Re: opennet/darknet

Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]> Tue, 7 Dec 2010 17:51:46 +0000
Newsgroups gmane.network.freenet.technical
Message-ID <[email protected]>
--===============0285410425==
Content-Type: multipart/signed;
  boundary="nextPart2534306.QQYkl0BKOt";
  protocol="application/pgp-signature";
  micalg=pgp-sha1
Content-Transfer-Encoding: 7bit

--nextPart2534306.QQYkl0BKOt
Content-Type: text/plain;
  charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

On Sunday 05 December 2010 05:21:42 hppppl fdfjisoa wrote:
>=20
> Hello, I remember all the discussions about opennet vs. darknet with diff=
icult security issues causing the project to focus on darknet, and I am rem=
inded of my nagging questions by recent devl discussions.
> I have concerns about darknet that maybe you folks have all figured out, =
but I don't recall it being mentioned anywhere, so perhaps you can explain.
>=20
> Many people obviously correlate the desire for anonymity for the desire t=
o conduct 'illegal' behavior. Would I want to directly ask people I know if=
 they run or if they would be willing to run a freenet node in a society wh=
ere there may be a stigma associated with this?
>=20
> What if a country makes running a freenet node illegal? Is it then more s=
afe to be connected to people you know? Is it more safe to approach the peo=
ple you know about it and risk getting turned in? Or when someone you know =
is caught operating a node, then they can confess about all the people they=
 connect to, and whole groups of people can be caught at once.
>=20
> I am wondering if opennet's inadequacies are inherent or if making it mor=
e secure is very hard. I'm just trying to imagine how the different concept=
s play out in various scenarios. I guess I just don't understand the reason=
ing.
>  		 	   		 =20
Opennet's inadequacies are IMHO inherent. It may be possible to build an op=
ennet-style distributed onion routing network like I2P (but IMHO it's an op=
en question), but on freenet's architecture it is inherently very vulnerabl=
e.

The answer to all such paranoid attacks on darknet is simple:
There is absolutely no way we can make it easy for a new user to get bootst=
rapped onto opennet without making it easy for an attacker to find and eith=
er connect to or block all opennet nodes.

Right now opennet's security is so poor that they are more likely to connec=
t to them all rather than blocking them. However blocking them is a very ch=
eap option.

The cost of creating a climate of fear where you can be subject to a dawn r=
aid merely because somebody said they heard you talking about Freenet, and =
where you can be imprisoned merely because Freenet was found after that, or=
 where a large proportion of your darknet peers are likely to knowingly run=
 government surveillance software, is *vastly* higher than *any* conceivabl=
e attack on even a large opennet.

--nextPart2534306.QQYkl0BKOt
Content-Type: application/pgp-signature; name=signature.asc 
Content-Description: This is a digitally signed message part.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEABEIAAYFAkz+dDIACgkQYUNbc3WUHYi7dwCfc5PnKo+jC2vhSGLp81MqhfnK
vUMAni1OzTZU+EiguabjUZrLl92YrlRq
=NNP5
-----END PGP SIGNATURE-----

--nextPart2534306.QQYkl0BKOt--

--===============0285410425==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Tech mailing list
[email protected]
http://freenetproject.org/cgi-bin/mailman/listinfo/tech
--===============0285410425==--