[tor-talk] Running an exit node which exits on a different IP than it listens to

Michael O Holstein michael.holstein at csuohio.edu
Tue Jun 24 13:35:45 UTC 2014


Is the collateral damage from trying to play hide-and-seek from RBL services really worth it? .. the "overzealoous" RBL operators just want to catalog proxy servers so website ops can decide if they want the headache or not -- which is a perfectly valid concern.

Overzealous is what happens when you try and play games and RBLs start getting less specific than a /32. 

I've been on both sides of this one, and were I to fire up an exit again I'd want to run it at zero bandwidth for a month or so just so all the RBL ops ensure it's listed .. people rush to abuse the new ones, and not for utopian visions of a free Internet either.

Michael Holstein
Cleveland State University


________________________________________
From: tor-talk <tor-talk-bounces at lists.torproject.org> on behalf of Anders Andersson <pipatron at gmail.com>
Sent: Tuesday, June 24, 2014 9:07 AM
To: tor-talk at lists.torproject.org
Subject: [tor-talk] Running an exit node which exits on a different IP than     it listens to

I have been sorting through my mailbox the last few days and stumbled
upon an email from 2012, from this mailing list. A worried user got a
false negative from check.torproject.org because an exit relay sent
exit traffic out on an IP that's different from what was advertised.

However, this made me think that it is perhaps not such a bad idea if
more exit relays did that, even slower ones. I have access to a couple
of IP numbers that I could easily configure in this way.

Basically: Use one IP for Tor traffic, and one IP for exit traffic.
The Tor traffic IP:Port is what would be advertised to the Tor
network, and only that.

The reason would be to minimize the chances of the exit IP ending up
in some overzealous blacklist. I'm pretty sure that a lot of the
blacklist operators just scrape the public list of relays and then
they end up in a lot of places where the customer is not even aware
what is being blocked. This is painfully obvious to people running a
non-exit relay from home, when trying to use IRC or other services.

Is this a good idea to do if you have the resources? Will it cause any
non-obvious problems? I guess one problem is that check.torproject.org
will show that you're not using Tor, unless it's been modified since
2012 to check this in another way.

I'm not sure if I'm making myself clear here, please ask me to clarify
if this is the case.

// Anders
--
tor-talk mailing list - tor-talk at lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk


More information about the tor-talk mailing list