i2p economy / freeloaders

<auto97841-revL73yDgGBWk0Htik3J/[email protected]> Sat, 16 Aug 2003 15:51:53 -0700
Newsgroups gmane.comp.security.invisiblenet.iip.devel
Message-ID <[email protected]>
'lo y'all

Here's a hard problem for ya, and some ideas about how it could be overcome.
 Given what you can see in the net spec, you'll notice that there is
no reciprocity mechanism - no specific economics to force everyone to
participate fairly in the network.

With I2P, unfair participants ask lots of routers to participate in tunnels
without participating in tunnels in return, or refusing to source route
garlic messages.  (There is other "unfair" activity, but these two things
are the hard ones to deal with)

How can I2P get past this?

Two techniques jump out at first, neither of which are 1.0 issues, but
are things we may want to implement when they become appropriate as responses
to plausible attacks.

1) Make using tunnels and requesting garlic routed messages costly. 
This can be done trivially through the attached Certificate objects -
 either hashcash-style certs or more expensive ones.  Note that this
doesn't force people to participate, it just makes it harder to use limited
resources excessively (big difference)

2) When requesting that people route garlic messages or participate in
tunnels, offer them thanks in the form of a Certificate (currently included
in TunnelCreateMessage).  The cert can contain a statement like "router
X did service Y on date Z, signed by public key K: $signature".  The
recipient of the cert can then publish it as part of their RouterInfo
structure that everyone else can see.  Also, routers who request a service
that is not provided as requested could write and sign a certificate
stating "router X did NOT provide service Y on date Z as it agreed: $signature".
   

Routers can then then use these positive and negative ratings published
on the RouterInfo structures to help decide what routers to select to
participate in its tunnels and garlic routed messages.  This in itself
isn't immune to the Sybill attack, but at that point, routers can build
the trust network based on their own first hand experiences (e.g. router
X actually passed on messages as part of a tunnel, and router X says
router Y did a service for them).

Obviously, trust networks are hard.  Hard.  Definitely nontrivial.  etc.
 None of this is top priority.  I'm just writing this up and sending
it out so get y'all thinkin about some possible attacks and how I2P needs
to deal with them as they come up (see what happens when I'm pounding
guinnesses at the bar?  i need a fsckin life...)

so, um.  hi.

-jrandom



Concerned about your privacy? Follow this link to get
FREE encrypted email: https://www.hushmail.com/?l=2

Free, ultra-private instant messaging with Hush Messenger
https://www.hushmail.com/services.php?subloc=messenger&l=434

Promote security and make money with the Hushmail Affiliate Program: 
https://www.hushmail.com/about.php?subloc=affiliate&l=427