Crazy idea: How trust in darknets enables secure democratic censorship
Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]>
| Newsgroups | gmane.network.freenet.general,gmane.network.freenet.technical |
|---|---|
| Message-ID | <[email protected]> |
Here's a really whacky idea I came up with on the train back from Strasbourg (please read the whole email before flaming me): Personally I support Freenet being uncensorable and providing untraceability for posters, because there is no way to prevent censorship abuses by the powerful (including governments and corporations), while still allowing censorship to prevent e.g. child porn. I propose below a means that could provide some form of self regulation, under locally democratic control, which would provide a powerful deterrent to people posting objectionable materials. This is only possible because of the trust relationships underlying a scalable darknet such as Freenet 0.7/Dark. There is an argument that unpopular content will fall out of the current Freenet; it won't if the original insertor keeps on pushing it back in. Maybe, just maybe, we can have our cake and eat it too. The result would be that freenet could be far more mainstream, usable by far more people (e.g. oppressed religious groups in china are likely to object to all the kiddy porn on freenet), and its content would reflect what its users want rather than what the state wants. Definition: Premix ID: - Each node has two identities. One is its pubkey and physical location to connect to it. This is only given out to its immediate peers, and they may not forward it, on a darknet. The second is its premix pubkey. This is the key which is used to encrypt premix-routed traffic which is sent through the node. This is public, along with the node's connections, in order for premix routing to work through the darknet - we have to expose the network topology in order for premix routing to work. Client C finds some content he finds objectionable. He sends out a Complaint to his friend nodes. This contains a pointer to the objectionable content, and possibly C's premix ID (I'm not decided on this bit). Users can then verify the complaint - voting for it to be upheld or not and for what sanctions to be applied. If it is not upheld by enough nodes it is not propagated, so complaint spamming will be severely limited. Each node can decide whether the complaint is upheld. It will take into account its own vote if any (weight 1), the votes of its friend nodes (weight 1), and the votes of those nodes connected to its friend nodes (probably weighted 1/n where n is the number of nodes connected to a given friend node). There would be turnout requirements (say 2/3), and supermajority requirements which depend on what sanction is called for. If the complaint is upheld, then the network will attempt to trace the insertor, and possibly any requestors, of the data: If a node was on the insert path, AND it considers the complaint to have been upheld, it will check its records and attempt to trace the request. As will the next node on the chain. The original insertor will be found, and its premix ID exposed. Possible sanctions are: - Reprimand; upheld complaint is recorded on the node's record - Premix disconnect; node may no longer use premix routing - Full disconnect; node may not remain connected to the network. Requires a larger supermajority. - Blow the node; node's IP address is broadcast (endangers the network itself, would require 80% or so majority, and could be turned off on some networks). The idea here is that we produce a deterrant. Nodes won't insert content regarded as bad by the majority of a particular network, because of the risks involved, and therefore complaints should be rare. The content itself would be blocked, but only after the vote, which could take a reasonable time - say 2 weeks - during which any interested individuals could inspect the objectionable content (many will simply follow others, but this is not a problem as the content _is_ available; provided the system works, complaints will be rare and people will not have to browse through filth on a regular basis). This should keep the whole process accountable. If the original insertor is not found, we can get as close as possible. Since there will likely be several blocks to trace (even if the objectionable content is a single file), and since we know the network topology, we can do some form of correlation attack - and narrow it down to a particular area of the network. If it is one node, we can take the above sanctions; if it is a group of nodes (or a particular link or set of links), then we can break those connections and fork the network into two disconnected darknets with different standards (it should be reasonably easy to determine this given enough data to trace). Votes would have to be public for this to work (at least, public to nearby nodes). There is no secret ballot. On the other hand, since we are assuming that Freenet nodes are illegal in any case in the long term on a darknet, and since nobody who isn't trusted by you can find your IP address, people should be able to vote in accordance with their consciences. Technical forms of voterigging will be very difficult due to this being a local rather than a global vote, and since votes are public, and nodes' operators can talk to other nodes' operators (with free anti-spam mechanisms of course), buying votes etc shouldn't be a big problem. Secret ballot protocols might be possible but would be difficult and dubious given that each node will participate in many votes with the same vote (one for each node it is connected to). -- Matthew J Toseland - toad-EI5O+8PHWbJeeLb3ft/[email protected] Freenet Project Official Codemonkey - http://freenetproject.org/ ICTHUS - Nothing is impossible. Our Boss says so. _______________________________________________ chat mailing list [email protected] Archived: http://news.gmane.org/gmane.network.freenet.general Unsubscribe at http://dodo.freenetproject.org/cgi-bin/mailman/listinfo/chat Or mailto:[email protected]?subject=unsubscribe
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (GNU/Linux) iD8DBQFC0o2dHzsuOmVUoi0RAlwCAJ0UjC+dSGgWh0sTeA/8b1qgwg0ZBwCdGHrA gAMojaNABe104e5nhrOYZHs= =+XZU -----END PGP SIGNATURE-----