ZeroHour
arXiv cs.CRpublished ()ingested Jules Dejaeghere

Sociotechnical Aspects of Tor Relay Rejection

infoResearchimportance 25
AI summary · glm-5.3

User study and simulations of Tor's relay end-of-life rejection policy find operators favor it; network churn affects anonymity more than EoL exclusions.

The study examines the Tor Project's 2019 end-of-life policy that rejects outdated relays, which constitute a notable fraction of consensus weight. A user study of 26 relay operators found they generally view the policy favorably despite limited awareness, though operational practices occasionally exclude newly installed relays. Historical-data-driven simulations show the policy gives adversaries only marginal advantage, with network churn exerting a more pronounced effect on user anonymity. Analysis of four exclusion rounds shows a minority of rejected relays typically account for over 50% of the security provided by all excluded relays, informing EoL policy recommendations.

  • Tor's 2019 EoL policy rejects outdated relay versions from consensus
  • 26-operator study shows generally favorable but unevenly known policy
  • Simulations show marginal adversarial advantage; churn matters more
  • Minority of rejected relays provides over 50% of excluded-relay security
Full article171 words · extracted from arxiv.org · click to collapse

In 2019, the Tor Project enforced an end-of-life (EoL) policy for Tor versions, leading to the rejection of outdated relays, amounting to a notable fraction of consensus weight. While this policy aids network maintenance, reduces backporting efforts, and shortens vulnerability exposure, its sociotechnical implications remain unstudied. A user study ($N=26$) reveals that relay operators, though not universally aware of the EoL policy, generally view it favorably. Operational practices vary, occasionally excluding newly installed relays from the network. Network simulations, grounded in historical data, assess the policy's immediate impact on Tor clients against common adversaries. Results indicate a marginal adversarial advantage, with network churn (i.e., relays entering and exiting) exerting a more pronounced effect on user anonymity. Security metrics are introduced to evaluate relay contributions against two adversary models, enabling ranking by individual utility and security. Analysis of four exclusion rounds shows that a minority of rejected relays typically account for over 50% of the security provided by all excluded relays. Recommendations for EoL policy implementation are proposed to mitigate potential drawbacks.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.15192