Watch and judge by yourself and discuss below if you feel like.
TL;DW
This video explains a major vulnerability in the Tor networkās directory protocol, based on Purdue University research published in 2024, revealing that the entire Tor network can be disabled for only $53 using a targeted, low-cost DDoS attack. The attack exploits a design flaw in how Torās nine directory authorities synchronize and agree on network relays. If attackers use commercial DDoS services to target just five of these authorities, Torās safeguards break down and the entire network becomes unusable for millions of users.
Thatās a hell of refutation of everything else he said in that video. Congrats!
PS.
FYI, the advertised salary for the post of Director of Engineering at TOR project was 150.000$ (negotiable with opt-in salary transparency) already in 2022. And for the software developer for the anti censorship team, 100.000$ (2021).
So, let me count, 1,2ā¦5,6⦠Oh! That makes a six figure salary!
Thatās your interpretation. Iām not saying that his points & arguments arenāt true. But Iām doubtful that the conclusions he his presenting (e.g. they refuse to fix the issue, theyāre lazy asses with a big paycheck that work from home all the time ⦠) is painting the full picture. Sure, itās poorly communicated from the TOR team as there has been no public statements in response to the discovery of the vulnerabilities.
The Director of Engineering & a single Software Developer is simply not representative for the whole team. That is an oversimplification. Sure, theyāve got their staff and yes, they employ software developers. But there are still those contributors who work on the project on voluntary terms or those who are hired & employed by one of their sponsors.
From my perspective - his critique on the TOR project and their developers doesnāt fully reflect the nature of the Tor Project as an NGO that only is able to employ some core developers and builds upon 3rd party sponsorships as well as voluntary work contributions. Thatās it.
Personally, Iām not involved and I donāt use Tor at all. All Iām saying is more or less: If I would be an volunteer who is donating either directly in terms of code contributions or indirectly in hosting infrastructure nodes, this kind of narrative would be discouraging.
The vulnerability has been demonstrated by the researchers from Purdue University already in 2024.
It can be exploited with only five minutes of DDoS traffic to five directory authorities, overwhelming their bandwidth and stopping the consensus protocol that Tor relies on for relay information.ā
Researchers from Purdue proposed a protocol change based on āpartial synchrony,ā allowing the network to recover and function even if several authorities are offline or delayed. They provided a working Rust implementation that mitigates the described attacks.
Despite knowing about the vulnerability, the Tor Projectās main codebase (written in C) is still running the old, vulnerable protocol without meaningful fixes, and their new Rust implementation (āArtiā) does not yet include directory authority functions or a public timeline for improvements.
So, the networkās security currently depends on hoping no one bothers to exploit this cheap and devastating attack, leaving users and activists relying on infrastructure described as āheld together by hope.ā
The question of who gets paid or not and how much and whatnot is not the point of this video. It is irrelevant.
What is relevant here is the fact that TOR project has been informed about this vulnerability for over one year and also has been presented with a working solution but so far has not chosen to implement it.
What in hell why?
How would you feel about a similar situation but regarding a critical vulnerability in the Linux kernel or some essential package in the Arch Linux putting the safety and security of your system in danger?
Would you still feel āpityā over all the non-paid code contributors to the Linux kernel and/or Arch Linux if someone leverage a critique about the situation specially when someone else has done the job and presented the solution?
Nevertheless, he choose that wording and framed them that way. That being said, Iām mostly criticizing the messenger, not the message itself.
I canāt tell why the TOR Project hasnāt responded to those vulnerabilities and in which way they intend to address this. But I doubt that they are simply ignoring it, or, as he frames it in the video : That they refuse to implement the mitigation.
Why theyāre not obfuscating the IPs of the directory authority nodes as well as their fallbacks is definitely something they also could address as well, on top of the proposed direct threat mitigations.