Tor Project boosts Onion sites' defense against DoS attacks

Illustration of the "dark web", logo of the Tor Browser, which provides access to the Darknet. Binary codes are shown in the background
(Image credit: Photo by Florian Gaertner/Photothek via Getty Images)

The developers behind one of the most secure browsers around, the Tor Project, have just increased the security of its onion sites against cyberattacks.

Onion services are sites that can be accessed only by using the Tor browser. However, while seeking to maximize users' privacy online, their technical design has also made these more vulnerable to DoS (denial-of-service) attacks.

That's why the team added its latest version a new proof-of-work (PoW) defense to prioritize verified network traffic and deter attackers. Let's see how this works in practice.

Proof-of-Work defense for onion services

As the provider explains in a blog post, "Tor's PoW defense is a dynamic and reactive mechanism, remaining dormant under normal use conditions to ensure a seamless user experience, but when an onion service is under stress, the mechanism will prompt incoming client connections to perform a number of successively more complex operations. The onion service will then prioritize these connections based on the effort level demonstrated by the client."

The need for such an additional tool comes from the fact that when an IP address gets obfuscated, connections are more likely to be seen as illegitimate. This makes DoS attackers' duties, whose aim is making a machine or network inaccessible, even easier to accomplish.

This is why the Tor Project team devised a PoW mechanism involving a client puzzle to prevent DoS attacks from happening, without affecting user privacy. Simply put, it "blocks attackers while giving real users a chance to reach their destination."

This process acts as a ticket system which is turned off by default and gets triggered when it reveals some stress on the network. For attackers, who make a huge number of connection attempts to an onion service, this means a way greater computational effort. While users will barely notice such a process most of the time.

"PoW for onion services is invisible to the user and quite user-friendly due to its dynamic and reactive properties," Pavel Zoneff from the Tor Project explained to TechRadar. "This is why we would argue that Tor’s PoW defense is actually the anti-CAPTCHA because it is a privacy-preserving, user-friendly alternative."

The Tor team believes the tool will discourage bad actors by making large-scale attacks more expensive and impractical. That's mainly because the Tor PoW will give priority to traffic verified as legitimate. "It's expected that a whole class of DoS attacks against onion services will simply disappear," said Zoneff.

Even better, Tor promises that performance will benefit from the new tool as well, by reducing the negative impact of targeted attacks on network speeds. This should ensure more consistent and reliable access to onion services overall. All onion sites are then encouraged to upgrade to version 0.4.8. right away to be sure of delivering users the safest possible service. 

Talking about further security upgrades, Zoneff told TechRadar: "We continue to focus on improving network health and speed and have rolled out Congestion Control and Conflux which aim at helping with network speeds. We continue to rewrite our core software in Rust, which will bring with it significant security improvements across the ecosystem, easier developer integration and faster feature iteration."

TechRadar VPN review disclaimer

Chiara Castro
News Editor (Tech Software)

Chiara is a multimedia journalist committed to covering stories to help promote the rights and denounce the abuses of the digital side of life – wherever cybersecurity, markets, and politics tangle up. She writes news, interviews, and analysis on data privacy, online censorship, digital rights, cybercrime, and security software, with a special focus on VPNs, for TechRadar and TechRadar Pro. Got a story, tip-off, or something tech-interesting to say? Reach out to chiara.castro@futurenet.com

Read more
Tor
What is Onion over VPN?
VPN server logo with foggy mountain in the middle
What is obfuscation? Everything you need to know about VPN obfuscation technology
Home internet connection. A wlan router on desk with notebook in background.
Cloudflare admits security tool is blocking some challenger browsers
An image of network security icons for a network encircling a digital blue earth.
Standing strong against hyper-volumetric DDoS attacks
Abstract illustration of a young woman looking at a smartphone, as large eyes peek through from her hair
Want to hit restart on your online presence? Here's 5 tools you need to stay truly private online
Security
Protect your network with an AI-secure browser and SASE framework
Latest in Pro
Branch office chairs next to a TechRadar-branded badge that reads Big Savings.
This office chair deal wins the Amazon Spring Sale for me and it's so good I don't expect it to last
Saily eSIM by Nord Security
"Much more than just an eSIM service" - I spoke to the CEO of Saily about the future of travel and its impact on secure eSIM technology
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
FlexiSpot office furniture next to a TechRadar-branded badge that reads Big Savings.
Upgrade your home office for under $500 in the Amazon Spring Sale: My top picks and biggest savings
Beelink EQi 12 mini PC
I’ve never seen a PC with an Intel Core i3 CPU, 24GB RAM, 500GB SSD and two Gb LAN ports sell for so cheap
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring