Hi Sebastian,

I have started a discussion among dirauth operators on how to deal with
relays who are actively harming outdated clients like that.

As someone who advocated for many years that the torproject and tor
directory authorities should take a stronger stance on relays without proper
family configuration I really appreciate if tor directory authorities would 
finally
be more active and take actions against such relays.

That would be unexpected and surprising but a very welcome and positive outcome.

Please do not limit the removal of relays to just relays putting end-of-life 
tor clients at risk but **also**
include relays that put currently supported tor clients at risk. MyFamily does 
not support super large groups as you know.

To avoid surprising relay operators I would suggest to officially announce that 
change in actually enforced policy
because operators are not used to it since many run relays in their current 
configuration since a long time
and directory authorities never did take any actions against them.

I've been in contact with one large operator that would be affected and they 
confirmed that they will update their configuration soon.

In OrNetStats I had(*) a dedicated section for relay groups that have an actual 
chance to perform end-to-end correlation attacks:

Operators are only listed if they actually have a chance to do end-to-end 
correlation attacks, that is:

- their guard and exit probability is > 0%
- they did not properly configure MyFamily
- they run in more than a single /16 network block

(*) unfortunatelly onionoo data quality is still not back to how it used to be 
before the CollecTor/collector-rs change on 2026-04-02,
therefore OrNetStats has not been updated since March 2026 because it depends 
on collector and onionoo data.

kind regards,
nusenu
--
https://nusenu.github.io


_______________________________________________
tor-relays mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to