Re: Passing firewalls and hiding freenet traffic

Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]>
Newsgroups gmane.network.freenet.general
Message-ID <[email protected]>
On Wed, Apr 27, 2005 at 02:42:57AM +0200, Martin Scheffler wrote:
> Am Freitag, 22. April 2005 17:39 schrieb Matthew Toseland:
> > On Fri, Apr 22, 2005 at 11:08:25AM -0400, Nick Tarleton wrote:
> > > ... A bigger worry is that the traffic
> > > pattern would look suspicious; HTTP usually alternates small
> > > client->server transactions with large server->client transactions
> > > (unless the client is uploading lots of files); Freenet has large
> > > amounts of data continuously passing each way. Very unlike HTTP.
> 
> With freenet 0.6 we have bi-directional pipes, maybe it is possible to 
> make the connections uni, so that the connecting peer only sends 
> requests, and the "server" only sends results. However, opening two 
> connections A->B and B->A does not seem valueable either.
> This would imply an higher connection count (bad for the small world 
> thing?).

Counts as one connection really.. but the problem would be that it
doesn't really solve the problem, as it's rare that you have such
bidirectional HTTP connections. We could disguise traffic as e.g.
realplayer, or h.323/internet telephony, and keep UDP. There are a
number of possibilities and each one is less than ideal.
> 
> > Yes, that is a problem. But domestic SSL servers are very unusual,
> > which is a bigger problem...
> 
> We could bring the world on SSL if freenet rocks (SCNR).
> But anyway, why not add the possibility to put a personal homepage aside, 
> mimicing an apache or IIS or boa or anything webserver, and suddenly more 
> and more people present their (legal) content via https and run a node.

The best thing is probably a passthrough. We want to have a real web
server behind it, so we don't have to mimic it. Then we just takeover
when we need to. This would make portscanning totally worthless. But I'd
like to have UDP as an option for performance reasons.
> 
> This shall not be the only option, because some providers block or slow 
> down connections to clients. We _have_ to make it work with outbound 
> conns only or other restraints.

_That_ will be very hard. We can get over a typical domestic firewall.
We can even get over an ISP's NAT, if they support the tricks needed to
pass UDP (or TCP).. intentionally. Outgoing connections only, in the
strict sense, is possible, but:
- For fixed/trusted links, it shouldn't be a huge problem
- For dynamic links, we would need an external or internal means for
  nodes outside to tell the node to connect to them, rather than
  directly connecting to it.
-- 
Matthew J Toseland - toad-EI5O+8PHWbJeeLb3ft/[email protected]
Freenet Project Official Codemonkey - http://freenetproject.org/
ICTHUS - Nothing is impossible. Our Boss says so.

_______________________________________________
chat mailing list
[email protected]
Archived: http://news.gmane.org/gmane.network.freenet.general
Unsubscribe at http://dodo.freenetproject.org/cgi-bin/mailman/listinfo/chat
Or mailto:[email protected]?subject=unsubscribe
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (GNU/Linux)

iD8DBQFCbuKGHzsuOmVUoi0RAiNLAJ9RrLR1eKCGlHgH3B4o7R0K3bE42wCfcJEU
4ZXxBXHMb4OpfKha6aMIeHs=
=2dou
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.