Opened 7 years ago

Last modified 17 months ago

#5456

Defend against path bias and tagging attacks

Reported by: mikeperry Owned by:
Priority: High Milestone: Tor: unspecified
Component: Core Tor/Tor Version:
Keywords: SponsorZ-large, needs-proposal, tor-client research-program
Cc: rransom, nickm, arma, mikeperry, isis, saint Actual Points:
Parent ID: Points:
Reviewer: Sponsor:


In, some dude who claims to be a raccoon proved that tagging attacks are an amplification attack that allow an adversary who has c/n of the network bandwidth to compromise of c/n of all circuits through the network.

The tagging attack he describes is actually a subset of path bias attacks we've known about for a long time. Tagging is just a particularly nasty one that also allows for a level of amplification that we previously were not aware of.

This ticket is to serve as the parent ticket for several things we can do to improve the situation and defend against tagging in specific or path bias in general.

Child Tickets

#3890closedtbb-teamApplications should start using optimistic dataApplications/Tor Browser
#5343closedRequire a threshold of exit nodes before believing we can build circuitsCore Tor/Tor
#5457newmikeperryBw auths don't count circuit failures in descriptor modeCore Tor/Torflow
#5458closedmikeperryClients should warn and disable guards responsible for excessive circuit failuresCore Tor/Tor
#5459closedaagbsnExit scanner should scan for Guard <-> Exit reachabilityCore Tor/Torflow
#5460closednickmWrite proposal(s) to implement improved relay/circuit crypto authenticationCore Tor/Tor
#5563closedBetter support for ephemeral relay identity keysCore Tor/Tor
#5956closedmikeperryThresholds of nodes to build circuits should be tunable and maybe consider weights tooCore Tor/Tor
#5968newImprove onion key and TLS managementCore Tor/Tor
#6135closedTune + tighten path bias parametersCore Tor/Tor
#7003newWipe relay key material from memory on common crash conditionsCore Tor/Tor
#7157closed"Low circuit success rate %u/%u for guard %s=%s."Core Tor/Tor
#7509newPublish and use circuit success rates in extrainfo descriptorsCore Tor/Tor
#7582closedDon't disable exits so harshly for unexpected END_REASON_EXITPOLICYCore Tor/Tor
#9001newSlow Guard Discovery of Hidden Services and ClientsCore Tor/Tor

