On Thu, Dec 21, 2017 at 10:11:47PM +0100, Felix wrote: My current thought is that these are actually Tor clients, not intentional denial-of-service attacks, but there are millions of them so they are producing surprises and damage. (Also, maybe there is not a human behind each of the Tor clients, so maybe we shouldn't value them as much as we would value more Tor Browser users.)
I've started the process of cranking down the extra circuits that new clients make: https://trac.torproject.org/24716
With luck, over the next day or so things will get better. We'll learn something about the issue either way.
Keep an eye on your "Circuit handshake stats since last time" notice-level log lines over the next day or two.
(This won't resolve the "way too many connections" issue though. One step at a time. :)
--Roger