[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-relays] Re: How is this attack causing 900 Mbps download and 100 Mbps upload?
On 2026-09-10 01:31, forest via tor-relays wrote:
Can someone find a few IPs that are participating in this attack and
send tcpdump output (with timestamps)? I'm curious if there's a timing
pattern that could be exploited for detection.
I was, unfortunately, more interested in defending than analysis and I
no longer have any attacked nodes.
I only have six relays I run or manage, and two of them had been
attacked simultaneously. Including one I would consider a point of
interest, which is why I am concerned these are not just DoS attacks but
aimed at deanonymizing some traffic. I can imagine several effective
timing attacks against tor anonymity that would be highly effective for
anyone with the ability to inject disproportionate traffic at will.
By shutting down Tor and restarting it 15 minutes later, I was able to
get the attack to stop. In another case when I realized it was
targeting
another relay of mine, I had to wait over an hour with Tor off before
it
stopped.
I find the attacks stop within an hour of activating DirCache 0. Likely
as the attacker realizes their attack is spinning its wheels and no
longer achieving asymmetric replies.
There is also a forum discussion on these attacks. I highly recommend
developer input into this as automated defenses from outside tor is
problematic at best. My recommendations to developers are in the forum
post:
https://v236xhqtyullodhf26szyjepvkbv6iitrhjgrqj4avaoukebkk6n6syd.onion/t/traffic-disbalance-and-overload/21926/2
The fact that this attack is a) highly effective, b) circumvents most or
all of current firewall protections, and c) NOT widespread leads me to
believe it is in use in the wild not to destabilize but either as a
proof of concept for something that *could* destabilize Tor at
(someone's) will, and/or as a current deanonymizing tool in targeted
current use.
So I will reiterate what I said in the forum, that I think this is a
serious threat to Tor.
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx