Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is there actually anything you can do to prevent this kind of attack?

I'm assuming once your network is compromised to such an extent there is not much you can do.



One (rather wasteful) workaround to delay the discovery a little bit is to have each node generate an equivalent amount of traffic going somewhere else.

The concept of a hidden service is itself interesting since it must still be "visible" to some extent, or else nothing could communicate with it; but at the same time, it's attempting to hide any indications of its presence. Attacks based on a large volume of traffic will always work if the service is centralised, since that's where all the traffic will (eventually) go. The only real solution I see is to make hidden services highly distributed so that the load is spread out and largely masked by other traffic.

Somewhat related: http://en.wikipedia.org/wiki/Fast_flux


Cut the hardline. Well, but seriously, shut down the network temporarily.


Wouldn't that only make it easier to confirm that this network/ip is associated with given hidden service?

This made me thinking btw about the latest hetzner hiccups which never happened before.


Yeah, assuming a global adversary, you'd just watch which servers went dark and the investigate them. We really need a "defensive mode" for TOR.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: