Re: opennet/darknet
Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]> Tue, 7 Dec 2010 17:51:46 +0000
| Newsgroups | gmane.network.freenet.technical |
|---|---|
| Message-ID | <[email protected]> |
--===============0285410425== Content-Type: multipart/signed; boundary="nextPart2534306.QQYkl0BKOt"; protocol="application/pgp-signature"; micalg=pgp-sha1 Content-Transfer-Encoding: 7bit --nextPart2534306.QQYkl0BKOt Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline On Sunday 05 December 2010 05:21:42 hppppl fdfjisoa wrote: >=20 > Hello, I remember all the discussions about opennet vs. darknet with diff= icult security issues causing the project to focus on darknet, and I am rem= inded of my nagging questions by recent devl discussions. > I have concerns about darknet that maybe you folks have all figured out, = but I don't recall it being mentioned anywhere, so perhaps you can explain. >=20 > Many people obviously correlate the desire for anonymity for the desire t= o conduct 'illegal' behavior. Would I want to directly ask people I know if= they run or if they would be willing to run a freenet node in a society wh= ere there may be a stigma associated with this? >=20 > What if a country makes running a freenet node illegal? Is it then more s= afe to be connected to people you know? Is it more safe to approach the peo= ple you know about it and risk getting turned in? Or when someone you know = is caught operating a node, then they can confess about all the people they= connect to, and whole groups of people can be caught at once. >=20 > I am wondering if opennet's inadequacies are inherent or if making it mor= e secure is very hard. I'm just trying to imagine how the different concept= s play out in various scenarios. I guess I just don't understand the reason= ing. > =20 Opennet's inadequacies are IMHO inherent. It may be possible to build an op= ennet-style distributed onion routing network like I2P (but IMHO it's an op= en question), but on freenet's architecture it is inherently very vulnerabl= e. The answer to all such paranoid attacks on darknet is simple: There is absolutely no way we can make it easy for a new user to get bootst= rapped onto opennet without making it easy for an attacker to find and eith= er connect to or block all opennet nodes. Right now opennet's security is so poor that they are more likely to connec= t to them all rather than blocking them. However blocking them is a very ch= eap option. The cost of creating a climate of fear where you can be subject to a dawn r= aid merely because somebody said they heard you talking about Freenet, and = where you can be imprisoned merely because Freenet was found after that, or= where a large proportion of your darknet peers are likely to knowingly run= government surveillance software, is *vastly* higher than *any* conceivabl= e attack on even a large opennet. --nextPart2534306.QQYkl0BKOt Content-Type: application/pgp-signature; name=signature.asc Content-Description: This is a digitally signed message part. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEABEIAAYFAkz+dDIACgkQYUNbc3WUHYi7dwCfc5PnKo+jC2vhSGLp81MqhfnK vUMAni1OzTZU+EiguabjUZrLl92YrlRq =NNP5 -----END PGP SIGNATURE----- --nextPart2534306.QQYkl0BKOt-- --===============0285410425== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Tech mailing list [email protected] http://freenetproject.org/cgi-bin/mailman/listinfo/tech --===============0285410425==--