On 2026-09-12 05:52, forest via tor-relays wrote:
I agree and I'm a bit surprised that there hasn't been any announcementabout it or even acknowledgement. Even "we're aware of it and and tryingto figure out solutions" would be helpful. Although I also acknowledge that they are busy and quickly developing an ad-hoc mitigation probably isn't going to be one of their priorities. Arti is.
Arti will likely have the same vulnerability. And something that can de-anonymize connections today and which could be used to literally cripple every guard on the network tomorrow should be a priority. At least to acknowledge.
Regarding the forum post, I disagree with the suggestion that offending relays should be blacklisted.
I don't mean the relays experiencing the attack. I mean the relays sending the directory requests. These are clearly ones that are running hacked tor instances. Nothing on the outside of a tor instance can cause it to execute a directory request on another relay. So these aren't relays that are themselves being abused. These are intentionally malicious ones.
The bad news is that since the attacks are coming through malicious relays, there is little outside of tor we can do with a firewall. The good news is that every one of them will have to have a relay fingerprint that can be blacklisted.
I now have a repeat customer re-attacking a relay I manage in the same way. I'm going to do what I can to trace it before I turn off the DirCache again.
I'm getting a constant 4MiB/s download and over 40MiB/s continuous upload. I'm not even sure I have 40MiB/s bandwidth to the public internet on this machine, so this may be very targeted by someone in my provider's data center.
_______________________________________________ tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx