[tor-dev] Tor Proposal 295

2020-01-13 Thread Tomer Ashur
Dear all, Please find attached out final version for Proposal 295. This version has two changes compared to the previous one: 1. It fixes a vulnerability introduced in the previous iteration which was the result of making the authentication layer stateless. Since there is no freshness enterin

Re: [tor-dev] Changes to accessing and using MaxMind's databases

2020-01-13 Thread Nick Mathewson
On Thu, Jan 9, 2020 at 8:25 AM Karsten Loesing wrote: > > Hi! > > When trying to update tor's geoip databases the other day I found that > MaxMind's GeoLite2 database is not available for download anymore. The > reason is: > > https://blog.maxmind.com/2019/12/18/significant-changes-to-accessing-an

[tor-dev] Evaluating rendezvous circuit build up CPU usage

2020-01-13 Thread Valentin Franck
Hello tor-devs, I am currently working on a DoS mitigation system aiming to protect the availability of onion services flooded with INTRO2 cells. My idea is using a (Privacy Pass like) token based approach as suggested in https://trac.torproject.org/projects/tor/ticket/31223#comment:6 For the eva