A group of researchers have written a paper that lays out an attack against Tor (PDF) in enough detail to cause Roger Dingledine a fair amount of heartburn. The essential avenue of attack is that Tor doesn’t verify claims of uptime or bandwidth, allowing an attacker to advertise more than it need deliver, and thus draw traffic.
There doesn’t seem to be huge concern over this exploit right now, but it’s something Tor users should bear in mind. With this information public, a “fix” is probably right around the corner.
Source: Slashdot