On Tue, Aug 20, 2019 at 04:05:36PM +1000, teor wrote:
On 20 Aug 2019, at 14:35, Larry Brandt lbrandt@cni.net wrote:
This may be similar to my situation with my Finland exit relay [1]. I was finally forced to deal with kern overload that shut my cpu down. I had several thousand IP's without hashed fingerprints opting to get into Tor. A combination of hardening, banning and increasing kern processing to 100,000 helped. Since then I have a Consensus Weight of 600 rather than the 8000 before the intrusion. Strange thing: ufw banning and reboot does not seem to stop a few of the Iranian IP addresses--they're still there.
We think this is a result of Iranian censorship, I think the anti-censorship team are working on the issue. I've cc'd Philipp for more info.
This is the first time I heard about this issue. I'll bring this up during Thursday's anti-censorship meeting.
Cheers, Philipp