Re: Passing firewalls and hiding freenet traffic
Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]>
| Newsgroups | gmane.network.freenet.general |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Apr 22, 2005 at 11:08:25AM -0400, Nick Tarleton wrote: > If you were tunnelling over SSL on the https port, it's doubtful anyone could break it if you used a good key. (Wouldn't completely put it past the NSA though.) A bigger worry is that the traffic pattern would look suspicious; HTTP usually alternates small client->server transactions with large server->client transactions (unless the client is uploading lots of files); Freenet has large amounts of data continuously passing each way. Very unlike HTTP. Yes, that is a problem. But domestic SSL servers are very unusual, which is a bigger problem... > > As has been mentioned, though, the most effective thing a repressive government could do is just stop individuals' computers from accepting TCP connections except for a very few protocols where this would be commonly needed; and these protocols probably wouldn't be easy to hide Freenet under. I remember jrand0m's old proposal for a flexible steganographic protocol that could transport Freenet over HTTP, FTP, e-mail, or pretty much anything; seems interesting. Right. Video-conferencing might be an option, (it could even be UDP!), but would be suspicious 24/7. Hard links could be invisible from a network perspective, but are very visible from a physical perspective; you can perhaps use them for some of the "local" links (these could be wifi, cable, routed over a community wifi network, etc)... there are no easy answers, but you _can_ make it more expensive for your opponent. And you can do a lot more if you don't mind long latencies - email may be useful for some functions; transporting a box of DVD-Rs may be useful for others. > > -----Original Message----- > From: Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]> > Sent: Apr 22, 2005 8:31 AM > To: "panamerica334-hX/r/[email protected]" <panamerica334-hX/r/[email protected]> > Cc: "[email protected]" <[email protected]> > Subject: Re: [freenet-chat] Passing firewalls and hiding freenet traffic > > On Fri, Apr 22, 2005 at 09:43:02AM +0200, panamerica334-hX/r/[email protected] wrote: > > > >ssl is the best foundation for hiding traffic as there are many ssl-encrypted connections around and even if They find out how to break ssl, they would see the (with content-coding: gzip to preserve space and cleartext) http packets and have to demasquerade these. > > >difficult to find if you have no suspicion a specific ssl-channel could be carrying freenet protocol data -- Matthew J Toseland - toad-EI5O+8PHWbJeeLb3ft/[email protected] Freenet Project Official Codemonkey - http://freenetproject.org/ ICTHUS - Nothing is impossible. Our Boss says so. _______________________________________________ chat mailing list [email protected] Archived: http://news.gmane.org/gmane.network.freenet.general Unsubscribe at http://dodo.freenetproject.org/cgi-bin/mailman/listinfo/chat Or mailto:[email protected]?subject=unsubscribe
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (GNU/Linux) iD8DBQFCaRrLHzsuOmVUoi0RAkANAJ9kIvUBL7mTjDTeWgMPjM9OJ1G5fwCdGr1q s6yxpxPuIm7nP5uo1HhASAA= =fXL7 -----END PGP SIGNATURE-----