Re: Freenet compared to Tahoe-LAFS

Ian Clarke <[email protected]> Sun, 25 Mar 2012 10:49:08 -0500
Newsgroups gmane.network.freenet.technical
Message-ID <CAFbwM5EG=K+yFG=AeLmrv43J832t2Ut1jRv84ZPs_bk3yvR1cw@mail.gmail.com>
--===============2107142767==
Content-Type: multipart/alternative; boundary=0016e6d9a1f9fd8cad04bc133383

--0016e6d9a1f9fd8cad04bc133383
Content-Type: text/plain; charset=ISO-8859-1

On Sat, Mar 24, 2012 at 10:49 AM, Florent Daigniere <
[email protected]> wrote:

> On Sat, Mar 24, 2012 at 08:42:33AM -0600, Zooko Wilcox-O'Hearn wrote:
> Hi Zooko,
>
> It was me... And the difference in betweek fproxy (the freenet web-gateway)
>  and what Tahoe-LAFS does is that we attempt to parse and filter the
> content.


Ah yes, this is true.  We employ a whitelist approach so that only parts of
the HTML DOM that we know to be safe get through.  So, for example,
anything that might cause the user's browser to ping a remote server is
verboten.  It seems to work well enough in practice (I don't recall anyone
ever finding a vulnerability in it).

But our threat model is quite different to Tahoe's, this type of thing may
not be a concern for you.

Ian.

-- 
Ian Clarke
Founder, The Freenet Project
Email: [email protected]

--0016e6d9a1f9fd8cad04bc133383
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

On Sat, Mar 24, 2012 at 10:49 AM, Florent Daigniere <span dir=3D"ltr">&lt;<=
a href=3D"mailto:[email protected]">[email protected]</=
a>&gt;</span> wrote:<br><div class=3D"gmail_quote"><blockquote class=3D"gma=
il_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-lef=
t:1ex">

<div class=3D"im">On Sat, Mar 24, 2012 at 08:42:33AM -0600, Zooko Wilcox-O&=
#39;Hearn wrote:<br>
</div>Hi Zooko,<br>
<br>
It was me... And the difference in betweek fproxy (the freenet web-gateway)=
<br>
=A0and what Tahoe-LAFS does is that we attempt to parse and filter the cont=
ent.</blockquote><div><br></div><div>Ah yes, this is true. =A0We employ a w=
hitelist approach so that only parts of the HTML DOM that we know to be saf=
e get through. =A0So, for example, anything that might cause the user&#39;s=
 browser to ping a remote server is verboten. =A0It seems to work well enou=
gh in practice (I don&#39;t recall anyone ever finding a vulnerability in i=
t).</div>

</div><div><br></div><div>But our threat model is quite different to Tahoe&=
#39;s, this type of thing may not be a concern for you.</div><div><br></div=
>Ian.<br clear=3D"all"><div><br></div>-- <br>Ian Clarke<br>Founder, The Fre=
enet Project<br>

Email: <a href=3D"mailto:[email protected]" target=3D"_blank">ian@free=
netproject.org</a><br>

--0016e6d9a1f9fd8cad04bc133383--

--===============2107142767==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Tech mailing list
[email protected]
https://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech
--===============2107142767==--