Live data from Hacker News

Tor’s history of D/DoS attacks and future strategies for mitigation

forum.torproject.org

31–40 of 103 posts

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#31

I’ve heard passing mention of people switching to i2p because they feel the design choices of the Tor project are questionable - suggesting compromise. But these were vague assertions, is there more reading or ability to substantiate this?

I was curious so I went and found this : https://geti2p.net/en/comparison/tor

```

Benefits of I2P over Tor

...

Java, not C (ewww)

```

Excuse me?

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#32
post #4

I wish people stopped using discourse. Sending pictures of pieces of hand written paper over email would be a more user friendly and usable interface than this javascript mess.

Ah yes I love how email is set up so any conversation becomes indented 200 times by quoting the entire previous chain so I have to add another monitor to see the whole thing, while being a complete mishmash of styles from different mail providers.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#33
post #27
post #7

Earlier quoted context omitted.

One of the design goals of Discourse was that it should work well on mobile phones. I guess most other forum software is either from the time of before widespread smartphone use or it doesn't consider mobile users. With that being said, I actually don't like discourse's UI and prefer more classical forums like PHPbb.

Discourse goes a bit overboard with the javascript and all the bells and whistles but I don't understand how anybody could prefer PHPbb over it, other than familiarity. That being said I always found PHPbb abysmal to use, even in the early 2000, so clearly I'm biased. My main issue with Discourse is that I prefer HN/Reddit-like threading for replies rather than linear comments, but PHPbb does the same and there are p…

> even in the early 2000

Those signatures loaded with images and longer than actual content were pretty bad.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#34

Earlier quoted context omitted.

I was curious so I went and found this : https://geti2p.net/en/comparison/tor

``` Benefits of I2P over Tor ... Java, not C (ewww) ``` Excuse me?

I feel like “written in a memory-safe language” is a fair selling point, especially when we are talking about a tool designed to accept completely untrusted data from the network and keep you safe from attackers with significant resources.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#35
post #5

What are anyones thoughts on the proof of work solution? Aside from energy use

The problem is, that it still requires an address (be it tor or IP). Even if you run the script locally, there is still a need to communicate input and output. So people can just ddos that page. Works great for combating human spam though. You tend to behave better if your login took half a day to get and expires quickly when not used. Plus build in cool down time after getting banned.

Behaving better isn't the only outcome. Another outcome is leaving the service permanently.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#36

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Have you actually run any sort of web service/website without Cloudflare? This sounds like something straight out of a sales reps mouth, obviously there is more solutions than just Cloudflare out there...

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#37
post #4

I wish people stopped using discourse. Sending pictures of pieces of hand written paper over email would be a more user friendly and usable interface than this javascript mess.

I prefer it over every forum I’ve used, especially on mobile.

Ever tried flarum? It's my preferred option in the "modern" forum realm, still pretty lightweight (even degrades gracefully without js).

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#38

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Have you actually run any sort of web service/website without Cloudflare? This sounds like something straight out of a sales reps mouth, obviously there is more solutions than just Cloudflare out there...

[deleted]

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#39
post #28

Earlier quoted context omitted.

Not a question of money. If i recall, all of these are as easy to reach for governments as cloudfare itself. Especially with the threat of KYC. Would be happy to be wrong here though.

"If a government decides they want you offline" is quite a big difference from the original "Once you get kicked off Cloudfare, thats mostly it for you".

Initial post was about controlling public discourse. Thats something where the attackers are governments. Sorry if the wording was misleading.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#40

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

A bit dramatic right? Sure, it might be more expensive and difficult but obviously you can run your own WAF, DDOS protection etc.

There are quite a few options, but what could be heard through the grapevines with Kiwifarms most turn out to be theoretical once attackers are motivated enough. Think about them what you will, they make a great canary.
Post reply on HN