Live data from Hacker News

Tor’s history of D/DoS attacks and future strategies for mitigation

forum.torproject.org

81–90 of 103 posts

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#81

Earlier quoted context omitted.

I was curious so I went and found this : https://geti2p.net/en/comparison/tor

``` Benefits of I2P over Tor ... Java, not C (ewww) ``` Excuse me?

It's joke that every one will hate one or the other. They make the same joke the other direction.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#82

Earlier quoted context omitted.

>But once cloudflare no longer wants you, your other options have a tendency to evaporate as well This! If the forces persecuting you made Cloudflare to drop you, and you go, you establish your own site and your own platform your own infrastructure, unless you have some billions lying around to put fiber optical cables over the oceans physically connecting your servers to the rest of the world, you will depend on oth…

I believe cloudflare drops if they cannot withstand the level of traffic you’re being hit with, which is an exception to your suggestion. As per other posts, if CF drops you, you won’t be able to build your own ddos mitigating infra without billions. Microsoft and Amazon offer similar services, but I’m guessing cloudflare offers the best resiliency based on ops specific naming of CF.

We don’t drop customers who get DDoSed. That would be crazy. https://blog.cloudflare.com/unmetered-mitigation/

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#83

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Have you actually run any sort of web service/website without Cloudflare? This sounds like something straight out of a sales reps mouth, obviously there is more solutions than just Cloudflare out there...

A lot of these solutions don't actually mitigate large DDoS attacks, or have enormous loopholes that can be bypassed by a novice attacker. I've heard that OVH's DDoS protection used to let in other OVH servers, for example.

When I checked, some of the equivalents to Cloudflare's lower plans cost hundreds of dollars a month.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#84
post #56

Another tor page says ddos attacks primarily use UDP packets, which tor doesn't allow: https://support.torproject.org/abuse/what-about-ddos/ So, is this an attack using a different method? And what about mitigating attacks on other networks/sites that originate from tor? The site I linked only said "attackers who control enough bandwidth to launch an effective DDoS attack can do it just fine without Tor." They didn't…

There have been cases of darknet markets employing enormous botnets to layer 7 DDoS their rivals, by constantly requesting data from the site through seemingly legitimate requests. Considering that Proof of Work is one of the primary things they're looking into, it's probably something similar to this.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#85
post #2

Has anyone tried using TOR as a replacement for Cloudflare DDOS protection? There is a single hop mode on hidden services.

I've run it in NonAnonymous mode as an experiment. Not to replace a CDN for DDoS protection but to replace the CDN as a way to anonymize where the server is because people play games to try to cancel hosting accounts when they get mad about topics being discussed. When they can't control the narrative they will start emailing abuse@ making false claims and some hosting providers are lazy. From the DDoS aspect, people…

I've done a POC before where the main site was a tor hidden service, and I had cheap VPSs acting as a clearnet reverse proxy to it

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#86

Earlier quoted context omitted.

Have you actually run any sort of web service/website without Cloudflare? This sounds like something straight out of a sales reps mouth, obviously there is more solutions than just Cloudflare out there...

A lot of these solutions don't actually mitigate large DDoS attacks, or have enormous loopholes that can be bypassed by a novice attacker. I've heard that OVH's DDoS protection used to let in other OVH servers, for example. When I checked, some of the equivalents to Cloudflare's lower plans cost hundreds of dollars a month.

> OVH's DDoS protection used to let in other OVH servers

And why wouldn't they? If you're getting ddos'd on OVH from OVH, they'll just turn off the source of the traffic rather than trying to fight it on the receiving end.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#87
post #4

I wish people stopped using discourse. Sending pictures of pieces of hand written paper over email would be a more user friendly and usable interface than this javascript mess.

Most of your typical self-hosted forums aren't much better, just more familiar.

Most of your typical self-hosted forums don't have excessive amounts of javascript which override half your keyboard inputs.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#88

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Have you actually run any sort of web service/website without Cloudflare? This sounds like something straight out of a sales reps mouth, obviously there is more solutions than just Cloudflare out there...

Yes? I haven’t used cloudflare in years now.

99.9% of the time you literally don’t need their services.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#89
post #4

I wish people stopped using discourse. Sending pictures of pieces of hand written paper over email would be a more user friendly and usable interface than this javascript mess.

For some context, I use a keyboard driven vim binding plugin for firefox to deal with the web. Discourse, aside from just being slow on older machines due to all the JS, binds half my keyboard to some nonsense. Apparently due to how firefox works, these bindings take precedence over everything else and there's no way to turn them off.

This is a frustrating web experience for anyone who uses any custom bindings in a browser and it repeats itself every time I use one of these websites.

Lastly, I have no idea why forum software needs absolutely any javascript to just render a basic page. Discourse renders as a blank page with javascript disabled, that's just extremely unnecessary.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#90
post #44

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Who got kicked off of Cloudflare? Because both the cases I can think of weren't because of governments and were the sorts of schmucks that you really don't want hanging around.

One of my favorite illegal streaming websites that streamed old nickelodion tv shows and the xfiles from the 90s. they had problems with cloudflare and had to deal with a lot of problems from a rival hacker group ddosing
Post reply on HN