Andrew Lewman commited on 2005-06-07 04:10:13
Zeige 1 geänderte Dateien mit 26 Einfügungen und 20 Löschungen.
... | ... |
@@ -3,10 +3,10 @@ |
3 | 3 |
|
4 | 4 |
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> |
5 | 5 |
<head> |
6 |
- <title>Legal FAQ for Tor Server Operators</title> |
|
7 |
- <meta name="Author" content="EFF" /> |
|
6 |
+ <title>Abuse FAQ for Tor Server Operators</title> |
|
7 |
+ <meta name="Author" content="Roger Dingledine" /> |
|
8 | 8 |
<meta http-equiv="content-type" content="text/html; charset=ISO-8859-1" /> |
9 |
- <link rel="stylesheet" type="text/css" href="../stylesheet.css" /> |
|
9 |
+ <link rel="stylesheet" type="text/css" href="stylesheet.css" /> |
|
10 | 10 |
<link rel="shortcut icon" type="image/x-icon" href="/favicon.ico" /> |
11 | 11 |
</head> |
12 | 12 |
<body> |
... | ... |
@@ -17,16 +17,16 @@ |
17 | 17 |
<tr> |
18 | 18 |
<td class="banner-left"></td> |
19 | 19 |
<td class="banner-middle"> |
20 |
- <a href="../index.html">Home</a> |
|
21 |
- | <a href="../howitworks.html">How It Works</a> |
|
22 |
- | <a href="../download.html">Download</a> |
|
23 |
- | <a href="../documentation.html">Docs</a> |
|
24 |
- | <a href="../users.html">Users</a> |
|
25 |
- | <a href="../faq.html">FAQs</a> |
|
26 |
- | <a href="../contribute.html">Contribute</a> |
|
27 |
- | <a href="../developers.html">Developers</a> |
|
28 |
- | <a href="../research.html">Research</a> |
|
29 |
- | <a href="../people.html">People</a> |
|
20 |
+ <a href="index.html">Home</a> |
|
21 |
+ | <a href="howitworks.html">How It Works</a> |
|
22 |
+ | <a href="download.html">Download</a> |
|
23 |
+ | <a href="documentation.html">Docs</a> |
|
24 |
+ | <a href="users.html">Users</a> |
|
25 |
+ | <a class="current">FAQs</a> |
|
26 |
+ | <a href="contribute.html">Contribute</a> |
|
27 |
+ | <a href="developers.html">Developers</a> |
|
28 |
+ | <a href="research.html">Research</a> |
|
29 |
+ | <a href="people.html">People</a> |
|
30 | 30 |
</td> |
31 | 31 |
<td class="banner-right"></td> |
32 | 32 |
</tr> |
... | ... |
@@ -63,7 +63,7 @@ |
63 | 63 |
|
64 | 64 |
<p>Distributed denial of service attacks typically rely on having a group of thousands of computers all sending floods of traffic to a victim. Since the goal is to overpower the bandwidth of the victim, they typically send UDP packets since those don't require handshakes or coordination. </p> |
65 | 65 |
<p>But because Tor only transports correctly-formed TCP streams, not all IP packets, you cannot send UDP packets over Tor. (You can't do specialized forms of this attack like SYN flooding either.) So ordinary DDoS attacks are not possible over Tor. Tor also doesn't allow bandwidth amplification attacks against external sites: you need to send in a byte for every byte which the Tor network will send to your destination. So in general, attackers who control enough bandwidth to launch an effective DDoS attack can do it just fine without Tor. </p> |
66 |
-<p>And if this argument doesn't convince you, go try Tor and see how much aggregate throughput you can eke out of it, then come back to us if you're still worried. <img src="/wiki/classic/img/smile.png" width="15" alt=":)" height="15" > </p> |
|
66 |
+<p>And if this argument doesn't convince you, go try Tor and see how much aggregate throughput you can eke out of it, then come back to us if you're still worried. </p> |
|
67 | 67 |
<p> </p> |
68 | 68 |
|
69 | 69 |
<h3>What about spammers?</h3> |
... | ... |
@@ -82,7 +82,7 @@ |
82 | 82 |
<h3>Does Tor get much abuse?</h3> |
83 | 83 |
|
84 | 84 |
<p>Not much, in the grand scheme of things. We've been running the network since October 2003, and it's only generated a handful of complaints. Of course, like all privacy-oriented networks on the net, we attract our share of jerks. Tor's exit policies help separate the role of "willing to donate resources to the network" from the role of "willing to deal with exit abuse complaints", so we hope our network is more sustainable than past attempts at anonymity networks. </p> |
85 |
-<p>Since Tor has <a class="external" href="http://tor.eff.org/cvs/tor/doc/tor-doc.html"><img src="/wiki/classic/img/moin-www.png" width="11" alt="[WWW]" height="11" > many good uses as well</a>, we feel that we're doing pretty well at striking a balance currently. </p> |
|
85 |
+<p>Since Tor has <a href="http://tor.eff.org/cvs/tor/doc/tor-doc.html">many good uses as well</a>, we feel that we're doing pretty well at striking a balance currently. </p> |
|
86 | 86 |
<p> </p> |
87 | 87 |
|
88 | 88 |
<h3>So what should I expect if I run a server?</h3> |
... | ... |
@@ -95,7 +95,7 @@ |
95 | 95 |
</li> |
96 | 96 |
<li class="gap"><p> Somebody connects to an irc network and makes a nuisance of himself. Your ISP gets polite mail about how your computer has been compromised; and/or your computer gets ddosed. [Port 6667] </p> |
97 | 97 |
</li> |
98 |
-<li class="gap"><p> Somebody uses Tor to download a Vin Diesel movie, and your ISP gets a DMCA takedown notice. According to our lawyers (and this convinced the Harvard general counsel), your ISP can totally ignore this notice with no liability problems. See <a class="external" href="http://tor.eff.org/eff/tor-dmca-response.html"><img src="/wiki/classic/img/moin-www.png" width="11" alt="[WWW]" height="11" > http://tor.eff.org/eff/tor-dmca-response.html</a>. [Arbitrary ports] </p> |
|
98 |
+<li class="gap"><p> Somebody uses Tor to download a Vin Diesel movie, and your ISP gets a DMCA takedown notice. According to our lawyers (and this convinced the Harvard general counsel), your ISP can totally ignore this notice with no liability problems. See <a class="external" href="http://tor.eff.org/eff/tor-dmca-response.html">http://tor.eff.org/eff/tor-dmca-response.html</a>. [Arbitrary ports] </p> |
|
99 | 99 |
</li> |
100 | 100 |
</ul> |
101 | 101 |
<p>You might also find that your Tor server's IP is blocked from accessing some Internet sites/services. This might happen regardless of your exit policy, because some groups don't seem to know or care that Tor has exit policies. (If you have a spare IP not used for other activities, you might consider running your Tor server on it.) For example, </p> |
... | ... |
@@ -115,12 +115,14 @@ |
115 | 115 |
<p>But the real answer is to implement application-level auth systems, to let in well-behaving users and keep out badly-behaving users. This needs to be based on some property of the human (such as a password he knows), not some property of the way his packets are transported. </p> |
116 | 116 |
<p>Of course, not all IRC networks are trying to ban Tor nodes. After all, quite a few people use Tor to IRC in privacy in order to carry on legitimate communications without tying them to their real-world identity. Each IRC network needs to decide for itself if blocking a few more of the millions of IPs that bad people can use is worth losing the contributions from the well-behaved Tor users. </p> |
117 | 117 |
<p>If you're being blocked, have a discussion with the network operators and explain the issues to them. They may not be aware of the existence of Tor at all, or they may not be aware that the hostnames they're klining are Tor exit nodes. If you explain the problem, and they conclude that Tor ought to be blocked, you may want to consider moving to a network that is more open to free speech. Maybe inviting them to #tor on irc.oftc.net helps them show that we are not all evil people. </p> |
118 |
-<p>Finally, if you become aware of an IRC network which seems to be blocking Tor, or a single Tor exit node, please put that information on <a href="/noreply/TheOnionRouter/BlockingIrc">../BlockingIrc</a> so that others can share. At least one IRC network consults that page to unblock exit nodes which have been blocked inadvertently. </p> |
|
118 |
+<p>Finally, if you become aware of an IRC network which seems to be |
|
119 |
+blocking Tor, or a single Tor exit node, please put that information on |
|
120 |
+<a href="http://wiki.noreply.org/wiki/TheOnionRouter/BlockingIrc">BlockingIrc</a> so that others can share. At least one IRC network consults that page to unblock exit nodes which have been blocked inadvertently. </p> |
|
119 | 121 |
<p> </p> |
120 | 122 |
|
121 | 123 |
<h3>Your nodes are banned from the mail server I want to use.</h3> |
122 | 124 |
|
123 |
-<p>Even though <a class="external" href="http://wiki.noreply.org/wiki/TheOnionRouter/TorFAQ#WhatAboutSpammers"><img src="/wiki/classic/img/moin-www.png" width="11" alt="[WWW]" height="11" > Tor isn't useful for spamming</a>, some over-zealous blacklisters seem to think that all open networks like Tor should be boycotted. They don't understand how Tor works (e.g. that it has exit policies), and don't seem to care to understand it. If your server administrators decide to make use of these blacklists to refuse incoming mail, you should have a conversation with them and explain how Tor works. </p> |
|
125 |
+<p>Even though <a class="external" href="http://wiki.noreply.org/wiki/TheOnionRouter/TorFAQ#WhatAboutSpammers">Tor isn't useful for spamming</a>, some over-zealous blacklisters seem to think that all open networks like Tor should be boycotted. They don't understand how Tor works (e.g. that it has exit policies), and don't seem to care to understand it. If your server administrators decide to make use of these blacklists to refuse incoming mail, you should have a conversation with them and explain how Tor works. </p> |
|
124 | 126 |
<p> </p> |
125 | 127 |
|
126 | 128 |
<h3>I want to ban the Tor network from my service.</h3> |
... | ... |
@@ -128,16 +130,20 @@ |
128 | 130 |
<p>First, ask yourself if there's a way to do application-level decisions to separate the legitimate users from the jerks. For example, you might have certain areas of the site, or certain privileges like posting, available only to people who are registered. You could set up this distinction only for certain IP addresses such as Tor exit nodes. This way you can have multi-tiered access and not have to ban everything. </p> |
129 | 131 |
<p>Second, consider that thousands of people use Tor every day to protect against data-gathering corporations like Doubleclick while going about their normal activities. Some Tor users may be legitimately connecting to your service right now to carry on normal activities. You need to decide whether banning the Tor network is worth losing the contributions of these users, as well as potential future such users. </p> |
130 | 132 |
<p>Lastly, please remember that Tor servers have individual exit policies. Many Tor servers do not allow exiting connections at all. Many of those that do, probably already disallow connections to your service. When you go about banning nodes, you should parse the exit policies and only block the ones that allow these connections; and you should keep in mind that exit policies can change (as well as the overall list of nodes in the network). </p> |
131 |
-<p>If you really want to do this, there is a python script to parse the Tor directory <a class="external" href="http://tor.eff.org/cvs/tor/contrib/exitlist"><img src="/wiki/classic/img/moin-www.png" width="11" alt="[WWW]" height="11" > here</a>. </p> |
|
133 |
+<p>If you really want to do this, there is a python script to parse the Tor directory <a class="external" href="http://tor.eff.org/cvs/tor/contrib/exitlist">here</a>. </p> |
|
132 | 134 |
<p> </p> |
133 | 135 |
|
134 | 136 |
<h3>I have legal questions about Tor abuse.</h3> |
135 | 137 |
|
136 | 138 |
<p>We're only the developers. We can answer technical questions, but we're not the ones to talk to about legal questions or concerns. </p> |
137 |
-<p>Please take a look at the <a class="external" href="http://tor.eff.org//eff/tor-legal-faq.html"><img src="/wiki/classic/img/moin-www.png" width="11" alt="[WWW]" height="11" > Tor Legal FAQ</a>, and contact EFF directly if you have any further questions. </p> |
|
139 |
+<p>Please take a look at the <a class="external" href="http://tor.eff.org//eff/tor-legal-faq.html">Tor Legal FAQ</a>, and contact EFF directly if you have any further questions. </p> |
|
138 | 140 |
<p> </p> |
139 | 141 |
|
140 | 142 |
</div><!-- #main --> |
141 | 143 |
</div> |
144 |
+ <div class="bottom" id="bottom"> |
|
145 |
+ <i><a href="mailto:tor-webmaster@freehaven.net" class="smalllink">Webmaster</a></i> - |
|
146 |
+ $Id$ |
|
147 |
+ </div> |
|
142 | 148 |
</body> |
143 | 149 |
</html> |
144 | 150 |