-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Hello.
I'm finding very good success automatically blocking an entire /24 (and /64 for IPv6) with a >8/m over 2m and 16/h over 1h. Obviously the list of Tor relays is whitelisted (kept up to date with the cached consensus file that's added to an nftables set). This substantially reduces the amount of malicious load on my relays compared to the original ruleset. I also drop established connections once they are blacklisted, otherwise I keep seeing the same Contabo and Hetzner IPs remaining connected and continue using a significant amount of resources. There seem to be no false positives as the chances that multiple people in the same /24 would be using me as their guard and all restarting Tor within the same few minutes is very low. Regards, forest -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCambCOAAKCRAw+TRLM+X4 xtaxAQCGefZYBo3ixdwkf8iq4xVJw/MpVcSBW+6vcXXPd3xDzgEA7V0vFgo+8BCY mR3hK2f4oheOtdjYFFKR2RM1c1+14A0= =ZtJu -----END PGP SIGNATURE----- _______________________________________________ tor-relays mailing list -- [email protected] To unsubscribe send an email to [email protected]
