FINDING · EVALUATION
HOWLR provides Light protection (≥3 witnesses in prefix) to 89% of Tor relay prefixes and Strong protection (≥8 witnesses from ≥2 CAs) to 64%, based on sampling 200 random relays. By contrast, DNS server prefixes receive Light protection in only 40% and Strong protection in only 12% of cases, reflecting their tendency toward residential or sparse hosting.
From 2026-doumanidis-howlr-client-driven-approach — HOWLR: A Client-Driven Approach to BGP Hijack Detection · §6 · 2026 · arXiv preprint
Implications
- Tor relay operators should prioritize hosting on professional cloud/data-center infrastructure rather than residential IPs, where co-located TLS-authenticated witnesses exist at sufficient density for BGP-hijack detection.
- Circumvention tools can implement HOWLR-style witness discovery as a pre-flight check before adding a relay/bridge to an active peer set.
Tags
Extracted by claude-sonnet-4-6 — review before relying.