[tor-relays] max TCP interruption before Tor circuit teardown?

Dan Staples danstaples at disman.tl
Sun Oct 20 17:32:34 UTC 2013


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256



On 10/20/2013 12:42 PM, Gordon Morehouse wrote:
> If a tor relay has a circuit built through a peer, and the peer
> starts dropping 100% of packets, how long will it take before the
> relay with the circuit "gives up" on the circuit and tears it down?
> I want to set my temp ban time *below* this timeout.  Thus, unlucky
> peers that were caught in the filter and have circuits already
> built through the relay they will experience a brief performance
> degradation, but they won't lose their active circuits through the
> overloaded relay, and in the meantime hopefully the overload
> condition is becoming resolved.

Might it be better to actually cause the connecting client to tear
down the circuit instead of degrading performance? If your relay is
already being swamped by circuit-creation requests, it might be better
to cause clients to build new circuits, hopefully not using your
relay, no?

Dan

- -- 
http://disman.tl
OpenPGP key: http://disman.tl/pgp.asc
Fingerprint: 2480 095D 4B16 436F 35AB 7305 F670 74ED BD86 43A9
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCAAGBQJSZBOyAAoJEPZwdO29hkOpNgoP/1z4V+bShe1Sin1asAp+bfJP
kZM3IHkvqkMk4peUxk2SpSKzREx8OfeJFqE1uplPQtMUK4Rbi5wPpqI6nBaMw3sw
qSeq5fjZm1VHLFFyoeKMUgBZMVjD5ctkz6QBMbofSSA40xqEe3pQhH84HD0oVsWj
K6yZcnhvI05L0bKCB0qQJe/8Ig+pE0LGIJwADEI6/4ChBqdzlf0zlKPZEPeXNvbF
t6N6k6lcqAXaJsJMH6THCgfib+MfVrpAGnmihYMjUnzRinf+tXQlskDREgnTYISK
/lVyS1tkYJGkvEH78XB5y8ofeIjJNX2SULVk13WPWykaj1T2l/Icvw0we02WovEv
+ydlt2yqTL/AgCoB0UEtmNETpAHCkegIvXiYv+djq60us+/aWy4zhLfg4Y0WIA5i
ZDWm0zTvst5H5QWDYB2pz9g7jrGK42w2eG/LAyOsF7NyiU7XTPj8C8IZ7YvFQ/+H
yEtqXIhfLkAlyCGFma8eTG9hA2zRJxhNY45taFp2/0XTaWgvpGgDbeDl/j4gxjVD
X7Ni/5VvTX6zRpc/A+PcwxCIpddbjc0KakAyoPrqwUC6tyoV1K/+cRXJMA9D+VkH
7NPlwor9pFMsz5bsRdO1hc3RP3CtOH2tXn+lp3ecXvfMA+uy1HeDprHz2SmPpBWP
DP9kcmbYOePE5ZSIObrI
=CbnN
-----END PGP SIGNATURE-----


More information about the tor-relays mailing list