Re: Freenet compared to Tahoe-LAFS
Ian Clarke <[email protected]> Sun, 25 Mar 2012 10:49:08 -0500
| Newsgroups | gmane.network.freenet.technical |
|---|---|
| Message-ID | <CAFbwM5EG=K+yFG=AeLmrv43J832t2Ut1jRv84ZPs_bk3yvR1cw@mail.gmail.com> |
--===============2107142767== Content-Type: multipart/alternative; boundary=0016e6d9a1f9fd8cad04bc133383 --0016e6d9a1f9fd8cad04bc133383 Content-Type: text/plain; charset=ISO-8859-1 On Sat, Mar 24, 2012 at 10:49 AM, Florent Daigniere < [email protected]> wrote: > On Sat, Mar 24, 2012 at 08:42:33AM -0600, Zooko Wilcox-O'Hearn wrote: > Hi Zooko, > > It was me... And the difference in betweek fproxy (the freenet web-gateway) > and what Tahoe-LAFS does is that we attempt to parse and filter the > content. Ah yes, this is true. We employ a whitelist approach so that only parts of the HTML DOM that we know to be safe get through. So, for example, anything that might cause the user's browser to ping a remote server is verboten. It seems to work well enough in practice (I don't recall anyone ever finding a vulnerability in it). But our threat model is quite different to Tahoe's, this type of thing may not be a concern for you. Ian. -- Ian Clarke Founder, The Freenet Project Email: [email protected] --0016e6d9a1f9fd8cad04bc133383 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable On Sat, Mar 24, 2012 at 10:49 AM, Florent Daigniere <span dir=3D"ltr"><<= a href=3D"mailto:[email protected]">[email protected]</= a>></span> wrote:<br><div class=3D"gmail_quote"><blockquote class=3D"gma= il_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-lef= t:1ex"> <div class=3D"im">On Sat, Mar 24, 2012 at 08:42:33AM -0600, Zooko Wilcox-O&= #39;Hearn wrote:<br> </div>Hi Zooko,<br> <br> It was me... And the difference in betweek fproxy (the freenet web-gateway)= <br> =A0and what Tahoe-LAFS does is that we attempt to parse and filter the cont= ent.</blockquote><div><br></div><div>Ah yes, this is true. =A0We employ a w= hitelist approach so that only parts of the HTML DOM that we know to be saf= e get through. =A0So, for example, anything that might cause the user's= browser to ping a remote server is verboten. =A0It seems to work well enou= gh in practice (I don't recall anyone ever finding a vulnerability in i= t).</div> </div><div><br></div><div>But our threat model is quite different to Tahoe&= #39;s, this type of thing may not be a concern for you.</div><div><br></div= >Ian.<br clear=3D"all"><div><br></div>-- <br>Ian Clarke<br>Founder, The Fre= enet Project<br> Email: <a href=3D"mailto:[email protected]" target=3D"_blank">ian@free= netproject.org</a><br> --0016e6d9a1f9fd8cad04bc133383-- --===============2107142767== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Tech mailing list [email protected] https://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech --===============2107142767==--