[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-relays] Re: If the IPv6 ORPort can't be reached, will clients/relays fall back to the IPv4 ORPort?
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Hello.
rE-Bo0t.bx1 wrote:
> Short answer: no, Tor doesn't do Happy Eyeballs for OR connections.
> Whatever address family gets picked for a connection attempt is what
> gets tried, and if it fails, that's it for that attempt. Tor won't turn
> around and retry the same relay over IPv4. A later circuit attempt may
> try again or choose another path, but that's separate, not a fallback.
The reason I ask is because I'm considering implications of the toralf
tor-ddos script on relays that use IPv6. By its very design, there are a
number of hosting providers that will provide, say, a routed /48 for a
low cost which could then be used to completely overwhelm the IPv6 anti-
DDoS firewall rules (unlike the IPv4 rules where an attacker would need
to buy a costly new IPv4 just to get an additional 8 connections).
If a hard limit for the number of simultaneous IPv6 connections were set,
then that would force the attacker to fall back to IPv4 long before the
relay is actually overwhelmed, but that would also prevent anyone else
from connecting with IPv6. If connections fell back to IPv4 after failure
to connect with IPv6, it could be a solution. It's unfortunate they don't.
As it is, it seems like the anti-DDoS script and firewall rules are only
effective on dual-stack relays so long as no attacker figures out that
there are plenty of routed IPv6 netblocks that they can cheaply use.
Regards,
forest
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCal7DNAAKCRAw+TRLM+X4
xiY4AP9ZrbdRHeQC/RVe7XH7B0Q9wAzpUpHmSxC1M0ifWHs6FQEA0urIqk7LHNJ5
hoR3PiMXH0VD3VSR0Dbmp4P9/nln8AE=
=QkjG
-----END PGP SIGNATURE-----
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx