FINDING · DETECTION

A single malicious Tor middle router advertising 10 MB/s bandwidth discovered 2,369 distinct bridges in 14 days. The catch probability is determined solely by the aggregated bandwidth M = k·b of malicious middle routers regardless of how that bandwidth is distributed across nodes: three routers at 10 MB/s each achieve strictly greater catch probability than 512 nodes at 50 KB/s each. This means a well-resourced single node is equivalent to or surpasses hundreds of low-bandwidth Sybil nodes.

From 2012-ling-extensiveExtensive Analysis and Large-Scale Empirical Evaluation of Tor Bridge Discovery · §IV-B, §V-B, Theorem 3 · 2012 · INFOCOM

Implications

Tags

censors
cngeneric
techniques
ip-blocking
defenses
bridgestor

Extracted by claude-sonnet-4-6 — review before relying.