I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.
Who got kicked off of Cloudflare? Because both the cases I can think of weren't because of governments and were the sorts of schmucks that you really don't want hanging around.
Tor’s history of D/DoS attacks and future strategies for mitigation
61–70 of 103 posts
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#62Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#63I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.
Who got kicked off of Cloudflare? Because both the cases I can think of weren't because of governments and were the sorts of schmucks that you really don't want hanging around.
Though I'm not sure how to really solve it. I support ISPs being considered utilities with an obligation to serve any customer unless they can argue a compelling reason why they can't, but DDoS protection is not a technical essential like an internet connection is. Even if it's almost essential for a popular site in 2023
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#64I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.
Have you actually run any sort of web service/website without Cloudflare? This sounds like something straight out of a sales reps mouth, obviously there is more solutions than just Cloudflare out there...
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#65Earlier quoted context omitted.
A bit dramatic right? Sure, it might be more expensive and difficult but obviously you can run your own WAF, DDOS protection etc.
There are quite a few options, but what could be heard through the grapevines with Kiwifarms most turn out to be theoretical once attackers are motivated enough. Think about them what you will, they make a great canary.
People are naively willing to look to other for a dangerous precedent went it is happening to a person or group that they dislike.
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#66Has anyone tried using TOR as a replacement for Cloudflare DDOS protection? There is a single hop mode on hidden services.
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#67Has anyone tried using TOR as a replacement for Cloudflare DDOS protection? There is a single hop mode on hidden services.
> There is a single hop mode on hidden services. These[0][1][2]? [0]: https://blog.torproject.org/whats-new-tor-0298/ [1]: https://2019.www.torproject.org/docs/tor-manual.html.en#Hidd... [2]: https://2019.www.torproject.org/docs/tor-manual.html.en#Hidd...
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#68Earlier quoted context omitted.
Have you actually run any sort of web service/website without Cloudflare? This sounds like something straight out of a sales reps mouth, obviously there is more solutions than just Cloudflare out there...
I dont think you appreciate the threat scenario discussed here if you think its reasonable to ask for personal experience. Leaves me to wonder if i am supposed to deny having committed any crimes while we are at it? Still thank you for the response, gives the ability to clarify that this is by no means an advertisement. You have of course endless options for ddos mitigation right now. But once cloudflare no longer wa…
This! If the forces persecuting you made Cloudflare to drop you, and you go, you establish your own site and your own platform your own infrastructure, unless you have some billions lying around to put fiber optical cables over the oceans physically connecting your servers to the rest of the world, you will depend on other people. And the forces persecuting you, they could just go the next level and start to demand Tier 1 providers to drop you. And the whole thing start to derailing into a cat a mouse game. Where you will have to constantly be thinking "Okay, what is their next move to deplatform me?"
Because as you said. Usually when Cloudflare drops you... it's not very absurd to assume banking institutions, Mastercard, Visa, Google, Microsoft, Amazon, etc... will also drop you. And the law pretty much allows those multibillion dollar companies to deny service to a paying costumer, which is a pretty dangerous precedent in my opinion.
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#69These are likely nation state actors who have the ability to fund these attacks. I wouldn’t be surprised if they’re using advanced techniques to slow down the network and track the routes as they traverse. I would be wary of anonymity while using tor during one of these attacks.
Re: Tor’s history of D/DoS attacks and future strategies for mitigation
#70I’ve heard passing mention of people switching to i2p because they feel the design choices of the Tor project are questionable - suggesting compromise. But these were vague assertions, is there more reading or ability to substantiate this?
I2P has been designed with "hidden services" in mind. AlphaBay, which until a few months ago was the most modern and progressive dark web market had fully moved to I2P. Stating that they saw no future in Tor, as the Tor Project refused to address major design issues even though they have heaps of money. So far using i2p has been very nice to use and the tools are well developed. I run a node myself. The way i2p works…