Live data from Hacker News

Tor’s history of D/DoS attacks and future strategies for mitigation

forum.torproject.org

41–50 of 103 posts

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#41

Earlier quoted context omitted.

I was curious so I went and found this : https://geti2p.net/en/comparison/tor

``` Benefits of I2P over Tor ... Java, not C (ewww) ``` Excuse me?

If you really dislike Java that much, there are other I2P implementations like this:

https://github.com/PurpleI2P/i2pd

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#42

Earlier quoted context omitted.

``` Benefits of I2P over Tor ... Java, not C (ewww) ``` Excuse me?

I feel like “written in a memory-safe language” is a fair selling point, especially when we are talking about a tool designed to accept completely untrusted data from the network and keep you safe from attackers with significant resources.

All of the "boring crypto" has been written in C.

https://cr.yp.to/talks/2015.10.05/slides-djb-20151005-a4.pdf

Unfortunately, Java encryption libraries are far from boring.

https://www.bleepingcomputer.com/news/security/bouncy-castle...

https://www.cvedetails.com/vulnerability-list/vendor_id-7637...

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#43

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Have you actually run any sort of web service/website without Cloudflare? This sounds like something straight out of a sales reps mouth, obviously there is more solutions than just Cloudflare out there...

I dont think you appreciate the threat scenario discussed here if you think its reasonable to ask for personal experience. Leaves me to wonder if i am supposed to deny having committed any crimes while we are at it?

Still thank you for the response, gives the ability to clarify that this is by no means an advertisement. You have of course endless options for ddos mitigation right now. But once cloudflare no longer wants you, your other options have a tendency to evaporate as well.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#44

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Who got kicked off of Cloudflare? Because both the cases I can think of weren't because of governments and were the sorts of schmucks that you really don't want hanging around.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#45
post #4

I wish people stopped using discourse. Sending pictures of pieces of hand written paper over email would be a more user friendly and usable interface than this javascript mess.

Absolutely not. Most mailing lists are run horribly. With horrible deliverability, security ("don't use an important password here"-clownery plus no SRS, ARC or DKIM) and a plethora of MUA idiocy sprinkled on top. Not to mention way obsolete opinions such as "no HTML at all" or "40kB maximum".

Discourse is one of the nicest to use forum platforms. Works on phones, has normal notifications, proper markdown, nice mention-subscription-quote system, nice plugins (such as abbreviation explainer) and it's not an eyesore.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#46
post #42

Earlier quoted context omitted.

I feel like “written in a memory-safe language” is a fair selling point, especially when we are talking about a tool designed to accept completely untrusted data from the network and keep you safe from attackers with significant resources.

All of the "boring crypto" has been written in C. https://cr.yp.to/talks/2015.10.05/slides-djb-20151005-a4.pdf Unfortunately, Java encryption libraries are far from boring. https://www.bleepingcomputer.com/news/security/bouncy-castle... https://www.cvedetails.com/vulnerability-list/vendor_id-7637...

People have done a lot of things, the track record so far has shown that to be a terrible idea.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#47
post #44

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Who got kicked off of Cloudflare? Because both the cases I can think of weren't because of governments and were the sorts of schmucks that you really don't want hanging around.

It was a generic statement about a path to get rid of unwanted public discourse. The problem is that paths that exist get taken. Examples of who that happened to already and your opinion of who deserves what are not the point.

Its totalitarian rot, it doesnt stop, its like a moldy fruit.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#48
post #4

I wish people stopped using discourse. Sending pictures of pieces of hand written paper over email would be a more user friendly and usable interface than this javascript mess.

Absolutely not. Most mailing lists are run horribly. With horrible deliverability, security ("don't use an important password here"-clownery plus no SRS, ARC or DKIM) and a plethora of MUA idiocy sprinkled on top. Not to mention way obsolete opinions such as "no HTML at all" or "40kB maximum". Discourse is one of the nicest to use forum platforms. Works on phones, has normal notifications, proper markdown, nice menti…

Jeff Atwood is one of the co-founders of Discourse and probably knows what he is doing. Compared to much of the legacy forum software, it's a big upgrade. His team also, in my experience, has offered very good support for corporate customers.

Source: Was on the team (but not the decision-maker) to replace a very large legacy forum with Discourse.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#49

I’ve heard passing mention of people switching to i2p because they feel the design choices of the Tor project are questionable - suggesting compromise. But these were vague assertions, is there more reading or ability to substantiate this?

I2P has been designed with "hidden services" in mind. AlphaBay, which until a few months ago was the most modern and progressive dark web market had fully moved to I2P. Stating that they saw no future in Tor, as the Tor Project refused to address major design issues even though they have heaps of money.

So far using i2p has been very nice to use and the tools are well developed. I run a node myself. The way i2p works is very interesting. Some services like Dread which provide i2p access have only been accessible via i2p in recent times due to the load on tor.

We'll have to see how i2p holds up when it inevitably takes over Tor and becomes a target of ddos itself.

https://geti2p.net/en/comparison/tor

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#50
post #44

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Who got kicked off of Cloudflare? Because both the cases I can think of weren't because of governments and were the sorts of schmucks that you really don't want hanging around.

this is the same line as the UK takes for encryption btw
Post reply on HN