Live data from Hacker News

Ongoing DDoS on the Tor Network: Status

lists.torproject.org

1–3 of 3 posts

Re: Ongoing DDoS on the Tor Network: Status

#3
post #2

Since all TOR traffic is encrypted, how can they differentiate between legitimate TOR traffic and DDOS traffic?

I assume the DDOS is not a generic flood of traffic, but rather a particular kind of traffic that causes a disproportionate ammount of work (or, rather, memory usage) in the target. In this case, the offending component would necessarily be part of the unencrypted portion of a TOR packet that the relay is processing.