this post was submitted on 27 Sep 2024
121 points (99.2% liked)

Privacy

42924 readers
923 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
all 23 comments
sorted by: hot top controversial new old
[–] shortwavesurfer@lemmy.zip 13 points 1 year ago (1 children)

Having the proof of work defense has been a game changer for the network. I've noticed a hell of a lot less unresponsive onion services. However, this is old news as it was released last August. Most everybody should have a version capable of doing the proof of work by now.

[–] possiblylinux127@lemmy.zip 4 points 1 year ago

That's why I posted it. It has been rolled

[–] delirious_owl@discuss.online 12 points 1 year ago* (last edited 1 year ago) (1 children)

I wish more companies understood that Onion Services have excellent protection from DoS attacks.

You don't even have to give away your keys to CloudFlare. Just get trigger happy with IP blocking and tell users to use the Onion address to bypass any blocks.

[–] possiblylinux127@lemmy.zip 0 points 1 year ago (1 children)

Honestly that's not a terrible idea (assuming the target audience knows about Tor)

[–] delirious_owl@discuss.online 1 points 1 year ago

Most of the people who get blocked are going to be tech savvy. Except maybe someone computer illiterate at a Uni

[–] admin@lemmy.nowhere.moe 12 points 1 year ago* (last edited 1 year ago)

no offense, but that's old news as of august of last year. But yea this has been a big game changer for hidden services that were under constant DDoS, such as the Dread forum.

[–] delirious_owl@discuss.online 4 points 1 year ago

This is a year old. But please do notify me when its available in the default Debian repos.

[–] foremanguy92_@lemmy.ml 3 points 1 year ago

Could be good, but be aware that it doesn't bother the real users. Continue working! 😃

[–] delirious_owl@discuss.online 3 points 1 year ago

RIP EndGame

[–] PropaGandalf@lemmy.world -3 points 1 year ago (5 children)
[–] magic_lobster_party@fedia.io 18 points 1 year ago (1 children)

It’s not like it’s going to consume electricity like Bitcoin.

PoW was first conceptualized as an anti spam method. It’s just a little overhead to make it expensive to make DOS attacks. This makes perfect sense.

[–] Mubelotix@jlai.lu 1 points 1 year ago

It will, but that's the point. Costing money

[–] delirious_owl@discuss.online 17 points 1 year ago (1 children)

What do you think PoW was created for. This is exactly the use case of PoW -- to reduce malicious traffic. It works great!

[–] Mubelotix@jlai.lu 1 points 1 year ago* (last edited 1 year ago) (1 children)

Though if an attacker has an ASIC he can single-handedly dominate the whole pool of other users as ASICs are tremendously more efficient than CPUs

[–] delirious_owl@discuss.online 5 points 1 year ago (1 children)

Depends on the hashing algorithm. Tor implements two, and neither are vulnerable to custom architectures like ASICs

[–] Mubelotix@jlai.lu 1 points 1 year ago
[–] BroBot9000@lemmy.world 9 points 1 year ago

Still a better use of the electricity than Ai.

[–] ziviz@lemmy.sdf.org 8 points 1 year ago* (last edited 1 year ago) (1 children)

At least it appears to be something that gets triggered. In theory, if a node is not under attack or heavy usage, this isn't a consideration. Doesn't seem to be a perfect solution as it still slows the traffic of legitimate users in the event of an attack. I don't know the full details, but in the worse case it makes it easier to semi-DoS, maybe not by fully making a node unresponsive, but by making the service so painfully slow that users may give up on it.

[–] shortwavesurfer@lemmy.zip 2 points 1 year ago

Only for those users who do not have proof of work capability, they get put at the back of the line, but anybody with proof of work capability, which was released last August, will do the work and be put higher priority. I know some people who run seed nodes for Haveno-reto and they had major DDOS issues until they got PoW enabled. It was taking like 5 or 10 minutes to get connected to the network. And now it takes about 30 seconds.

[–] possiblylinux127@lemmy.zip 4 points 1 year ago (1 children)