[tor-relays] DoSer is back, Tor dev's please consider

starlight.2017q4 at binnacle.cx starlight.2017q4 at binnacle.cx
Fri Mar 23 00:23:26 UTC 2018


Please note:

Here parameter DoSCircuitCreationMinConnections=1 is set (rather than the default value of 3).

Mar 11 17:23:53 Tor[]: DoS mitigation since startup: 0 circuits rejected . . .
. . .
Mar 22 11:23:54 Tor[]: DoS mitigation since startup: 299608 circuits rejected. . .
Mar 22 17:23:54 Tor[]: DoS mitigation since startup: 806025 circuits rejected. . .

I.E. mitigation circuit rejections increased 170% in six hours after moving vaguely for over ten days.

Also:

top - 19:05:53 up 11 days.
  PID USER      PR  NI  VIRT  RES  SHR S %CPU %MEM    TIME+  COMMAND 
 1998 tor       20   0  662m 611m 108m R 47.2 15.4   7901:32 tor
 2000 tor       20   0  662m 611m 108m S 42.2 15.4 343:28.28 tor
 2001 tor       20   0  662m 611m 108m R 56.8 15.4 343:24.46 tor

I.E. crypto workers pegged after barely registering since DoSer shut it down on March 7th.

'iptables' mitigation rule here shows the DoS source-IPs ablaze.

==========

Suggestion:  DoSCircuitCreationMinConnections=1 be established in consensus



More information about the tor-relays mailing list