-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

How many simultaneous connections are involved in one of these directory
fetching attacks? If it's only a few, a simple ratelimit in a firewall
might be able to help mitigate it. It's a shame the DirPort and ORPort
are combined now or we could apply rate-limiting selectively on DirPort.

Btw, simply restarting the relay seems to interrupt the attack, probably
because the attacker doesn't continuously retry the same relay if the
connection gets broken. But that probably kicks them to another relay.

I'm guessing the attack works by simultaneously fetching directory data
over and over to overload the CPU with compression work? Perhaps a long-
term mitigation would be for the Tor process to switch to a lower level
of compression (e.g. the equivalent of zstd -1) if it detects that the
bottleneck is becoming the CPU rather than the network.

Regards,
forest
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCanE98QAKCRAw+TRLM+X4
xvjEAP96v7/UU+mz/kMdACM31oaVGrIfRpbta0JzAfn7UEgFaAD/YPjrjLiX0syt
dh5nIaFQM5/JB9xbBMKikZj2DXhTEwg=
=2uOn
-----END PGP SIGNATURE-----
_______________________________________________
tor-relays mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to