Re: Passing firewalls and hiding freenet traffic
| Newsgroups | gmane.network.freenet.general |
|---|---|
| Message-ID | <[email protected]> |
>easy; "silent bob" would be transformed to "picky bob"
>
>listen on port 80[http]/443[https]/8080[tomcat]/8443[ssl-tomcat]/3128[squid; not sure if the port number is correct]/whatever.
>if authorization was okay, send freenet protocol data back
>if auth failed, return http-500 with a short delay so retries are somewhat hindered :)
or yet even better -- return a valid site! so FRED would be a small webserver capable in handling low load for the ocassions someone stumbled into the server but when auth succeeds FRED switches to freenet for this one client. this way even the too-much-telling 500
could be evaded. as content for the "innocent" side the node maintainer can create their own webpage (stored within docroot) or use a default webpage saying something like "Hier entsteht eine Internetpräsenz" ("here will be a web presence shortly"), a very
widespread dummy content page for newly created websites. of course that would be typical for german hosts. but perhaps the default page could be automatically adjusted to the language settings of the OS. so in japan their typical "here will be a web presence shortly"
can be used. i think every country has their somewhat standard placeholders for empty webservers. if there are more than one of these for a given region (e.g. america), FRED would pick one of these on first startup by random so e.g. for america there would be five
standard placeholders where alice's FRED would choose one of these, and bob's FRED would choose a different one, making it difficult so see that both are freenet nodes viewed from an untrained eye.
>ssl is the best foundation for hiding traffic as there are many ssl-encrypted connections around and even if They find out how to break ssl, they would see the (with content-coding: gzip to preserve space and cleartext) http packets and have to demasquerade these.
>difficult to find if you have no suspicion a specific ssl-channel could be carrying freenet protocol data
hm, does "content-encoding: gzip" support passworded gzips?
just my 0,02¬
_______________________________________________
chat mailing list
[email protected]
Archived: http://news.gmane.org/gmane.network.freenet.general
Unsubscribe at http://dodo.freenetproject.org/cgi-bin/mailman/listinfo/chat
Or mailto:[email protected]?subject=unsubscribe