Live data from Hacker News

Tor’s history of D/DoS attacks and future strategies for mitigation

forum.torproject.org

11–20 of 103 posts

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#11
I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#13
post #4

I wish people stopped using discourse. Sending pictures of pieces of hand written paper over email would be a more user friendly and usable interface than this javascript mess.

I wish for the opposite.

Why?

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#15

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

It really isn't that dire, AWS has Shield (or really just Cloudfront), GPC has Cloud Armor, Azure has "Azure DDoS Protection", everything on Digital Ocean is protected by default. And if you're on-prem or colo then even a modestly sized edge router can handle quite a bit of traffic. And if all you want is the CDN part and not origin protection then every commercial CDN does DDoS protection.

If you mean "providing expensive protection services for free on a $5/mo VPC" then sure Cloudflare might be your only bet.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#16
post #15

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

It really isn't that dire, AWS has Shield (or really just Cloudfront), GPC has Cloud Armor, Azure has "Azure DDoS Protection", everything on Digital Ocean is protected by default. And if you're on-prem or colo then even a modestly sized edge router can handle quite a bit of traffic. And if all you want is the CDN part and not origin protection then every commercial CDN does DDoS protection. If you mean "providing exp…

Not a question of money. If i recall, all of these are as easy to reach for governments as cloudfare itself. Especially with the threat of KYC. Would be happy to be wrong here though.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#17

Earlier quoted context omitted.

I wish for the opposite.

Why?

I donʼt have many strong points, it mostly feels nice to use, be it browsing or participating.

But to name a couple of points: itʼs index-able by search engines (compared to a certain similarly named popular “alternative”); robust topic tracking system: I know exactly where I left each topic off.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#18
post #4

I wish people stopped using discourse. Sending pictures of pieces of hand written paper over email would be a more user friendly and usable interface than this javascript mess.

Most of your typical self-hosted forums aren't much better, just more familiar.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#19

I’ve heard passing mention of people switching to i2p because they feel the design choices of the Tor project are questionable - suggesting compromise. But these were vague assertions, is there more reading or ability to substantiate this?

I was curious so I went and found this : https://geti2p.net/en/comparison/tor
Post reply on HN