<oembed><type>rich</type><version>1.0</version><author_name>npub1wz2sm8h4ylh9dn28688vjzwrmhaxnh3jl04p8jk3qeq7umwf8cus72jvxz</author_name><author_url>https://nostr.ae/npub1wz2sm8h4ylh9dn28688vjzwrmhaxnh3jl04p8jk3qeq7umwf8cus72jvxz</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-11-27&#xA;📝 Original message:Hello there,&#xA;&#xA;quote:&#xA;&gt; Please see also the following:&#xA;&gt;&#xA;&gt; https://cpunks.org//pipermail/cypherpunks/2014-November/005971.html&#xA;&gt;&#xA;&#xA;I agree about the severity of the Tor/Bitcoin issue, but I see no&#xA;point in bashing Bitcoin&#39;s financial privacy characteristics as&#xA;the linked pages seem to do.&#xA;&#xA;Bitcoin can be useful as a part of a strategy to improve on privacy,&#xA;but it does not intend to be a run-and-forget solution for doing so.&#xA;&#xA;A lot of issues found in this context can actually be traced back to&#xA;Tor&#39;s characteristics already known before. It&#39;s just that&#xA;Bitcoin makes Tor&#39;s deficiencies more measurable - before Bitcoin,&#xA;those interested in researching how Tor performs in an automated&#xA;context where a much smaller community. In the end, I guess both&#xA;projects can benefit from the research we can do now.&#xA;&#xA;&gt; Respect,&#xA;&gt;&#xA;&gt; - -Odinn&#xA;&gt;&#xA;&gt; Jeff Garzik:&#xA;&gt; &gt; I don&#39;t recall being contacted directly, but the attack has been&#xA;&gt; &gt; discussed.  It relies on a number of conditions.  For example, if&#xA;&gt; &gt; you are over Tor, they try to kick the machine off Tor, _assuming_&#xA;&gt; &gt; that it will fall back to non-Tor.  That&#39;s only true for dual stack&#xA;&gt; &gt; nodes, which are not really 100% anonymous anyway -- you&#39;re&#xA;&gt; &gt; operating from your public IP anyway.&#xA;&gt; &gt;&#xA;&#xA;Generally, it cannot be said that the attack vector described here is&#xA;irrelevant for non-dual-stack nodes. An attacker might not be able to&#xA;collect IP addresses of Tor-only nodes, but he can try to kick the&#xA;users from all Tor exit nodes he does not control, and proceed with&#xA;other attacks when a large number of Tor-only users connect through&#xA;his Tor exit node(s).&#xA;&#xA;Since this attack vector has been discussed, I started making some&#xA;measurements on how effective it is to connect to Bitcoin using Tor,&#xA;and I found that the number of connections dropping to near-zero is&#xA;a situation which occurs rather frequently, which suggests that there&#xA;is still room to improve on the DoS handling.&#xA;&#xA;Best regards,&#xA;&#xA;Isidor</html></oembed>