Live data from Hacker News

Tor’s history of D/DoS attacks and future strategies for mitigation

forum.torproject.org

51–60 of 103 posts

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#51
post #44

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Who got kicked off of Cloudflare? Because both the cases I can think of weren't because of governments and were the sorts of schmucks that you really don't want hanging around.

Remember when google was one of the “not evil” companies? When it comes to internet companies we have got burned so many times it’s good to keep a healthy dose of skepticism when it comes to a company that potentially decides if you are able to survive on the internet.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#52

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

A bit dramatic right? Sure, it might be more expensive and difficult but obviously you can run your own WAF, DDOS protection etc.

Yes you can defend on your own. But it’s going to cost you a lot of resources.

In addition to a lot of clever tricks ddos protection comes down to a simple question. Who has more resources to keep going.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#53
post #28

Earlier quoted context omitted.

"If a government decides they want you offline" is quite a big difference from the original "Once you get kicked off Cloudfare, thats mostly it for you".

Initial post was about controlling public discourse. Thats something where the attackers are governments. Sorry if the wording was misleading.

How is DDOS protection the issue then? Isn’t the issue just DDOS?

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#55

I’ve heard passing mention of people switching to i2p because they feel the design choices of the Tor project are questionable - suggesting compromise. But these were vague assertions, is there more reading or ability to substantiate this?

I2P has been designed with "hidden services" in mind. AlphaBay, which until a few months ago was the most modern and progressive dark web market had fully moved to I2P. Stating that they saw no future in Tor, as the Tor Project refused to address major design issues even though they have heaps of money. So far using i2p has been very nice to use and the tools are well developed. I run a node myself. The way i2p works…

Yeah I think I saw AlphaBay’s complaint and was hoping there was an elaboration

Like is it like that Swiss encryption company that kept bricking the encryption for the CIA and employees kept noticing intentional encryption flaws and being told to work on something else?

or something else

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#56
Another tor page says ddos attacks primarily use UDP packets, which tor doesn't allow:

https://support.torproject.org/abuse/what-about-ddos/

So, is this an attack using a different method?

And what about mitigating attacks on other networks/sites that originate from tor? The site I linked only said "attackers who control enough bandwidth to launch an effective DDoS attack can do it just fine without Tor." They didn't say anything about mitigating the use of tor by attackers. And what they're saying about attacks not being possible on the network is clearly wrong.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#57
post #56

Another tor page says ddos attacks primarily use UDP packets, which tor doesn't allow: https://support.torproject.org/abuse/what-about-ddos/ So, is this an attack using a different method? And what about mitigating attacks on other networks/sites that originate from tor? The site I linked only said "attackers who control enough bandwidth to launch an effective DDoS attack can do it just fine without Tor." They didn't…

This is for protecting against attacks against the Tor network and onion services. Not for preventing people using Tor to conduct ddos attacks on normal websites which is what your linked page discusses

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#58

Earlier quoted context omitted.

Initial post was about controlling public discourse. Thats something where the attackers are governments. Sorry if the wording was misleading.

How is DDOS protection the issue then? Isn’t the issue just DDOS?

Somebody else asked this but deleted before i could respond, so i am glad you asked.

Centralized DDOS protection and DDOS seem to be two sides of the same coin, so i dont understand what the distinction would entail.

edit: You could argue that DDOS is an equal opportunity tool, while the threat of getting kicked off cloudflare is reserved for a selected few. So the difference would be which is more at threat of getting exploited. Hope that helps.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#59
post #33
post #27

Earlier quoted context omitted.

Discourse goes a bit overboard with the javascript and all the bells and whistles but I don't understand how anybody could prefer PHPbb over it, other than familiarity. That being said I always found PHPbb abysmal to use, even in the early 2000, so clearly I'm biased. My main issue with Discourse is that I prefer HN/Reddit-like threading for replies rather than linear comments, but PHPbb does the same and there are p…

> even in the early 2000 Those signatures loaded with images and longer than actual content were pretty bad.

You could turn them off, you know.

Yes, 20 years ago we were able to customize software for use. Mindblowing, I know.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#60

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Governments have more effective ways of deplatforming you than temporarily DDOSing your site.
Post reply on HN