FINDING · DETECTION
OLF reduces an adversary's target anonymity set from roughly 10,000 active onionsites to the ~1,500 stably available O-L sites—nearly an order of magnitude. Because O-L requires an exit circuit with a DNS lookup, a DNS-based Website Oracle further collapses the false-positive rate, making OLF effectively a closed-world attack on the enumerated O-L site list.
From 2025-syverson-onion-location-measurements-fingerprinting — Onion-Location Measurements and Fingerprinting · §2.3, §3 · 2025 · PoPETs 2025
Implications
- Any OA mechanism that requires a clearnet DNS lookup before connecting to the onion service exposes the visit to a Website Oracle attack; designs should avoid mandatory clearnet contact at per-connection time.
- Do not assume the large overall onion-service anonymity set protects O-L users; the effective anonymity set for O-L users is approximately 10× smaller and is fully enumerable by a passive guard adversary.
Tags
Extracted by claude-sonnet-4-6 — review before relying.