[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #8435 [Tor]: Ignore advertised bandwidths for flags once we have enough measured bandwidths

#8435: Ignore advertised bandwidths for flags once we have enough measured
 Reporter:  andrea       |          Owner:                    
     Type:  enhancement  |         Status:  new               
 Priority:  major        |      Milestone:  Tor: 0.2.4.x-final
Component:  Tor          |        Version:  Tor: unspecified  
 Keywords:  tor-auth     |         Parent:                    
   Points:               |   Actualpoints:                    

Comment(by andrea):

 There's also a dirserv_compute_performance_thresholds() which calls
 dirserv_get_bandwidth_for_router() directly and through
 router_counts_toward_thresholds().  The fix for 8273 altered the behavior
 here to use measured bandwidths rather than advertised when available.
 What possible attacks might be enabled by distorting the thresholds by
 spamming the dirauths with bogus bandwidth advertisements?  We should
 contemplate this too once we have setting flags nailed down.

Ticket URL: <https://trac.torproject.org/projects/tor/ticket/8435#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
tor-bugs mailing list