[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] Re: How is this attack causing 900 Mbps download and 100 Mbps upload?



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

The attacks are getting so severe against some of my more bandwidth-
constrained relays that I may begin needing to shut them down if there
is no mitigation soon. I've already started getting FUP-violation
notices from hosting providers.

I'll be trying one last thing, which is to automatically disable the
directory cache if severe asymmetric bandwidth is detected for more than
a few minutes. Unfortunately a number of issues with Tor's sandbox code
appears to prevent me from simply using "SETCONF DirCache=0" without Tor
crashing due to an assert.

On 2026-09-13 05:15, Red Oaive via tor-relays wrote:
> Ok, the attack seems to be distributed, but it looks to have a
> relatively small number of participating relays.  Here are relays that
> look like they are participating:

Are you absolutely sure that the relays themselves are participating?
Because the list you provided have relays with little in common. Some
have been around for days while others have been around for more than a
decade. Some run Linux and some run FreeBSD, etc.

> 2) They all self-report as low bandwidth servers and show data graphs
> with low data flow.  However, my relay is at this moment sending
> multiple megabytes per second to each one, enough to single handedly
> far exceed their entire reported data flow.

That's interesting. The data graphs are self-reported I believe and are
generated from Tor's bandwidth history stats in the state file. If it is
impossible for a legitimate version of Tor to self-report low bandwidth
while making these high-bandwidth requests, then that could show without
a doubt that they themselves are involved (either intentionally or they
are merely a set of relays on servers that have been compromised).

If you have solid evidence that certain relays are participating, you
should send the list to bad-relays@xxxxxxxxxxxxxxxxxxxx. You could also
open a ticket on the bug tracker. Attacks are sometimes discussed there.

Regards,
forest
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCaqepkQAKCRAw+TRLM+X4
xgn9AQCiibaPBI94i1djxzpV9H6zKDK5mPhLEFPj8M3ds6wacwD/dOFSukQM86Qn
GBdhhQJZ2iuEizZ13bWtJ19NW5Ze5gU=
=JjXU
-----END PGP SIGNATURE-----
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx