Earlier quoted context omitted.
The attacker would need way more power actually, to send enough requests to flood the server. You only want to get one request in. If the server can process 10k requests per minute, and you need to send 10 requests per minute, you only need 0.1% as much power.
My phone CPU normally draws well under a watt, but a server normally draws well over 100 watts.
Proof-of-Work Defense for Onion Services
141–150 of 159 posts
Re: Proof-of-Work Defense for Onion Services
#142Really interesting! Digging into the proposal [1]: > make it harder for attackers to overload the service with introduction request > We hope that this proposal can help us defend against the script-kiddie attacker and small botnets. Sets expectations: does not counter large botnets. > We hope that this proposal will allow the motivated user to always connect A user who really wants to connect can get through durring…
So now you have the drawbacks of both as well, in that the guy who has the most compute to use as a toaster can DoS everyone else. Plus, PoW is nothing but wasted, needless computation . Computing is not free . Every watt spent doing anything PoW is just that much more intensification of our current climate crisis. As someone with temps of 109 with heat index of 120 coming in the next few days, with all due respect,…
Every watt spent doing anything, period, right? Like using your computer to send comments on HN?
Or streaming video? Or any one of a million things that humans do which aren't strictly necessary for survival but we do them anyway?
The tirade against PoW is absurd. It's useful, get over it.
Re: Proof-of-Work Defense for Onion Services
#143It's a shame that Torproject has decided to reinvent its own wheel, lagging 10 years behind the crypto crowd, instead of integrating with existing coin(s). The problem is, such integration would require the chosen coin to be anonymous, which is essentially forbidden: https://www.theverge.com/2023/8/23/23843161/tornado-cash-ind...
You understood nothing and gave your opinion. Congratulations, tell us more about how offtopic you are? This proof of work doesn't mean crypto currency, it doesn't mean coins, it doesn't mean buying or selling tokens. It means proof of work. More exactly, having to put your computer at work in order to solve an equation. If you do that, the server lets you in. If you don't, you can't enter. This is the original proof…
Well, yes, I should've said 30 years, not 10.
You can start educating yourself on cryptocurrencies with the monero case: monero payments were used instead of captcha on an internet forum about 10 years ago.
Re: Proof-of-Work Defense for Onion Services
#144This has been suggested before, for email spam. Cloudflare could do this, too. Every time you access a busy site, seconds to minutes of useless crunching. The overall effect would be to drain batteries worldwide.
Re: Proof-of-Work Defense for Onion Services
#145It's a start but eventually I'd be great to add some sort of payment layer much like bitcoin lightening. If running a node pays much more people would be willing to do so.
Re: Proof-of-Work Defense for Onion Services
#146Earlier quoted context omitted.
> I'm surprised something like this wasn't done sooner, It should have been, but was delayed by people shrieking about oceans boiling.
>shrieking No one is doing any such thing.
>salawat
>PoW is nothing but wasted, needless computation. Computing is not free. Every watt spent doing anything PoW is just that much more intensification of our current climate crisis.
>As someone with temps of 109 with heat index of 120 coming in the next few days, with all due respect, fuck anyone who proposes PoW is a good idea for anything.
>It isn't interesting. It's the most egregious example of conspicuous consumption on the planet.
Re: Proof-of-Work Defense for Onion Services
#147Really interesting! Digging into the proposal [1]: > make it harder for attackers to overload the service with introduction request > We hope that this proposal can help us defend against the script-kiddie attacker and small botnets. Sets expectations: does not counter large botnets. > We hope that this proposal will allow the motivated user to always connect A user who really wants to connect can get through durring…
This version is good, don't get me wrong, but adding value transfer would be better imo.
Re: Proof-of-Work Defense for Onion Services
#148Earlier quoted context omitted.
So now you have the drawbacks of both as well, in that the guy who has the most compute to use as a toaster can DoS everyone else. Plus, PoW is nothing but wasted, needless computation . Computing is not free . Every watt spent doing anything PoW is just that much more intensification of our current climate crisis. As someone with temps of 109 with heat index of 120 coming in the next few days, with all due respect,…
Maybe we can ask the DoSers to stop, nicely? Everything else being equal, I bet the Tor/Onion-folk are pretty smart people, and this is what they felt was necessary to keep the service running.
That's an appeal to authority and an attempt to shut down inquisitive thought and investigation.
Imo, this goes against the spirit of HN.
Re: Proof-of-Work Defense for Onion Services
#149Really interesting! Digging into the proposal [1]: > make it harder for attackers to overload the service with introduction request > We hope that this proposal can help us defend against the script-kiddie attacker and small botnets. Sets expectations: does not counter large botnets. > We hope that this proposal will allow the motivated user to always connect A user who really wants to connect can get through durring…
I just wish that the PoW defence actually involved some sort of transfer of value from user to provider. (as opposed to just spending resources on the user side) This version is good, don't get me wrong, but adding value transfer would be better imo.
There might be legal issues for the users too-- e.g. upgrading copyright infringement into criminally prosecutable commercial copyright infringement.
Re: Proof-of-Work Defense for Onion Services
#150Earlier quoted context omitted.
Maybe we can ask the DoSers to stop, nicely? Everything else being equal, I bet the Tor/Onion-folk are pretty smart people, and this is what they felt was necessary to keep the service running.
> Everything else being equal, I bet the Tor/Onion-folk are pretty smart people, and this is what they felt was necessary to keep the service running. That's an appeal to authority and an attempt to shut down inquisitive thought and investigation. Imo, this goes against the spirit of HN.
A better response might have been to point out that the level of POW is reactive. If there are no attacks ongoing it will use little to no resources. If it's effective, the attacks will largely stop (no point in attempting an attack that won't work) and so paradoxically this can potentially provide its benefit without actually having much usage.
If it works out that way the benefit vs costs are very good for pretty much any way of evaluating the costs. This is the kind of nuanced thinking that you'd expect from smart people, as the prior poster suggested (and, in fact, is pointed out in the design document).