-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 How many simultaneous connections are involved in one of these directory fetching attacks? If it's only a few, a simple ratelimit in a firewall might be able to help mitigate it. It's a shame the DirPort and ORPort are combined now or we could apply rate-limiting selectively on DirPort.
Btw, simply restarting the relay seems to interrupt the attack, probably because the attacker doesn't continuously retry the same relay if the connection gets broken. But that probably kicks them to another relay. I'm guessing the attack works by simultaneously fetching directory data over and over to overload the CPU with compression work? Perhaps a long- term mitigation would be for the Tor process to switch to a lower level of compression (e.g. the equivalent of zstd -1) if it detects that the bottleneck is becoming the CPU rather than the network. Regards, forest -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCanE98QAKCRAw+TRLM+X4 xvjEAP96v7/UU+mz/kMdACM31oaVGrIfRpbta0JzAfn7UEgFaAD/YPjrjLiX0syt dh5nIaFQM5/JB9xbBMKikZj2DXhTEwg= =2uOn -----END PGP SIGNATURE----- _______________________________________________ tor-relays mailing list -- [email protected] To unsubscribe send an email to [email protected]
