[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] Re: How is this attack causing 900 Mbps download and 100 Mbps upload?



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Several minutes ago, another two of my servers were attacked. I need to
know what I should be doing. I only have a few ideas now:

1. No action. Keep my nodes up, at the risk of losing some of them due
to provider suspensions for extreme network and CPU overuse.

2. Temporarily set DirCache 0 when an attack is detected. This reduces
the negative effects on relaying, but network use remains very high.

3. Permanently set DirCache 0. This might cause the attacker to skip my
relays, but that also means I won't be providing any guards.

4. Shut down the relay for a few hours as soon as an attack starts. This
eliminates bandwidth but also means the attacker controls my uptime.

Until discussion begins for implementing a BEGIN_DIR rate-limiter and a
mitigation rolled out, the attacker will continue completely unimpeded
and users will likely be deanonymized, assuming that is their intent.

In the meantime, I have temporarily shut down those relays.

Regards,
forest
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCarnJrgAKCRAw+TRLM+X4
xjGVAP9GTmust6eS0wf8ZR8RIV02198zRC8aE7jRxx/bikxtIAEAkCamVOmt31cK
jR4rsrxIk70pFzzgC8HDvVeiQDlWCAY=
=3zSF
-----END PGP SIGNATURE-----
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx