[tor-bugs] #29607 [Core Tor/Tor]: 2019 Q1: Denial of service on v2 and v3 onion service

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed May 29 12:54:11 UTC 2019


#29607: 2019 Q1: Denial of service on v2 and v3 onion service
-------------------------------------------------+-------------------------
 Reporter:  pidgin                               |          Owner:  pidgin
     Type:  defect                               |         Status:
                                                 |  needs_information
 Priority:  Immediate                            |      Milestone:  Tor:
                                                 |  0.4.1.x-final
Component:  Core Tor/Tor                         |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  tor-hs, tor-dos, network-team-       |  Actual Points:
  roadmap-2019-Q1Q2, security, 041-longterm      |
Parent ID:  #29999                               |         Points:  10
 Reviewer:                                       |        Sponsor:
                                                 |  Sponsor27-must
-------------------------------------------------+-------------------------

Comment (by dgoulet):

 Replying to [comment:58 pidgin]:
 > Any updates on this problem ??

 Unfortunately not that much that could help stop this problem at once. To
 summarize:

 1. We've identified the cause of the DoS and defense vectors.
 2. Out of this investigation, a series of bugs were also found including
 reducing CPU load on path selection (#30291).
 3. We decided to focus on one important defense which will be done through
 #15516. It primarily focus on defending the network by soaking huge amount
 of introduction at the intro point so the service doesn't get bombarded.
 Should help with availability (service will not be overloaded) but not
 reachability (intro point could drop legit requests).

 Our primary goal for now is to protect the network and try as much as
 possible to avoid too much pressure on it like the last massive HS DoS
 back in the early months of 2018.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/29607#comment:59>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list