Attacking and Improving the Tor Directory Protocol
Zhongtang Luo, Adithya Bhat, Kartik Nayak, Aniket Kate
Abstract
The Tor network enhances clients’ privacy by routing traffic through an overlay network of volunteered intermediate relays. Tor employs a distributed protocol among nine hard-coded Directory Authority (DA) servers to securely disseminate information about these relays to produce a new consensus document every hour. With a straightforward voting mechanism to ensure consistency, the protocol is expected to be secure even when a minority of those authorities get compromised. However, the current consensus protocol is flawed: it allows an equivocation attack that enables only a single compromised authority to create a valid consensus document with malicious relays. Importantly the vulnerability is not innocuous: We demonstrate that the compromised authority can effectively trick a targeted client into using the equivocated consensus document in an undetectable manner. Moreover, even if we have archived Tor consensus documents available since its beginning, we cannot be sure that no client was ever tricked.We propose a two-stage solution to deal with this exploit. In the short term, we have developed and deployed TorEq, a monitor to detect such exploits reactively: the Tor clients can refer to the monitor before updating the consensus to ensure no equivocation. To solve the problem proactively, we first define the Tor DA consensus problem as the interactive consistency (IC) problem from the distributed computing literature. We then design DirCast, a novel secure Byzantine Broadcast protocol that requires minimal code change from the current Tor DA code base. Our protocol has near-optimal efficiency that uses optimistically five rounds and at most nine rounds to reach an agreement in the current nine-authority system. Our solutions are practical: our performance analysis shows that our monitor can detect equivocations without changing the authorities’ code in five minutes; the secure IC protocol can generate up to 500 consensus documents per hour in a real-world scenario. We are communicating with the Tor security team to incorporate the solutions into the Tor project.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2a31e02f-8e80-426f-99f8-8ed752e9387eCited by top-tier papers1
Ask how each one uses itBuilds on3
- Sync HotStuff: Simple and Practical Synchronous State Machine ReplicationIttai Abraham, Dahlia Malkhi, Kartik Nayak, Ling Ren et al.S&P 2020 · 240 citations
- Identifying and Characterizing Sybils in the Tor NetworkPhilipp Winter, Roya Ensafi, Karsten Loesing, Nick FeamsterUSENIX Security 2016 · 53 citations
- RandPiper - Reconfiguration-Friendly Random Beacons with Quadratic CommunicationAdithya Bhat, Nibesh Shrestha, Zhongtang Luo, Aniket Kate et al.CCS 2021 · 5 citations
Related papers
- Onions Got Puzzled: On the Challenges of Mitigating Denial-of-Service Problems in Tor Onion ServicesJinseo Lee, Hobin Kim, Min Suk KangUSENIX Security 2025
- Duplicate-Node Attack: Identifying Guards to Degrade and Triangulate Onion ServicesChunmian Wang, Xiaodan Gu, Ming Yang, Qi Chen et al.INFOCOM 2026
- Descriptors of Exposure: Undermining Tor Anonymity Through Exploiting Descriptor FloodChunmian Wang, Junzhou Luo, Zhen Ling, Yue Zhang et al.S&P 2026
- ValidaTor: Domain Validation over TorJens Frieß, Haya Schulmann, Michael WaidnerNSDI 2025
- Large-scale Evaluation of Malicious Tor Hidden Service Directory DiscoveryChunmian Wang, Zhen Ling, Wenjia Wu, Qi Chen et al.INFOCOM 2022 · 10 citations
