Hi everybody* if all 65535 connections on an IP were open to the Tor network, and
* the biggest Tor Guard has 0.91% Guard probability[0], then
* it would expect to see 597 connections.
Sorry if this is a silly question, but do we know if these are Torclients connecting our guards? We see many connects but not much circuits.
Some of us have analysed the details of this attack on our relays.
The clients perform SSL, the Tor link protocol, and parts of the circuit protocol.
Are they real Tor clients? Possibly not.
We're working on a fix, please see this email for details:
T