I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.
Who got kicked off of Cloudflare? Because both the cases I can think of weren't because of governments and were the sorts of schmucks that you really don't want hanging around.
Tor’s history of D/DoS attacks and future strategies for mitigation
51–60 of 103 posts
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#52I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.
A bit dramatic right? Sure, it might be more expensive and difficult but obviously you can run your own WAF, DDOS protection etc.
In addition to a lot of clever tricks ddos protection comes down to a simple question. Who has more resources to keep going.
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#53Earlier quoted context omitted.
"If a government decides they want you offline" is quite a big difference from the original "Once you get kicked off Cloudfare, thats mostly it for you".
Initial post was about controlling public discourse. Thats something where the attackers are governments. Sorry if the wording was misleading.
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#54I wish people stopped using discourse. Sending pictures of pieces of hand written paper over email would be a more user friendly and usable interface than this javascript mess.
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#55I’ve heard passing mention of people switching to i2p because they feel the design choices of the Tor project are questionable - suggesting compromise. But these were vague assertions, is there more reading or ability to substantiate this?
I2P has been designed with "hidden services" in mind. AlphaBay, which until a few months ago was the most modern and progressive dark web market had fully moved to I2P. Stating that they saw no future in Tor, as the Tor Project refused to address major design issues even though they have heaps of money. So far using i2p has been very nice to use and the tools are well developed. I run a node myself. The way i2p works…
Like is it like that Swiss encryption company that kept bricking the encryption for the CIA and employees kept noticing intentional encryption flaws and being told to work on something else?
or something else
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#56https://support.torproject.org/abuse/what-about-ddos/
So, is this an attack using a different method?
And what about mitigating attacks on other networks/sites that originate from tor? The site I linked only said "attackers who control enough bandwidth to launch an effective DDoS attack can do it just fine without Tor." They didn't say anything about mitigating the use of tor by attackers. And what they're saying about attacks not being possible on the network is clearly wrong.
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#57Another tor page says ddos attacks primarily use UDP packets, which tor doesn't allow: https://support.torproject.org/abuse/what-about-ddos/ So, is this an attack using a different method? And what about mitigating attacks on other networks/sites that originate from tor? The site I linked only said "attackers who control enough bandwidth to launch an effective DDoS attack can do it just fine without Tor." They didn't…
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#58Earlier quoted context omitted.
Initial post was about controlling public discourse. Thats something where the attackers are governments. Sorry if the wording was misleading.
How is DDOS protection the issue then? Isn’t the issue just DDOS?
Centralized DDOS protection and DDOS seem to be two sides of the same coin, so i dont understand what the distinction would entail.
edit: You could argue that DDOS is an equal opportunity tool, while the threat of getting kicked off cloudflare is reserved for a selected few. So the difference would be which is more at threat of getting exploited. Hope that helps.
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#59Earlier quoted context omitted.
Discourse goes a bit overboard with the javascript and all the bells and whistles but I don't understand how anybody could prefer PHPbb over it, other than familiarity. That being said I always found PHPbb abysmal to use, even in the early 2000, so clearly I'm biased. My main issue with Discourse is that I prefer HN/Reddit-like threading for replies rather than linear comments, but PHPbb does the same and there are p…
> even in the early 2000 Those signatures loaded with images and longer than actual content were pretty bad.
Yes, 20 years ago we were able to customize software for use. Mindblowing, I know.
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#60I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.