Commit c50cf094 authored by Nick Mathewson's avatar Nick Mathewson 🎨
r12212@catbus: nickm | 2007-03-17 17:05:54 -0400

 Merge or-dev discussion into 109; mark 109 accepted.

parent 5679edfd
......@@ -27,6 +27,6 @@ Proposals by number:
106 Checking fewer things during TLS handshakes [CLOSED]
107 Uptime Sanity Checking [CLOSED]
108 Base "Stable" Flag on Mean Time Between Failures [OPEN]
109 No more than one server per IP address [ACCEPTED]
110 Avoiding infinite length circuits [OPEN]
111 Prioritizing local traffic over relayed traffic [OPEN]
......@@ -4,7 +4,7 @@ Version:
Author: Kevin Bauer & Damon McCoy
Created: 9-March-2007
Status: Accepted
This document describes a solution to a Sybil attack vulnerability in the
......@@ -30,9 +30,24 @@ Security implications:
attacker must control in order to carry out traffic analysis.
We propose that the directory servers check if an incoming Tor router IP
address is already registered under another router. If this is the case,
then prevent the new router from joining the network.
For each IP address, each directory authority tracks the number of routers
using that IP address, along with their total observed bandwidth. If there
are more than MAX_SERVERS_PER_IP servers at some IP, the authority should
"disable" all but MAX_SERVERS_PER_IP servers. If the total observed
bandwidth of the remaining non-"disabled" servers exceeds MAX_BW_PER_IP,
the authority should "disable" some of the remaining servers until only one
server remains, or until the remaining observed bandwidth of non-"disabled"
servers is under MAX_BW_PER_IP. When choosing which servers to disable,
the authority should first disable non-Running servers in increasing order
of observed bandwidth, and then should disable Running servers in
increasing order of bandwidth.
Servers that are "disabled" MUST be marked as non-Valid and non-Running.
MAX_BW_PER_IP is 8 MB per s.
......@@ -66,17 +81,3 @@ Compatibility:
would only make use of a bit of it. So Roger suggested that he run
two Tor servers, to use more.
