i2p economy / freeloaders
<auto97841-revL73yDgGBWk0Htik3J/[email protected]> Sat, 16 Aug 2003 15:51:53 -0700
| Newsgroups | gmane.comp.security.invisiblenet.iip.devel |
|---|---|
| Message-ID | <[email protected]> |
'lo y'all Here's a hard problem for ya, and some ideas about how it could be overcome. Given what you can see in the net spec, you'll notice that there is no reciprocity mechanism - no specific economics to force everyone to participate fairly in the network. With I2P, unfair participants ask lots of routers to participate in tunnels without participating in tunnels in return, or refusing to source route garlic messages. (There is other "unfair" activity, but these two things are the hard ones to deal with) How can I2P get past this? Two techniques jump out at first, neither of which are 1.0 issues, but are things we may want to implement when they become appropriate as responses to plausible attacks. 1) Make using tunnels and requesting garlic routed messages costly. This can be done trivially through the attached Certificate objects - either hashcash-style certs or more expensive ones. Note that this doesn't force people to participate, it just makes it harder to use limited resources excessively (big difference) 2) When requesting that people route garlic messages or participate in tunnels, offer them thanks in the form of a Certificate (currently included in TunnelCreateMessage). The cert can contain a statement like "router X did service Y on date Z, signed by public key K: $signature". The recipient of the cert can then publish it as part of their RouterInfo structure that everyone else can see. Also, routers who request a service that is not provided as requested could write and sign a certificate stating "router X did NOT provide service Y on date Z as it agreed: $signature". Routers can then then use these positive and negative ratings published on the RouterInfo structures to help decide what routers to select to participate in its tunnels and garlic routed messages. This in itself isn't immune to the Sybill attack, but at that point, routers can build the trust network based on their own first hand experiences (e.g. router X actually passed on messages as part of a tunnel, and router X says router Y did a service for them). Obviously, trust networks are hard. Hard. Definitely nontrivial. etc. None of this is top priority. I'm just writing this up and sending it out so get y'all thinkin about some possible attacks and how I2P needs to deal with them as they come up (see what happens when I'm pounding guinnesses at the bar? i need a fsckin life...) so, um. hi. -jrandom Concerned about your privacy? Follow this link to get FREE encrypted email: https://www.hushmail.com/?l=2 Free, ultra-private instant messaging with Hush Messenger https://www.hushmail.com/services.php?subloc=messenger&l=434 Promote security and make money with the Hushmail Affiliate Program: https://www.hushmail.com/about.php?subloc=affiliate&l=427