Crazy idea: How trust in darknets enables secure democratic censorship

Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]>
Newsgroups gmane.network.freenet.general,gmane.network.freenet.technical
Message-ID <[email protected]>
Here's a really whacky idea I came up with on the train back from
Strasbourg (please read the whole email before flaming me):

Personally I support Freenet being uncensorable and providing
untraceability for posters, because there is no way to prevent
censorship abuses by the powerful (including governments and
corporations), while still allowing censorship to prevent e.g.
child porn. I propose below a means that could provide some form of self
regulation, under locally democratic control, which would provide a
powerful deterrent to people posting objectionable materials. This is
only possible because of the trust relationships underlying a scalable
darknet such as Freenet 0.7/Dark. There is an argument that unpopular
content will fall out of the current Freenet; it won't if the original
insertor keeps on pushing it back in. Maybe, just maybe, we can have our
cake and eat it too. The result would be that freenet could be far more
mainstream, usable by far more people (e.g. oppressed religious groups in
china are likely to object to all the kiddy porn on freenet), and its
content would reflect what its users want rather than what the state
wants.

Definition: Premix ID:
- Each node has two identities. One is its pubkey and physical location
  to connect to it. This is only given out to its immediate peers, and
  they may not forward it, on a darknet. The second is its premix
  pubkey. This is the key which is used to encrypt premix-routed traffic
  which is sent through the node. This is public, along with the node's
  connections, in order for premix routing to work through the darknet -
  we have to expose the network topology in order for premix routing to
  work.

Client C finds some content he finds objectionable.
He sends out a Complaint to his friend nodes. This contains a pointer to
the objectionable content, and possibly C's premix ID (I'm not decided
on this bit).
Users can then verify the complaint - voting for it to be upheld or not
and for what sanctions to be applied. If it is not upheld by enough
nodes it is not propagated, so complaint spamming will be severely
limited.
Each node can decide whether the complaint is upheld. It will take into
account its own vote if any (weight 1), the votes of its friend nodes
(weight 1), and the votes of those nodes connected to its friend nodes
(probably weighted 1/n where n is the number of nodes connected to a
given friend node). There would be turnout requirements (say 2/3), and
supermajority requirements which depend on what sanction is called for.

If the complaint is upheld, then the network will attempt to trace the
insertor, and possibly any requestors, of the data:

If a node was on the insert path, AND it considers the complaint to have
been upheld, it will check its records and attempt to trace the request.
As will the next node on the chain. The original insertor will be found,
and its premix ID exposed. Possible sanctions are:
- Reprimand; upheld complaint is recorded on the node's record
- Premix disconnect; node may no longer use premix routing
- Full disconnect; node may not remain connected to the network.
  Requires a larger supermajority.
- Blow the node; node's IP address is broadcast (endangers the network
  itself, would require 80% or so majority, and could be turned off on
  some networks).

The idea here is that we produce a deterrant. Nodes won't insert content
regarded as bad by the majority of a particular network, because of the
risks involved, and therefore complaints should be rare. The content
itself would be blocked, but only after the vote, which could take a
reasonable time - say 2 weeks - during which any interested individuals
could inspect the objectionable content (many will simply follow others,
but this is not a problem as the content _is_ available; provided the
system works, complaints will be rare and people will not have to browse
through filth on a regular basis). This should keep the whole process
accountable.

If the original insertor is not found, we can get as close as possible.
Since there will likely be several blocks to trace (even if the
objectionable content is a single file), and since we know the network
topology, we can do some form of correlation attack - and narrow it down
to a particular area of the network. If it is one node, we can take the
above sanctions; if it is a group of nodes (or a particular link or set
of links), then we can break those connections and fork the network into
two disconnected darknets with different standards (it should be
reasonably easy to determine this given enough data to trace).

Votes would have to be public for this to work (at least, public to
nearby nodes). There is no secret ballot. On the other hand, since we
are assuming that Freenet nodes are illegal in any case in the long term
on a darknet, and since nobody who isn't trusted by you can find your IP
address, people should be able to vote in accordance with their
consciences. Technical forms of voterigging will be very difficult due
to this being a local rather than a global vote, and since votes are
public, and nodes' operators can talk to other nodes' operators (with
free anti-spam mechanisms of course), buying votes etc shouldn't be a big
problem. Secret ballot protocols might be possible but would be difficult
and dubious given that each node will participate in many votes with the
same vote (one for each node it is connected to).
-- 
Matthew J Toseland - toad-EI5O+8PHWbJeeLb3ft/[email protected]
Freenet Project Official Codemonkey - http://freenetproject.org/
ICTHUS - Nothing is impossible. Our Boss says so.

_______________________________________________
chat mailing list
[email protected]
Archived: http://news.gmane.org/gmane.network.freenet.general
Unsubscribe at http://dodo.freenetproject.org/cgi-bin/mailman/listinfo/chat
Or mailto:[email protected]?subject=unsubscribe
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFC0o2dHzsuOmVUoi0RAlwCAJ0UjC+dSGgWh0sTeA/8b1qgwg0ZBwCdGHrA
gAMojaNABe104e5nhrOYZHs=
=+XZU
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.