Tunneling was Re: Wondering about darknets security

Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]> Sat, 6 Aug 2011 17:24:15 +0100
Newsgroups gmane.network.freenet.support,gmane.network.freenet.technical
Message-ID <[email protected]>
--===============0648745345==
Content-Type: multipart/signed;
  boundary="nextPart2929933.RuIVjb5ggU";
  protocol="application/pgp-signature";
  micalg=pgp-sha256
Content-Transfer-Encoding: 7bit

--nextPart2929933.RuIVjb5ggU
Content-Type: Text/Plain;
  charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

On Saturday 30 Jul 2011 08:08:19 Volodya wrote:
> On 07/29/2011 05:28 PM, Dennis Nezic wrote:
> > On Tue, 26 Jul 2011 14:15:35 +0100, Matthew Toseland wrote:
> >> Basically, you are vulnerable to your peers (those other freenet
> >> nodes your node connects to). They know your IP address - they have
> >> to to connect to you. They can identify you. As you rightly point
> >> out, your peers can also, with a fair bit of work, and on various
> >> plausible assumptions, identify much of what you are doing on
> >> Freenet.
> >
> > When will premix routing and tunneling and onion routing be implemented?
>=20
> Who will authenticate the key of the node that you tunnel to? Your peer c=
an make
> you believe that it is a whole tunnel. Even if you use two peers and then=
 try to
> find a common friend of a friend of a friend... you are still making some=
 big
> assumptions. So as i see it tunnelling can only guarantee safety when you=
 100%
> trust your friends not to spy on you, and in that case you don't really n=
eed it.

Tunneling is possible, however it will, be rather expensive. Therefore by d=
efault we will only use it for predictable top blocks, chat posts, and rein=
serts. This will provide good protection against initially distant but mobi=
le attackers on darknet (because each hop is expensive, involving social en=
gineering or remote compromise), and to a lesser degree on opennet. (Unfort=
unately, connecting to everyone is likely a viable attack on opennet).

This will not happen before 0.8 however. It will require a good deal more d=
esign and implementation work and since lots of users seem to assume Freene=
t is perfectly secure anyway (although we try to dispel that in the wizard)=
, it won't help us to get funding, so it can't be a big priority for me or =
Ian in the near future.

The reason tunneling is expensive is to provide security against a realisti=
c adversary - one who is initially distant (if you're already a suspect the=
y've probably bugged your computer already, freenet is about *anonymity*, i=
=2Ee. not getting found in the first place) - we have to route through 2 or=
 3 nodes *distributed across the entire network*, or a large chunk of this.=
 On opennet, you can connect directly to do this - I2P does this, Tor does =
this. However:
=2D Opennet is very easy to block. In the first instance, blocking seednode=
s is trivial. In the second instance, harvesting all known nodes and blocki=
ng their IPs is quite feasible. The infrastructure for this is rapidly bein=
g built and deployed even in "free" countries, although currently it operat=
es mainly on the transparent HTTP proxy or DNS level.
=2D This does not help with darknet.
=2D Duplicating the existing code from other networks is probably not very =
worthwhile, and a lot more work than it sounds. (And it has its own set of =
vulnerabilities, e.g. Tor is arguably more vulnerable to traffic analysis t=
han we are). Integrating their code would be very difficult, and politicall=
y anathema to those (including Ian) who see Tor as a direct competitor, and=
 to those like me who see darknet as the future.

On darknet, such routing requires that we route between each pair of nodes =
*ON THE NETWORK*, i.e. it will take 7 or more hops from node 0 to node 1, a=
nd from node 1 to node 2, and that's before it starts the actual request. T=
his makes it rather expensive.

Because it is so expensive it will be off by default, apart from predictabl=
e blocks mentioned above. We will allow users to create multiple WoT identi=
ties with different security settings, upload/download queues etc, or to se=
t specific security settings for particular downloads/uploads.

--nextPart2929933.RuIVjb5ggU
Content-Type: application/pgp-signature; name=signature.asc 
Content-Description: This is a digitally signed message part.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEABEIAAYFAk49aq8ACgkQYUNbc3WUHYhKEwCgjCJQyw8dXXuultU+gq9tinKC
xz8Anjaeud1KOo/u93YmgIbAzpEQ8WsX
=Hoey
-----END PGP SIGNATURE-----

--nextPart2929933.RuIVjb5ggU--

--===============0648745345==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Support mailing list
[email protected]
http://news.gmane.org/gmane.network.freenet.support
Unsubscribe at http://emu.freenetproject.org/cgi-bin/mailman/listinfo/support
Or mailto:support-request-RdDMkVZAZeuJnvDnx1genB2eb7JE58TQ@public.gmane.org?subject=unsubscribe
--===============0648745345==--