[tor-talk] Privacy Pass from Cloudflare, and the CAPTCHA problem

2017-11-20 Thread bob1983
Cloudflare just announced its support of Privacy Pass, a challenge-response protocol designed to avoid repetitive CAPTCHAs-solving for anonymous users, while using Zero-Knowledge Proof to prevent the possibility of distinguishing each user, to acquire both convenience and anonymity. It is develope

Re: [tor-talk] Layer-7 DoS Attack Against WWW Tor Hidden Service

2017-11-14 Thread bob1983
>> Is there a way to limit resource usage originated from a single Tor circuit? > There is no such functionality right now I'm afraid. People have been > wanting some sort of functionality like that for a while: > https://www.hackerfactor.com/blog/index.php?/archives/777-Stopping-Tor-Attacks.html

[tor-talk] Layer-7 DoS Attack Against WWW Tor Hidden Service

2017-11-14 Thread bob1983
Hi. I'm the sysadmin of an unnamed computer club, we support online security and privacy, so our website is available via a Tor hidden service. Recently, we found a surge of CPU and RAM usage as soon as Tor has been started. A closer look showed it was the result of a DoS script, likely a broken