-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Several minutes ago, another two of my servers were attacked. I need to know what I should be doing. I only have a few ideas now: 1. No action. Keep my nodes up, at the risk of losing some of them due to provider suspensions for extreme network and CPU overuse. 2. Temporarily set DirCache 0 when an attack is detected. This reduces the negative effects on relaying, but network use remains very high. 3. Permanently set DirCache 0. This might cause the attacker to skip my relays, but that also means I won't be providing any guards. 4. Shut down the relay for a few hours as soon as an attack starts. This eliminates bandwidth but also means the attacker controls my uptime. Until discussion begins for implementing a BEGIN_DIR rate-limiter and a mitigation rolled out, the attacker will continue completely unimpeded and users will likely be deanonymized, assuming that is their intent. In the meantime, I have temporarily shut down those relays. Regards, forest -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCarnJrgAKCRAw+TRLM+X4 xjGVAP9GTmust6eS0wf8ZR8RIV02198zRC8aE7jRxx/bikxtIAEAkCamVOmt31cK jR4rsrxIk70pFzzgC8HDvVeiQDlWCAY= =3zSF -----END PGP SIGNATURE-----