Hi forest,
Yeah, I think your concern is valid.
Looking at the current ipv6-rules.sh, some known
provider ranges are grouped by /64 or /80, while anything outside
those ranges is handled as /128. Even with /64 grouping, someone
with a routed /48 still has a huge number of prefixes to rotate
through.
So the current limits can still be worked around by changing
prefixes. A global IPv6 cap could help protect the relay, but
without fallback it would also block legitimate IPv6 users once
the cap is hit.
Wider prefix limits or a global emergency cap might help, but both
risk blocking innocent users too. This looks like a real IPv6
limitation in the current rules.
Cheers,
rE-Bo0t.bx1
https://relays.brokenbotnet.com
Hello.> _______________________________________________ > tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx > To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx
rE-Bo0t.bx1 wrote:
> Short answer: no, Tor doesn't do Happy Eyeballs for OR connections.
> Whatever address family gets picked for a connection attempt is what
> gets tried, and if it fails, that's it for that attempt. Tor won't turn
> around and retry the same relay over IPv4. A later circuit attempt may
> try again or choose another path, but that's separate, not a fallback.
The reason I ask is because I'm considering implications of the toralf
tor-ddos script on relays that use IPv6. By its very design, there are a
number of hosting providers that will provide, say, a routed /48 for a
low cost which could then be used to completely overwhelm the IPv6 anti-
DDoS firewall rules (unlike the IPv4 rules where an attacker would need
to buy a costly new IPv4 just to get an additional 8 connections).
If a hard limit for the number of simultaneous IPv6 connections were set,
then that would force the attacker to fall back to IPv4 long before the
relay is actually overwhelmed, but that would also prevent anyone else
from connecting with IPv6. If connections fell back to IPv4 after failure
to connect with IPv6, it could be a solution. It's unfortunate they don't.
As it is, it seems like the anti-DDoS script and firewall rules are only
effective on dual-stack relays so long as no attacker figures out that
there are plenty of routed IPv6 netblocks that they can cheaply use.
Regards,
forest
Attachment:
OpenPGP_0xB3BD6196E1CFBFB4.asc
Description: OpenPGP public key
Attachment:
OpenPGP_signature.asc
Description: OpenPGP digital signature
_______________________________________________ tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx