless, you need a device that’s more powerful than whatever the attacker is using. The article says they target 1 minute solve times under load. If that’s 1 minute on a 5GHz, 64 core machine with 512GB ram, an A100 and an FPGA, then it’s going to be at least 5-15 minutes on your phone. Also, the server farm can parallelize work across an arbitrary number of challenges, but legitimate users cannot.

The attacker would need way more power actually, to send enough requests to flood the server. You only want to get one request in. If the server can process 10k requests per minute, and you need to send 10 requests per minute, you only need 0.1% as much power.

My phone CPU normally draws well under a watt, but a server normally draws well over 100 watts.

Re: Proof-of-Work Defense for Onion Services

#53

How will the service operator know when their site is under "stress". Will this effectively prevent someone from having a "high traffic" hidden service free from Tor-imposed puzzles. If the hidden service operator is aware that the site is receiving high traffic, could the operator run several sites as mirrors, so that users had options if, e.g., one site was not responding fast enough. Is there guidance published an…

From the onionbalance site

https://www.benthamsgaze.org/wp-content/uploads/2015/11/sucu...

Re: Proof-of-Work Defense for Onion Services

#55
post #46

As others have commented, it's a shame there isn't a proof of work that doesn't also hurt the planet. It makes me wonder if there would ever be a way to actually do the opposite - your "proof of work" is somehow linked to extracting CO2 from the atmosphere?

We helped secure the bitcoin network and prevented our basement pipes from freezing around 5 years ago (Old building, new heat pumps installed for 1st and 2nd floor. The old basement steam boiler being removed lead to really low basement temps). Resistive heat was the only option down there. After improvements (water heater + circulation fan + insulation), we shipped the miner to a buyer from a hydro facility to burn excess watts for the rest of its life.

Don't hate on the BTC crowd, some of us also care about ecological load.

Re: Proof-of-Work Defense for Onion Services

#56
post #51
post #36

Earlier quoted context omitted.

So now you have the drawbacks of both as well, in that the guy who has the most compute to use as a toaster can DoS everyone else. Plus, PoW is nothing but wasted, needless computation . Computing is not free . Every watt spent doing anything PoW is just that much more intensification of our current climate crisis. As someone with temps of 109 with heat index of 120 coming in the next few days, with all due respect,…

[flagged]

This stinks of hollywood accounting, like a lot of "negative carbon" plans for things that would otherwise be nonsensical for.

The premise here is that if Bitcoin mining uses an energy source that inherently captures carbon or methane, then it's "carbon negative?" This ignores the fact that the energy budget is shared. We could just as well use that same energy for something else currently on carbon-based sources. So, energy is still being wasted on crypto speculation - you've just fudged the total energy budget calculations by pretending it doesn't apply here.

Re: Proof-of-Work Defense for Onion Services

#57
post #36

Really interesting! Digging into the proposal [1]: > make it harder for attackers to overload the service with introduction request > We hope that this proposal can help us defend against the script-kiddie attacker and small botnets. Sets expectations: does not counter large botnets. > We hope that this proposal will allow the motivated user to always connect A user who really wants to connect can get through durring…

So now you have the drawbacks of both as well, in that the guy who has the most compute to use as a toaster can DoS everyone else. Plus, PoW is nothing but wasted, needless computation . Computing is not free . Every watt spent doing anything PoW is just that much more intensification of our current climate crisis. As someone with temps of 109 with heat index of 120 coming in the next few days, with all due respect,…

Without this proof of work, users can be arbitrarily denied access due to overload.

With the proof of work, I think the assumption is that a legitimate user will be willing to accept a sufficient delay to make botnet DoS attack impossible.

The counter argument might be that the botnet can generate arbitrarily hard proof of work, but this isn't true. Assuming some fixed capacity by the botnet, and that the botnet needs to send some amount of requests per time in order for the attack to be effective (e.g., if they only send one proof of work request per minute, then the "bid" for the rest of the time is quite low), then there's some maximum effective "price" based on the capacity of the botnet past which a user is guaranteed access.

For example say a botnet has access to a million compute nodes, so they have 1 million proof of work seconds per second.

If there's a service which can serve 1000 requests per second, then the average proof of work seconds they have per request is 1000 seconds of proof, so as long as the user is able to provide 17 minutes of proof of work, they can get access. In reality, the user's hardware is likely more capable than the attacker's botnet (which is probably IoT devices etc.,) so the ratio is more favorable.

I find it amusing that this approach is pretty on brand for onion services, as an invisible hand type market solution from what I'd consider to be a fairly libertarian leaning group.

Re: Proof-of-Work Defense for Onion Services

#58

Earlier quoted context omitted.

> Computing is not free. That's the whole point.

What if instead of spending energy on compute, we just spend money instead? On the one hand, some people may be turned off by the idea of spending money, but on the other hand, the two are usually interchangeable unless you're stealing energy. Someone with a lot of money and no hardware or energy can purchase hardware and energy; someone with a lot of hardware and energy can sell the hardware and sell energy back to…

How do you suggest the people who are using Tor for anonymity pay money to use Tor? That might make sense for cryptocurrencies, but for Tor I think it's unusable.

Re: Proof-of-Work Defense for Onion Services

#60
post #51
post #36

Earlier quoted context omitted.

So now you have the drawbacks of both as well, in that the guy who has the most compute to use as a toaster can DoS everyone else. Plus, PoW is nothing but wasted, needless computation . Computing is not free . Every watt spent doing anything PoW is just that much more intensification of our current climate crisis. As someone with temps of 109 with heat index of 120 coming in the next few days, with all due respect,…

[flagged]

To the sibling, while I largely agree, I think there's some argument that building out additional manufacturing capacity for renewables even if it goes towards crypto mining has beneficial knock on effects for reducing the cost of the equipment provided that the learning curve effect and economies of scale outweigh the competition for resources, which to be fair isn't guaranteed.
Post reply on HN