Live data from Hacker News

Tor’s history of D/DoS attacks and future strategies for mitigation

forum.torproject.org

61–70 of 103 posts

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#61
post #44

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Who got kicked off of Cloudflare? Because both the cases I can think of weren't because of governments and were the sorts of schmucks that you really don't want hanging around.

KiwiFarms, The Daily Stormer

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#62

Earlier quoted context omitted.

I was curious so I went and found this : https://geti2p.net/en/comparison/tor

``` Benefits of I2P over Tor ... Java, not C (ewww) ``` Excuse me?

On the same site:

> Benefits of Tor over I2P

> ...

> - C, not Java (ewww)

It's a joke.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#63
post #44

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Who got kicked off of Cloudflare? Because both the cases I can think of weren't because of governments and were the sorts of schmucks that you really don't want hanging around.

A few companies with enough resources being able to decide who is a "schmuck that you really don't want hanging around" is worse than a government doing it IMO. At least the latter have to pretend to follow process and be accountable to the people

Though I'm not sure how to really solve it. I support ISPs being considered utilities with an obligation to serve any customer unless they can argue a compelling reason why they can't, but DDoS protection is not a technical essential like an internet connection is. Even if it's almost essential for a popular site in 2023

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#64

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Have you actually run any sort of web service/website without Cloudflare? This sounds like something straight out of a sales reps mouth, obviously there is more solutions than just Cloudflare out there...

Yes, you can roll your own protection but if kiwifarms is any indication it becomes your full time job.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#65

Earlier quoted context omitted.

A bit dramatic right? Sure, it might be more expensive and difficult but obviously you can run your own WAF, DDOS protection etc.

There are quite a few options, but what could be heard through the grapevines with Kiwifarms most turn out to be theoretical once attackers are motivated enough. Think about them what you will, they make a great canary.

>they make a great canary

People are naively willing to look to other for a dangerous precedent went it is happening to a person or group that they dislike.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#67
post #2

Has anyone tried using TOR as a replacement for Cloudflare DDOS protection? There is a single hop mode on hidden services.

> There is a single hop mode on hidden services. These[0][1][2]? [0]: https://blog.torproject.org/whats-new-tor-0298/ [1]: https://2019.www.torproject.org/docs/tor-manual.html.en#Hidd... [2]: https://2019.www.torproject.org/docs/tor-manual.html.en#Hidd...

Yes, this feature. It seems like a cheap way to put a bunch of servers between yourself and connecting users with built-in rate limiting.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#68

Earlier quoted context omitted.

Have you actually run any sort of web service/website without Cloudflare? This sounds like something straight out of a sales reps mouth, obviously there is more solutions than just Cloudflare out there...

I dont think you appreciate the threat scenario discussed here if you think its reasonable to ask for personal experience. Leaves me to wonder if i am supposed to deny having committed any crimes while we are at it? Still thank you for the response, gives the ability to clarify that this is by no means an advertisement. You have of course endless options for ddos mitigation right now. But once cloudflare no longer wa…

>But once cloudflare no longer wants you, your other options have a tendency to evaporate as well

This! If the forces persecuting you made Cloudflare to drop you, and you go, you establish your own site and your own platform your own infrastructure, unless you have some billions lying around to put fiber optical cables over the oceans physically connecting your servers to the rest of the world, you will depend on other people. And the forces persecuting you, they could just go the next level and start to demand Tier 1 providers to drop you. And the whole thing start to derailing into a cat a mouse game. Where you will have to constantly be thinking "Okay, what is their next move to deplatform me?"

Because as you said. Usually when Cloudflare drops you... it's not very absurd to assume banking institutions, Mastercard, Visa, Google, Microsoft, Amazon, etc... will also drop you. And the law pretty much allows those multibillion dollar companies to deny service to a paying costumer, which is a pretty dangerous precedent in my opinion.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#69
post #3

These are likely nation state actors who have the ability to fund these attacks. I wouldn’t be surprised if they’re using advanced techniques to slow down the network and track the routes as they traverse. I would be wary of anonymity while using tor during one of these attacks.

Eh, the techniques don't need to be that advanced or even expensive, and there are plenty of markets with motivation to DDOS their competitors. The government might even prefer that the markets stay up, so they can continue monitoring them and honeypotting criminals using them.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#70

I’ve heard passing mention of people switching to i2p because they feel the design choices of the Tor project are questionable - suggesting compromise. But these were vague assertions, is there more reading or ability to substantiate this?

I2P has been designed with "hidden services" in mind. AlphaBay, which until a few months ago was the most modern and progressive dark web market had fully moved to I2P. Stating that they saw no future in Tor, as the Tor Project refused to address major design issues even though they have heaps of money. So far using i2p has been very nice to use and the tools are well developed. I run a node myself. The way i2p works…

What was alphabay's specific complaint?
Post reply on HN