Live data from Hacker News

Tor’s history of D/DoS attacks and future strategies for mitigation

forum.torproject.org

71–80 of 103 posts

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#71
post #59
post #33

Earlier quoted context omitted.

> even in the early 2000 Those signatures loaded with images and longer than actual content were pretty bad.

You could turn them off, you know. Yes, 20 years ago we were able to customize software for use. Mindblowing, I know.

The first 5 words of your comment were highly relevant. The rest is snark. This is HN - please don't contribute to its enshittification.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#72

Earlier quoted context omitted.

There are quite a few options, but what could be heard through the grapevines with Kiwifarms most turn out to be theoretical once attackers are motivated enough. Think about them what you will, they make a great canary.

>they make a great canary People are naively willing to look to other for a dangerous precedent went it is happening to a person or group that they dislike.

Naive being the key point.

Worth mentioning that totalitarianism is often characterized by being the rule of the stupid. Shortsighted actionism and signaling in spite of reality with the resulting corruption growing like a self destructive cancer. Bonhoeffer’s Theory of Stupidity puts it great and Meerloo giving a vivid description of what kind of societies this creates.

edit: Willful naivete is not a good life choice. Staying away from darwin awards and are not accidentally creating a fourth reich both require ongoing effort, no falling asleep on the wheel. History tells you this is a valid risk if you dont consider certain things when acting. With the guys having fought the nazis advising you to be less stupid to not repeat that. Seeing how horrible that was, maybe at least try to stay away from that instead of just intending to. This is insanely bad on the severity scale and justifies some effort. Reality is clearly lacking a bright red warning sign here with technology offering ever greater levers for less and less intentioned actions.

I can not overstate how bad of an idea it is to ignore that out of group think/tribalism and ego. It simply does not work and in hindsight you could have known. Failing so badly that nobody risks a "having told you so".

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#73

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Have you actually run any sort of web service/website without Cloudflare? This sounds like something straight out of a sales reps mouth, obviously there is more solutions than just Cloudflare out there...

Yes, AWS's WAF is very good, for instance.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#74
post #2

Has anyone tried using TOR as a replacement for Cloudflare DDOS protection? There is a single hop mode on hidden services.

I've run it in NonAnonymous mode as an experiment. Not to replace a CDN for DDoS protection but to replace the CDN as a way to anonymize where the server is because people play games to try to cancel hosting accounts when they get mad about topics being discussed. When they can't control the narrative they will start emailing abuse@ making false claims and some hosting providers are lazy. From the DDoS aspect, people could send Tor to 100% CPU but the httpd server wasn't even passing 1% CPU. This was long ago however so this observation is likely outdated. early days of v3

Nobody was able to decloak the server even being in NonAnonymous mode but the bigger issue was the ability to reach the server. At least at the time not many people had a browser that could talk to .onion sites. I don't know how many people use Brave or the Tor Browser these days so maybe now it would be less of an issue now. Maybe I will try it again soon. It's easy to send people to the Tor Onion version of your site using the Onion-Location header [1] to see how many people would be able to reach the .onion side of your site.

[1] - https://community.torproject.org/onion-services/advanced/oni...

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#75
post #71
post #59

Earlier quoted context omitted.

You could turn them off, you know. Yes, 20 years ago we were able to customize software for use. Mindblowing, I know.

The first 5 words of your comment were highly relevant. The rest is snark. This is HN - please don't contribute to its enshittification.

Go blame the software industry for throwing away what made software of yesteryear so amazing to use. I'm just a simple farmer tending to his memes.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#76

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Governments have more effective ways of deplatforming you than temporarily DDOSing your site.

Taking down a website by sending men with guns is a much worse look for them than an unpopular site succumbing to ddos attacks.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#77

Earlier quoted context omitted.

I dont think you appreciate the threat scenario discussed here if you think its reasonable to ask for personal experience. Leaves me to wonder if i am supposed to deny having committed any crimes while we are at it? Still thank you for the response, gives the ability to clarify that this is by no means an advertisement. You have of course endless options for ddos mitigation right now. But once cloudflare no longer wa…

>But once cloudflare no longer wants you, your other options have a tendency to evaporate as well This! If the forces persecuting you made Cloudflare to drop you, and you go, you establish your own site and your own platform your own infrastructure, unless you have some billions lying around to put fiber optical cables over the oceans physically connecting your servers to the rest of the world, you will depend on oth…

I believe cloudflare drops if they cannot withstand the level of traffic you’re being hit with, which is an exception to your suggestion. As per other posts, if CF drops you, you won’t be able to build your own ddos mitigating infra without billions. Microsoft and Amazon offer similar services, but I’m guessing cloudflare offers the best resiliency based on ops specific naming of CF.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#78

Earlier quoted context omitted.

>But once cloudflare no longer wants you, your other options have a tendency to evaporate as well This! If the forces persecuting you made Cloudflare to drop you, and you go, you establish your own site and your own platform your own infrastructure, unless you have some billions lying around to put fiber optical cables over the oceans physically connecting your servers to the rest of the world, you will depend on oth…

I believe cloudflare drops if they cannot withstand the level of traffic you’re being hit with, which is an exception to your suggestion. As per other posts, if CF drops you, you won’t be able to build your own ddos mitigating infra without billions. Microsoft and Amazon offer similar services, but I’m guessing cloudflare offers the best resiliency based on ops specific naming of CF.

"Literally, I woke up in a bad mood and decided someone shouldn't be allowed on the internet," wrote Mr Prince (Cloudflare CEO). https://www.bbc.com/news/technology-40960053

But they will continue to protect genocidal regime services: https://www.forbes.com/sites/thomasbrewster/2022/03/07/cloud...

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#79

Earlier quoted context omitted.

>But once cloudflare no longer wants you, your other options have a tendency to evaporate as well This! If the forces persecuting you made Cloudflare to drop you, and you go, you establish your own site and your own platform your own infrastructure, unless you have some billions lying around to put fiber optical cables over the oceans physically connecting your servers to the rest of the world, you will depend on oth…

I believe cloudflare drops if they cannot withstand the level of traffic you’re being hit with, which is an exception to your suggestion. As per other posts, if CF drops you, you won’t be able to build your own ddos mitigating infra without billions. Microsoft and Amazon offer similar services, but I’m guessing cloudflare offers the best resiliency based on ops specific naming of CF.

I think generally with cloudflare is they may be quick to drop you (or demand payment) if large DDoS is a regular occurrence for you. The free tier is generous but it dries up if your a huge target.

My company runs a a bunch of large community products and we run cloudflare in front of them to handle frequent DDoS attacks. We also pay for a cloudflare enterprise plan though.

The other side of the coin is them dropping a custom for other reasons.

https://blog.cloudflare.com/why-we-terminated-daily-stormer/

HN discussion at the time: https://news.ycombinator.com/item?id=15031922

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#80
post #4

I wish people stopped using discourse. Sending pictures of pieces of hand written paper over email would be a more user friendly and usable interface than this javascript mess.

Ah yes I love how email is set up so any conversation becomes indented 200 times by quoting the entire previous chain so I have to add another monitor to see the whole thing, while being a complete mishmash of styles from different mail providers.

That's the user and/or user agent inserting those. You can have streamlined email threads without those issues. You just don't top post.

Now, try to do encourage that behavior in a corporate environment, and you'll just get blank stares.

Post reply on HN