Proposal: permanent passwords

Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]>
Newsgroups gmane.network.freenet.technical
Message-ID <[email protected]>
Permanent passwords
===================

We could make IP + password play the same role as noderefs do now. They
must be exchanged in both directions, but if you have both passwords you
can initiate a connection and noderefs will be exchanged. This should be
a reasonably simple protocol: Just send a packet which includes proof
that you have both passwords (a hash), and a random nonce for crypto
setup.

This is no more work than out of band verification. However, you cannot
broadcast your IP + password and wait for people to contact you, which
is a distinct advantage in out of band verification: All contacts must
be arranged strictly in advance. And it's not very newbie friendly
either.

Dependancies
------------

UP&P isn't necessary if the exchange is conducted in real time. If it is
almost-real-time then UP&P may be helpful.

Attacks
-------

If the attacker can guess both passwords he can MITM, identify traffic,
etc.

_______________________________________________
Tech mailing list
[email protected]
http://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFF7M3VA9rUluQ9pFARAht0AJ9oueUBxrSSCmFqrSzgT/NuI+5bpwCfUZ1/
fxlfzvt61GQksOhr3qqa4XQ=
=pXbZ
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.