Live data from Hacker News

Tor’s history of D/DoS attacks and future strategies for mitigation

forum.torproject.org

91–100 of 103 posts

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#91
post #4

I wish people stopped using discourse. Sending pictures of pieces of hand written paper over email would be a more user friendly and usable interface than this javascript mess.

Absolutely not. Most mailing lists are run horribly. With horrible deliverability, security ("don't use an important password here"-clownery plus no SRS, ARC or DKIM) and a plethora of MUA idiocy sprinkled on top. Not to mention way obsolete opinions such as "no HTML at all" or "40kB maximum". Discourse is one of the nicest to use forum platforms. Works on phones, has normal notifications, proper markdown, nice menti…

It's weird how gets treated as an endorsement on this website.

For reference, me saying that emailing around pictures of handwritten text would be preferable to discourse was not an endorsement of mailing around pictures of handwritten text.

Also, as a side note, mailing list deliverability sucks because mailing list maintainers are sometimes stuck in the past and think that impersonating users while modifying messages is a good idea.

All the well ran mailing lists either don't modify messages and instead add unsubscribe headers and pass things on, or modify the messages as well as the from email addresses to avoid falling afoul of DKIM and therefore causing deliverability problems due to DMARC rejections.

HTML emails are also an abomination for replying so I am not sure what your point is there. There's basically one standard for in-line replies for plain text emails but there is no agreement on how to in-line reply to HTML emails.

But I can see how someone might dislike emails and don't think its the right solution for forums. That being said, they're still better than discourse.

List of advantages over discourse:

- Don't need a modern PC or phone to render all the javascript

- There's no mandatory (or any) javascript

- My keyboard isn't hijacked for the purposes of implementing an input scheme which doesn't match the rest of my browsing experience and therefore requires me to re-learn how to use my web browser when I go on the website

- I archive the content easily, index it myself and search through it at my leisure

- The UI is as simple as I want it to be

Forum websites should not require javascript for rendering, or even ideally posting, it was never needed it in the past and I never felt like adding javascript added anything to the user experience. It should be simple, secure, easily searchable and above all else shouldn't hijack your keyboard.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#92
post #78

Earlier quoted context omitted.

I believe cloudflare drops if they cannot withstand the level of traffic you’re being hit with, which is an exception to your suggestion. As per other posts, if CF drops you, you won’t be able to build your own ddos mitigating infra without billions. Microsoft and Amazon offer similar services, but I’m guessing cloudflare offers the best resiliency based on ops specific naming of CF.

"Literally, I woke up in a bad mood and decided someone shouldn't be allowed on the internet," wrote Mr Prince (Cloudflare CEO). https://www.bbc.com/news/technology-40960053 But they will continue to protect genocidal regime services: https://www.forbes.com/sites/thomasbrewster/2022/03/07/cloud...

> "No-one should have that power."

Is immediately after. And a person died. Clouflare are aware that they shouldn’t exist. They exist because they solve a problem that our telecoms networks and government/regulatory apparatus won’t. And it’s regarding the daily stormer.

Cloudflare keeps protecting the Russian state because if they don’t Russia will develop the technology themselves and then eat some of Cloudflare’s lunch. The effectiveness of a single period of successful DDOS attacks in a whole war is debatable.

It’s easy to stop a handful of neo Nazis. The Russian state is a lot harder. If you want Cloudflare to do it get the government to force them.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#93
post #89
post #4

I wish people stopped using discourse. Sending pictures of pieces of hand written paper over email would be a more user friendly and usable interface than this javascript mess.

For some context, I use a keyboard driven vim binding plugin for firefox to deal with the web. Discourse, aside from just being slow on older machines due to all the JS, binds half my keyboard to some nonsense. Apparently due to how firefox works, these bindings take precedence over everything else and there's no way to turn them off. This is a frustrating web experience for anyone who uses any custom bindings in a b…

> Apparently due to how firefox works, these bindings take precedence over everything else and there's no way to turn them off.

We really need a user agent that actually acts in the interest of the user.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#94
post #44

Earlier quoted context omitted.

Who got kicked off of Cloudflare? Because both the cases I can think of weren't because of governments and were the sorts of schmucks that you really don't want hanging around.

A few companies with enough resources being able to decide who is a "schmuck that you really don't want hanging around" is worse than a government doing it IMO. At least the latter have to pretend to follow process and be accountable to the people Though I'm not sure how to really solve it. I support ISPs being considered utilities with an obligation to serve any customer unless they can argue a compelling reason why…

It's not a few companies. It's private people deciding who they want to serve. And yes that can mean that you find it impossible to publish neoNazi rags online.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#95

Earlier quoted context omitted.

Have you actually run any sort of web service/website without Cloudflare? This sounds like something straight out of a sales reps mouth, obviously there is more solutions than just Cloudflare out there...

I dont think you appreciate the threat scenario discussed here if you think its reasonable to ask for personal experience. Leaves me to wonder if i am supposed to deny having committed any crimes while we are at it? Still thank you for the response, gives the ability to clarify that this is by no means an advertisement. You have of course endless options for ddos mitigation right now. But once cloudflare no longer wa…

As someone who has run services online for the last two decades, without ever using Cloudflare, you do have "options". Those options tend to be rooted in proper network engineering, DDoS mitigation, owning and operating your own ASN and advertising routes through multiple physical POPs and proper distributed hosting, with low-dynamic content.

But if by "options" you are talking about "pay someone else to deal with the problem", then sure you might be right.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#96

Earlier quoted context omitted.

>But once cloudflare no longer wants you, your other options have a tendency to evaporate as well This! If the forces persecuting you made Cloudflare to drop you, and you go, you establish your own site and your own platform your own infrastructure, unless you have some billions lying around to put fiber optical cables over the oceans physically connecting your servers to the rest of the world, you will depend on oth…

I believe cloudflare drops if they cannot withstand the level of traffic you’re being hit with, which is an exception to your suggestion. As per other posts, if CF drops you, you won’t be able to build your own ddos mitigating infra without billions. Microsoft and Amazon offer similar services, but I’m guessing cloudflare offers the best resiliency based on ops specific naming of CF.

If cloudflare dropped someone because they couldn't withstand the traffic, that would be an exceptional event that would not go unnoticed. I don't believe they do that.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#97

I’ve heard passing mention of people switching to i2p because they feel the design choices of the Tor project are questionable - suggesting compromise. But these were vague assertions, is there more reading or ability to substantiate this?

Wow, yeah I would definitely not make a decision to do something critical like that based on that kind of "evidence" lol

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#98
post #44

Earlier quoted context omitted.

Who got kicked off of Cloudflare? Because both the cases I can think of weren't because of governments and were the sorts of schmucks that you really don't want hanging around.

It was a generic statement about a path to get rid of unwanted public discourse. The problem is that paths that exist get taken. Examples of who that happened to already and your opinion of who deserves what are not the point. Its totalitarian rot, it doesnt stop, its like a moldy fruit.

Wait so your point is that if Cloudflare (or anybody?) doesn't want to do business with lying Nazis, then, the world is on an inexorable slippery slope to totalitarian fascism? That's obviously false.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#99

Earlier quoted context omitted.

It was a generic statement about a path to get rid of unwanted public discourse. The problem is that paths that exist get taken. Examples of who that happened to already and your opinion of who deserves what are not the point. Its totalitarian rot, it doesnt stop, its like a moldy fruit.

Wait so your point is that if Cloudflare (or anybody?) doesn't want to do business with lying Nazis, then, the world is on an inexorable slippery slope to totalitarian fascism? That's obviously false.

>That's obviously false.

That perspective is how being wrong looks here. Its an incredible shortsightedness, you have no basis for that degree of certainty. For starters, if it was so obvious you could explain how.

We are talking about a barrier to enter public discourse enforced through DDOS, not freedom to do business with whom you please. This robs you of the ability to self host. With zero checks and balances. You being certain that the likes of the daily stormer shouldnt exist in the public discourse doesnt absolve you of the responsibility for the delete function you just created. For which you have zero concern. That is how a totalitarian slope looks, totalitarians prick holes into the public discourse with no regards for the safe use of such holes. Unsurprising as there is no safe way to do this. Its building a horrific weapon with no targeting mechanism or safety.

You having made yourself a totalitarian through your flagrant disregard for the consequences of your actions. Your error lies in believing your intention matters more then the outcome. To the degree that safeguards became unnecessary. You could and should know better, reality always wants its toll for such behavior.

edit: Please check the comment a bit down starting with " Naive being the key point." on the use of the term totalitarian. I also mentioned stuff to read on the topic by people a lot more capable then me and and hopefully a lot harder to ignore.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#100
post #44

Earlier quoted context omitted.

Who got kicked off of Cloudflare? Because both the cases I can think of weren't because of governments and were the sorts of schmucks that you really don't want hanging around.

One of my favorite illegal streaming websites that streamed old nickelodion tv shows and the xfiles from the 90s. they had problems with cloudflare and had to deal with a lot of problems from a rival hacker group ddosing

With those shows narratives heavily influencing how we think. With some no longer available after falling through the cracks of DRM (like Malcolm in the Middle in some countries).
Post reply on HN