Just 53$ can afford you to bring the whole TOR down 😱

Watch and judge by yourself and discuss below if you feel like.

TL;DW

This video explains a major vulnerability in the Tor network’s directory protocol, based on Purdue University research published in 2024, revealing that the entire Tor network can be disabled for only $53 using a targeted, low-cost DDoS attack. The attack exploits a design flaw in how Tor’s nine directory authorities synchronize and agree on network relays. If attackers use commercial DDoS services to target just five of these authorities, Tor’s safeguards break down and the entire network becomes unusable for millions of users.

:kitchen_knife: :onion:

Now I know what Santa’s job is when it’s off-season. :santa_claus:

If that’s Santa I’m afraid he would be shot this year for being too STUPID. Sorry, not sorry Boyz & Girlz. Ho Ho Ho HaHaHa

I don’t know who this guy is that made the video, but his statement

their devs make six figures

simply made me to not take him that seriously.

That’s a hell of refutation of everything else he said in that video. Congrats! :sweat_smile:

PS.

FYI, the advertised salary for the post of Director of Engineering at TOR project was 150.000$ (negotiable with opt-in salary transparency) already in 2022. And for the software developer for the anti censorship team, 100.000$ (2021).

So, let me count, 1,2…5,6… Oh! That makes a six figure salary! :rofl:

That’s your interpretation. I’m not saying that his points & arguments aren’t true. But I’m doubtful that the conclusions he his presenting (e.g. they refuse to fix the issue, they’re lazy asses with a big paycheck that work from home all the time … ) is painting the full picture. Sure, it’s poorly communicated from the TOR team as there has been no public statements in response to the discovery of the vulnerabilities.

The Director of Engineering & a single Software Developer is simply not representative for the whole team. That is an oversimplification. Sure, they’ve got their staff and yes, they employ software developers. But there are still those contributors who work on the project on voluntary terms or those who are hired & employed by one of their sponsors.

From my perspective - his critique on the TOR project and their developers doesn’t fully reflect the nature of the Tor Project as an NGO that only is able to employ some core developers and builds upon 3rd party sponsorships as well as voluntary work contributions. That’s it.

Personally, I’m not involved and I don’t use Tor at all. All I’m saying is more or less: If I would be an volunteer who is donating either directly in terms of code contributions or indirectly in hosting infrastructure nodes, this kind of narrative would be discouraging.

That’s your interpretation.

My take from the video:

  • The vulnerability has been demonstrated by the researchers from Purdue University already in 2024.

  • It can be exploited with only five minutes of DDoS traffic to five directory authorities, overwhelming their bandwidth and stopping the consensus protocol that Tor relies on for relay information.​

  • Researchers from Purdue proposed a protocol change based on ā€œpartial synchrony,ā€ allowing the network to recover and function even if several authorities are offline or delayed. They provided a working Rust implementation that mitigates the described attacks.

  • Despite knowing about the vulnerability, the Tor Project’s main codebase (written in C) is still running the old, vulnerable protocol without meaningful fixes, and their new Rust implementation (ā€œArtiā€) does not yet include directory authority functions or a public timeline for improvements.

  • So, the network’s security currently depends on hoping no one bothers to exploit this cheap and devastating attack, leaving users and activists relying on infrastructure described as ā€œheld together by hope.ā€

The question of who gets paid or not and how much and whatnot is not the point of this video. It is irrelevant.

What is relevant here is the fact that TOR project has been informed about this vulnerability for over one year and also has been presented with a working solution but so far has not chosen to implement it.

What in hell why?

How would you feel about a similar situation but regarding a critical vulnerability in the Linux kernel or some essential package in the Arch Linux putting the safety and security of your system in danger?

Would you still feel ā€œpityā€ over all the non-paid code contributors to the Linux kernel and/or Arch Linux if someone leverage a critique about the situation specially when someone else has done the job and presented the solution?

I would wonder what in hell are they waiting for.

Nevertheless, he choose that wording and framed them that way. That being said, I’m mostly criticizing the messenger, not the message itself.

I can’t tell why the TOR Project hasn’t responded to those vulnerabilities and in which way they intend to address this. But I doubt that they are simply ignoring it, or, as he frames it in the video : That they refuse to implement the mitigation.

Anyway, besides the known directory authorities there is at least of set of mirrors / fallbacks in place.

Why they’re not obfuscating the IPs of the directory authority nodes as well as their fallbacks is definitely something they also could address as well, on top of the proposed direct threat mitigations.