How to handle millions of new Tor clients
blog.torproject.org
blog.torproject.org
If I were looking at things, I'd backtrace from sites of interest. If your computer connected to a broad number of websites, and sufficient numbers of fishy websites - and other computers did likewise - then yeah, the false positives would be too great. But just increasing traffic through the network doesn't necessarily do that, at least as far as I understand it.
Yep. That's one way to attack the network.
Note that the handshake is the CPU-limited part, so a CPU-limited node benefits (in terms of MB/s) from having few clients which use high bandwidth, the opposite of these bots.
Then the portion of the blog post (at the very end) you are responding to:
>
> I still maintain that if you have a multi-million node botnet, it's silly to try
> to hide it behind the 4000-relay Tor network. These people should be using their
> botnet as a peer-to-peer anonymity system for itself. So I interpret this
> incident as continued exploration by botnet developers to try to figure out what
> resources, services, and topologies integrate well for protecting botnet
> communications. Another facet of solving this problem long-term is helping them
> to understand that Tor isn't a great answer for their problem.
>
> [- Roger]
>
where you believe the blog is mistaken on the botnet's use of Tor. You point out the intention of hiding the owner's control of the botnet vs. your interpretation of the blog post as claiming the botnet is trying to hide entirely behind Tor.My interpretation of the blog post excerpt is that the botnet offers its creator a chance to run a better Tor than Tor itself... with more nodes and the option of configuring whatever percentage as entry / relay / exit nodes.
If I own every relay on your circuit, I can monitor your traffic; if I own three million relays, it's almost certain that a significant portion of the traffic will be running through circuits composed of relays I own.
Instead of hacking relays to prioritize one botnet version over another, they should properly implement rate-limiting algorithms like exponential backoff in case of failure.
This would also allow for plausible deniability. If the Tor network was compromised and half the nodes were owned by the feds or a botnet or something like that, it would still be impossible to tell if the traffic coming from your ip was from you or someone else.