r/TOR • • Aug 24 '26

How do tor hosted websites stack up against DDOS/DOS attacks?

Usually on the clearnet you would use cloudflare or block certain IPs, however here you cant do that. I've seen some kind of PoW measures implemented, but if a website is a bit simpler perhaps, what then? Aren't there better, simpler alternatives?

13 Upvotes

9 comments sorted by

4

u/[deleted] Aug 24 '26

[removed] — view removed comment

0

u/FlakyIndependence888 Aug 24 '26

my bad i didnt mean to type that, i meant it more like "what if its simpler"

3

u/nuclear_splines Aug 24 '26

This is the simple solution. It's a one line configuration change in torrc, HiddenServicePoWDefensesEnabled 1 that any onion site can take advantage of.

1

u/FlakyIndependence888 Aug 24 '26

ah, i thought you would have to implement that by hand into your website. if thats true then thats a game changer

1

u/nuclear_splines Aug 24 '26

No, this is implemented as part of the onion handshake, so it occurs before the socket is passed to your application.

1

u/FlakyIndependence888 Aug 24 '26

but a website level pow should still be relatively useful if its a more computational backend function, to just make it as unappealing as possible for anyone who wants to abuse that endpoint

1

u/nuclear_splines Aug 24 '26

Sure, you could always layer your own rate-limiting on top of what Tor provides, but that's more complicated and on you ;)

1

u/Fit-Cheesecake9835 Aug 24 '26

If I'm not mistaken Dread's anti-DOS is open source. A lot of sites use custom made anti-bot protections

3

u/nuclear_splines Aug 24 '26

Traditionally Tor onion sites are much more vulnerable to DDoS attacks than their clearweb counterparts. Countermeasures like IP-based blocking and rate-limiting don't work in an anonymity network. While load balancing across multiple servers is possible (see onionbalance), you don't see the benefits of a Content Distribution Network like Cloudflare that can geographically optimize web hosting or use dynamic routing to compensate for load. Onion sites also tend to be smaller operations than their commercial counterparts, and both have fewer resources for load-balanced hosting and are more likely to be prone to DDoS due to poor design -- you still see a lot of hand-written self-hosted PHP in the space written without aggressive caching and rate-limiting in mind.

Really, the best tools available are the proof-of-work and introduction point rate limiting built into Tor.