Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

Sociotechnical Aspects of Tor Relay Rejection

A study of the 2019 Tor end-of-life policy, its impact on relay operators, network security, and anonymity
Jules Dejaeghere; Lionel Goffaux; Pierre Luycx; Hosam Elkoulak; Florentin Rochetยท 2026ยท DOI 10.48550/arXiv.2609.15192

The core problem

In 2019, the Tor Project enforced an end-of-life (EoL) policy for Tor versions, leading to the rejection of outdated relays, amounting to a notable fraction of consensus weight. While this policy aids network maintenance, reduces backporting efforts, and shortens vulnerability exposure, its sociotechnical implications remain unstudied. This paper addresses this gap by investigating how relay operators perceive the EoL policy and what impact the rejection of outdated relays has on network security and user anonymity. The authors conduct a user study with 26 relay operators and perform network simulations grounded in historical data to assess the policy's immediate impact against common adversaries. They introduce security metrics to evaluate relay contributions and analyze four exclusion rounds. The findings reveal that operators generally view the policy favorably, though awareness is not universal, and that network churn exerts a more pronounced effect on anonymity than the policy itself. A minority of rejected relays typically account for over 50% of the security provided by all excluded relays. Recommendations for EoL policy implementation are proposed to mitigate potential draw

Innovation

The user study reveals that relay operators, though not universally aware of the EoL policy, generally view it favorably. Operational practices vary, occasionally excluding newly installed relays from the network. Network simulations indicate a marginal adversarial advantage due to the policy, with network churn (i.e., relays entering and exiting) exerting a more pronounced effect on user anonymity. Analysis of four exclusion rounds shows that a minority of rejected relays typically account for over 50% of the security provided by all excluded relays. Specifically, the security contribution of rejected relays can be quantified using metrics such as the probability of a relay being selected in a circuit. For a relay , its selection probability is proportional to its consensus weight :

The results suggest that the EoL policy's impact on anonymity is small compared to the natural churn of the network. The authors also find that the policy reduces the number of vulnerable relays, thereby shortening exposure to known vulnerabilities.

In 2019, the Tor Project enforced an end-of-life (EoL) policy for Tor versions, leading to the rejection of outdated relays, amounting to a notable fraction of consensus weight. While this policy aids network maintenance, reduces backporting efforts, and shortens vulnerability exposure, its sociotechnical implications remain unstudied. This paper addresses this gap by investigating how relay operators perceive the EoL policy and what impact the rejection of outdated relays has on network security and user anonymity. The authors conduct a user study with 26 relay operators and perform network simulations grounded in historical data to assess the policy's immediate impact against common adversaries. They introduce security metrics to evaluate relay contributions and analyze four exclusion rounds. The findings reveal that operators generally view the policy favorably, though awareness is not universal, and that network churn exerts a more pronounced effect on anonymity than the policy itself. A minority of rejected relays typically account for over 50% of the security provided by all excluded relays. Recommendations for EoL policy implementation are proposed to mitigate potential drawbacks.
The study employs a mixed-methods approach combining a user study with network simulations. The user study involved semi-structured interviews with Tor relay operators to gauge awareness and attitudes toward the EoL policy, as well as operational practices. The simulations are grounded in historical Tor network data to model the immediate impact of relay rejection on client anonymity against two adversary models: a global passive adversary and a relay-level adversary. The authors introduce security metrics to quantify the contribution of individual relays to network security, enabling ranking by utility and security. They analyze four exclusion rounds corresponding to the EoL enforcement, identifying which relays were rejected and their impact. The simulation framework is illustrated in the following Mermaid diagram:

Why it matters

The findings highlight a tension between the security benefits of the EoL policy and its sociotechnical implications. While the policy effectively removes outdated relays and reduces backporting efforts, it may inadvertently exclude relays that contribute significantly to network security. The analysis of exclusion rounds shows that a small number of relays provided a disproportionate amount of security, suggesting that blanket rejection based on version may not be optimal. The authors propose recommendations for EoL policy implementation, such as gradual phase-outs, better communication with operators, and considering relay utility in exclusion decisions. The study also underscores the importance of network churn as a factor affecting anonymity, which may overshadow the policy's direct effects. The security metrics introduced enable a more nuanced evaluation of relay contributions, potentially guiding future policy decisions. Overall, the paper contributes to the understanding of sociotechnical aspects in anonymity networks and offers practical insights for the Tor Project.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ