Live data from Hacker News

Proof-of-Work Defense for Onion Services

blog.torproject.org

41–50 of 159 posts

Re: Proof-of-Work Defense for Onion Services

#41
post #34

I have an idea to minimize traffic on the tor network or make it faster. It should be possible to use the network as a cdn. If I want to make a file available, it should be possible for me to send pieces of the file to nodes who gave me permission to do so. When the file is requested, I then could point to these nodes. Of course, some care should be taken not to turn the tor network into a "anonymous torrent replacem…

That's kind of more the freenet model (content based), where tor is traditionally anonoymous TCP real time networking. I dont really see how it minimizes traffic on the network though. You still have to talk to the CDN nodes.

You're right. This doesn't minimizes traffic, it distributes it.

Re: Proof-of-Work Defense for Onion Services

#43
post #26

Earlier quoted context omitted.

There are PoW algorithms specifically developed to resist GPU and ASIC. Typically they do this by being memory intensive instead of (or in addition to) being compute intensive.

Regardless, you need a device that’s more powerful than whatever the attacker is using. The article says they target 1 minute solve times under load. If that’s 1 minute on a 5GHz, 64 core machine with 512GB ram, an A100 and an FPGA, then it’s going to be at least 5-15 minutes on your phone. Also, the server farm can parallelize work across an arbitrary number of challenges, but legitimate users cannot.

The attacker would need way more power actually, to send enough requests to flood the server. You only want to get one request in.

If the server can process 10k requests per minute, and you need to send 10 requests per minute, you only need 0.1% as much power.

Re: Proof-of-Work Defense for Onion Services

#44
post #36

Really interesting! Digging into the proposal [1]: > make it harder for attackers to overload the service with introduction request > We hope that this proposal can help us defend against the script-kiddie attacker and small botnets. Sets expectations: does not counter large botnets. > We hope that this proposal will allow the motivated user to always connect A user who really wants to connect can get through durring…

So now you have the drawbacks of both as well, in that the guy who has the most compute to use as a toaster can DoS everyone else. Plus, PoW is nothing but wasted, needless computation . Computing is not free . Every watt spent doing anything PoW is just that much more intensification of our current climate crisis. As someone with temps of 109 with heat index of 120 coming in the next few days, with all due respect,…

> Computing is not free.

That's the whole point.

Re: Proof-of-Work Defense for Onion Services

#45
post #36

Earlier quoted context omitted.

So now you have the drawbacks of both as well, in that the guy who has the most compute to use as a toaster can DoS everyone else. Plus, PoW is nothing but wasted, needless computation . Computing is not free . Every watt spent doing anything PoW is just that much more intensification of our current climate crisis. As someone with temps of 109 with heat index of 120 coming in the next few days, with all due respect,…

> Computing is not free. That's the whole point.

What if instead of spending energy on compute, we just spend money instead? On the one hand, some people may be turned off by the idea of spending money, but on the other hand, the two are usually interchangeable unless you're stealing energy. Someone with a lot of money and no hardware or energy can purchase hardware and energy; someone with a lot of hardware and energy can sell the hardware and sell energy back to the grid to make money.

Re: Proof-of-Work Defense for Onion Services

#46
As others have commented, it's a shame there isn't a proof of work that doesn't also hurt the planet.

It makes me wonder if there would ever be a way to actually do the opposite - your "proof of work" is somehow linked to extracting CO2 from the atmosphere?

Re: Proof-of-Work Defense for Onion Services

#47
post #36

Really interesting! Digging into the proposal [1]: > make it harder for attackers to overload the service with introduction request > We hope that this proposal can help us defend against the script-kiddie attacker and small botnets. Sets expectations: does not counter large botnets. > We hope that this proposal will allow the motivated user to always connect A user who really wants to connect can get through durring…

So now you have the drawbacks of both as well, in that the guy who has the most compute to use as a toaster can DoS everyone else. Plus, PoW is nothing but wasted, needless computation . Computing is not free . Every watt spent doing anything PoW is just that much more intensification of our current climate crisis. As someone with temps of 109 with heat index of 120 coming in the next few days, with all due respect,…

>So now you have the drawbacks of both as well

Everything has drawbacks. It's always a tradeoff in software. You want a really simple interface? Now you can't do complex things. And so on.

Instead of complaining loudly, why not be the change you want to see? Proof of CPU makes you hot? How about proof of RAM? How about about something else, which you thought of yourself, which is a great idea, which you shared with their team, which they would eagerly accept as a superior solution to proof of work?

Re: Proof-of-Work Defense for Onion Services

#48
post #36

Really interesting! Digging into the proposal [1]: > make it harder for attackers to overload the service with introduction request > We hope that this proposal can help us defend against the script-kiddie attacker and small botnets. Sets expectations: does not counter large botnets. > We hope that this proposal will allow the motivated user to always connect A user who really wants to connect can get through durring…

So now you have the drawbacks of both as well, in that the guy who has the most compute to use as a toaster can DoS everyone else. Plus, PoW is nothing but wasted, needless computation . Computing is not free . Every watt spent doing anything PoW is just that much more intensification of our current climate crisis. As someone with temps of 109 with heat index of 120 coming in the next few days, with all due respect,…

The proof of work only engages when there is a Denial of Service attack. So if you're going to be mad at anyone for useless consumption, be mad at the attacker.

Re: Proof-of-Work Defense for Onion Services

#49
post #36

Really interesting! Digging into the proposal [1]: > make it harder for attackers to overload the service with introduction request > We hope that this proposal can help us defend against the script-kiddie attacker and small botnets. Sets expectations: does not counter large botnets. > We hope that this proposal will allow the motivated user to always connect A user who really wants to connect can get through durring…

So now you have the drawbacks of both as well, in that the guy who has the most compute to use as a toaster can DoS everyone else. Plus, PoW is nothing but wasted, needless computation . Computing is not free . Every watt spent doing anything PoW is just that much more intensification of our current climate crisis. As someone with temps of 109 with heat index of 120 coming in the next few days, with all due respect,…

I think the presence of this PoW system might mean that this form of abuse is discouraged enough that in practice it means that PoW will not be required. Who is going to compete with a huge amount of compute to DoS others? They'd need the same compute as all legitimate access put together to get to just 50% effectiveness.

If this is the case and in practice PoW is never required, then your rant is moot, and instead it is interesting that this effect occurs.

Re: Proof-of-Work Defense for Onion Services

#50
post #46

As others have commented, it's a shame there isn't a proof of work that doesn't also hurt the planet. It makes me wonder if there would ever be a way to actually do the opposite - your "proof of work" is somehow linked to extracting CO2 from the atmosphere?

If you sell carbon credits, the money you make doing so is proof that you did it (well, it's proof that you did something of value, which could also count).
Post reply on HN