FINDING · EVALUATION

The Tor client puzzle mechanism contains a fundamental architectural trade-off: the system is forced to choose between inflation resistance (preventing attackers from artificially raising puzzle difficulty) and congestion resistance (preventing the service from being overwhelmed), but cannot achieve both simultaneously — a root-cause vulnerability acknowledged by the Tor Project.

From 2025-lee-onions-got-puzzledOnions Got Puzzled: On the Challenges of Mitigating Denial-of-Service Problems in Tor Onion Services · Abstract · 2025 · USENIX Security 2025

Implications

Tags

defenses
tor

Extracted by claude-sonnet-4-6 — review before relying.