Live data from Hacker News

Orchid: a new surveillance-free layer on top of the existing Internet

orchidprotocol.com

131–140 of 196 posts

Re: Orchid: a new surveillance-free layer on top of the existing Internet

#131

What would convince my mom to use this though?

So, I don't know your mother, and can't say what kind of extreme technical needs she might have as part of her lifestyle or job; but, I guess I will presume you asked this question from the depressingly stereotypical perspective of "assuming peoples' mothers are not very technically skilled as they are older women, how would a mother use it" and answer your question anyway :(.

So, she might not use the first version, and if she does it might be installed or otherwise set up by you (so this hinges a lot on how much she trusts you ;P) or another friend of hers. However, we are building a simple user interface to make the experience of using it friendly and pleasant, and I guess it is worth adding that we also chose a name that we hope does not turn non-technical users away ;P.

Re: Orchid: a new surveillance-free layer on top of the existing Internet

#132
post #129

Earlier quoted context omitted.

We believe, as do many people as far as I have seen, that if a country like China could block the entire world of Internet, they would. Regardless: I consider it my mission to make them have to seriously consider doing just that, and if I read a news report saying "in a shocking turn of events, China has decided to cut off all access to the Western Internet in an attempt to shut down Orchid", I will consider myself t…

> I will consider myself to have won that round, not lost ;P. If fame and victory are what your company is going after, instead of taking care of your potential users, then I am sorry that you won't have my support. Btw, thank you for creating cydia if you were the author.

To "win" here means "win a battle on the road to an Internet free of surveillance". I (personally) firmly believe that if China were to do that, that the people would not stand for it; any form of "half solution" or "compromise position" where the Chinese govnerment can block just enough to remove access to material that bothers them while only minority inconveniencing users, is a world in which this form of freedom is actually less likely, as people are willing to tolerate a sad lot before try finally snap back :/.

It is also worth noting that if they went that far, at least some of the other Western countries that are currently willing to tolerate their seemingly-limited control over the Internet would no longer feel comfortable standing idly by and might have to start making resolutions against them. Again: forcing that chess move from them would, in my (personal) book, be a strong win in this fight.

FWIW, you seem to be taking a very short-term definition of "taking care of your potential users" that I have sometimes seen in attempts to make excuses for Apple over the past decade of my work on Cydia (such as when I have stated that one of my "win conditions" for Cydia Impactor is for Apple to remove entirely the Free Developer profile system), and I (personally: I do not speak for anyone else on my team when I say this) do not feel the loss of your support on this particular day (though maintain hope that in a few years you will thank us as you have now me for Cydia).

Re: Orchid: a new surveillance-free layer on top of the existing Internet

#133
post #132

Earlier quoted context omitted.

> I will consider myself to have won that round, not lost ;P. If fame and victory are what your company is going after, instead of taking care of your potential users, then I am sorry that you won't have my support. Btw, thank you for creating cydia if you were the author.

To "win" here means "win a battle on the road to an Internet free of surveillance". I (personally) firmly believe that if China were to do that, that the people would not stand for it; any form of "half solution" or "compromise position" where the Chinese govnerment can block just enough to remove access to material that bothers them while only minority inconveniencing users, is a world in which this form of freedom…

I think you might have misunderstood what I mean by "taking care of your potential users". It is not a short-term definition. On the contrary, I want a long-term solution, where users trust the platform that your company provides, trust that your company will be there for the users when Chinese government bans your software, instead of celebrating the ban as a success and call it a day (like what Google did).

To celebrate the banning of your platform would be what I call a short-term solution, because in the long run, it is merely a temporary attempt at solving the problem, that people will eventually forget when a long-term solution prevails. Chinese people, from all spectrum of political views alike, do not thank Google for exiting China, because it does not solve their problem. The act merely throws the problem into limbo state awaiting for other people to solve.

Also, I think you mixed up "support" and "gratitude". I thank you for creating Cydia as well as attempting to solve this problem with surveillance and censorship, as always. However, I disagree with your approach and therefore will not support this platform unless I can see that you have something bigger in mind beyond "celebrating being banned".

Re: Orchid: a new surveillance-free layer on top of the existing Internet

#134
post #113

Earlier quoted context omitted.

I'd really like to see a comparison to TOR. Because honestly, from randomly clicking through the website I don't see why you're better than TOR and why I should use ORCHID. I cannot (easily) find answers to pretty much every question I have, and sorry, I'm not going to read through a 50 page whitepaper before I decide if it's worth it. What is it, onion routing? There's some talk of ethereum, so presumably you can ge…

"I'm not going to read through a 50 page whitepaper before I decide if it's worth it." It sounds like this project is probably a little too early stage for you then? Maybe let people play with it for a couple if years and distill it down a bit. If it still exists maybe try again.

> It sounds like this project is probably a little too early stage for you then? > Maybe let people play with it for a couple if years and distill it down a bit. If it still exists maybe try again.

I don't have a problem reading a whitepaper. But there's approx. 12 billion new etherum startups a day. So I just think a little tl;dr would be nice to know if it's something I care about. Because right now I don't know if I should care early stage.

Re: Orchid: a new surveillance-free layer on top of the existing Internet

#135
post #127

Earlier quoted context omitted.

Here's the tl;dr: a practical encrypted mesh network that can work over the traditional internet protocol (IP) or over real-world links and radio antennas.

Since the parent was deleted and I couldn't comment by the time I finished typing, here's the non-tl;dr: The main advantage is non-hierarchical routing. Your ip address is in fact the fingerprint of your public key, which is used to encrypt all traffic. Because of this the address allocation works a lot different and there's no need for a central authority. The lack of a central authority is usually a problem if you…

That sounds like a good way to get very inefficient routing.

Supposed I have keypair A at a friend and keypair B for me, how is cjdns going to find the fastest route between me and my friend?

Re: Orchid: a new surveillance-free layer on top of the existing Internet

#136
Ok, I wasted a few hours reading the whitepaper. It was just as idiotic as you'd expect. Here are a few notes:

It seems like this takes Bitcoin and Ethereum electrical power waste to a whole new level

  To produce a medallion, a peer takes a public
  key K , and the most recent Ethereum block hash
  E , then (iteratively or in parallel) locates a
  salt S such that H ( K, E, S ) ≥ N ,  where N
  is some difficulty scaling factor.
And with all that "an anonymous" network does not provide payment anonymity (while amount paid correlated with amount of data sent). So this will disclose how much data each user put into the network. This is valuable if you can observe large amounts of data out of the exit nodes (like a government-scale actor might). This might even allow correlation between data and users.

  We will argue that The Orchid Payments
  (section 7.12) fulfill all but the
  anonymity requirement.
Yup... not anonymous at all...

  The pseudo-anonymity of Orchid payments
  is equivalent to what can be achieved in
  regular Ethereum transactions

But it gets better. While you can use anyone as a relay, you PREPAY them before they do any work for you. This is claimed to solve the problem of nonpayment, but nobody mentions the opposite problem: I take your money and do no work for you. The money cannot be taken back - I own it now. cool.

  If there is some setup cost to Alice and
  Bob’s relationship ( S Alice , S Bob s.t.
  S Alice > xy, S Bob > xy ), the answer is
  yes.
And for fun, it also messes with SSL. Allegedly only "for good", but who'll notice when this changes?

  (see the entire section 10 in whitepaper)
And then there is the completely not scalable method to prove you will route as required by the network. For that you need to literally get EVERY node on the network to sign off on the fact that you can route to them. So the size of this proof, its computational cost, and the time to complete it will grow as the network does. Total work done just to provide for network joining grows as N^2. Oh, and god help you in case of temporary partitions (like has happened in the internet a number of times when various underwater cables were cut). For extra fun, nobody mandates you actually do route anything. Only that you prove you can. I see nothing in there that prevents packets from being purposefully dropped after collecting payment for "forwarding" them.

  (see whitepaper section 11.5)
Oh, and if you thought this will provide INTERNET access, you are mistaken. Apparently HTTP w/ DNS only. As per whitepaper, exit nodes can filter based on domain. I am not even going to mention that running an exit node without a whitelist is idiotic (one user downloads CP, you go to jail). So everyone must have a whitelist? And just how big do you figure a typical "whitelist" of safe domains is? 100GB, 1000GB? Good thing you need to send it as a reply to Get Offers request.

  (see whitepaper section 11.9)
Blocking this is easy (as the whitepaper concedes) by DPI and blocking Ethereum. Whitepaper claims "this will be solved later" but offers not even a handwavy explanation of how this will happen while remaining compatible with mainline Ethereum clients...

  (see whitepaper sections 12.3 & 15.3)
Of course, besides handwaving on "it will totally be ok"(tm), there are no real world performance numbers.

  (see whitepaper section 13.3)



But funny most of all, these guys didn't address the simplest attack of all. Pretend to be an exit node, /dev/null the traffic, pocket the payment.

My guess: the scheme is simply to raise an ICO and laugh their way to the bank. (as always)

Re: Orchid: a new surveillance-free layer on top of the existing Internet

#137
post #131

What would convince my mom to use this though?

So, I don't know your mother, and can't say what kind of extreme technical needs she might have as part of her lifestyle or job; but, I guess I will presume you asked this question from the depressingly stereotypical perspective of "assuming peoples' mothers are not very technically skilled as they are older women, how would a mother use it" and answer your question anyway :(. So, she might not use the first version,…

So the reasons she might use it are:

* you install it on her computer

* it has a simple user interface

* it has a non-technical sounding name

Is that correct?

What if you reinterpret "my mother" to be "average internet user, in a country with average internet freedoms, who doesn't read HN etc"?

Re: Orchid: a new surveillance-free layer on top of the existing Internet

#138

This sounds like a good idea. One problem with things like tor and i2p is you want to have tons of traffic so as to hide things from the various spies, but it is hard to get enough people to support nodes. Add a token and perhaps that problem will be solved.

A token seems to solve the supply side (relay and exit nodes) but what about the demand side? Why would anyone who doesn't care about subverting censorship or surveillance pay for this?

Re: Orchid: a new surveillance-free layer on top of the existing Internet

#139

Ok, I wasted a few hours reading the whitepaper. It was just as idiotic as you'd expect. Here are a few notes: It seems like this takes Bitcoin and Ethereum electrical power waste to a whole new level To produce a medallion, a peer takes a public key K , and the most recent Ethereum block hash E , then (iteratively or in parallel) locates a salt S such that H ( K, E, S ) ≥ N , where N is some difficulty scaling facto…

(Note I'm David Salamon, one of the white paper authors.)

I agree with your payment analysis. As you point out, we explicitly disclose that payments need modification before they will be at the level of anonymity required for Orchid. Anonymous payments for the Ethereum platform are being worked on right now by very talented teams. As we don't believe we have anything substantial to add to that conversation, we are deferring to them, and will simply audit and adopt the methods they design as soon as doing so is feasible.

> And for fun, it also messes with SSL. Allegedly only "for good", but who'll notice when this changes?

This is a fully general argument. Even if we didn't check the validity of certificates (which many phone apps don't do but should, hence our adding the feature), couldn't you still claim we might act maliciously in the future without anyone noticing?

(As you don't point out, our software will be AGPL3 licensed / open source. If one person notices and says something, everyone will notice. This is the logic behind trusting Linux, OpenSSL, Tor, etc... Are you aware of a better solution? I'm skeptical one exists.)

> Total work done just to provide for network joining grows as N^2

No, connection proofs are O(routing_table_size * per_element_proof_length). Routing table size is O(log(n)) and per-element proof length is the routing tables of the point-to-point route taken O(log(n)^2), so the proof is O(log(n)^3) -- likely much less in practice, as the successor and predecessor nodes are very likely to share every connection that the joining node needs to make.

This is good feedback, we should explicitly do that calculation in the whitepaper, added to the TODO list. Thanks!

> Blocking this is easy (as the whitepaper concedes) by DPI and blocking Ethereum. Whitepaper claims "this will be solved later" but offers not even a handwavy explanation of ohw this will happen while remaining compatible with mainline Ethereum clients...

The data which needs to be received is already defined by Ethereum's gossip protocol, so in theory adding Ethereum proxy support would be trivial. (Just proxy Ethereum traffic the same as any other traffic.)

We have not specified that, however, because we are worried about the possibility of a malicious proxy hiding some transactions from a customer. Once we feel like we have a good handle on how to analyze these kinds of attacks, and have a solution which mitigates them, we will add a solution to the whitepaper. This is somewhat outside our core product, and so has suffered a bit of neglect. It might be as simple as just receiving gossip from multiple independently chosen Relays, but I'd like to be more sure before making that the official method.

> Of course, besides handwaving on "it will totally be ok"(tm), there are no real world performance numbers.

We felt that publishing real-world performance numbers would be best left until after there was a real-world system.

> But funny most of all, these guys didn't address the simplest attack of all. Pretend to be an exit node, /dev/null the traffic, pocket the payment.

We do in a way. If a proxy behaves this way, Chrome disconnects, resulting in the attacker not being paid beyond a couple of kilobytes. This is not profitable, but still annoying. So the attacker causes a widespread nuisance, spends most of their time waiting for new customers, and suffers the loss of their CPU to proof-of-work. It's not profitable, but I expect some users will still do it for the lulz.

> My guess: the scheme is simply to raise an ICO and laugh their way to the bank. (as always)

(Note I'm not a cofounder)

I joined in spite of not being able to negotiate myself to anywhere near cofounder levels of token ownership -- I would probably have made more by accepting a different job doing mobile A/B testing software company.

I do think some of the cofounders are very much in this for the money, but I also think every single person on this team hates what's happening on the web with respect to privacy and censorship. If that changes, I'll probably end up leaving and working on this separate from them. (Well, or demanding more money?)

So basically: if I don't quit you can conclude they've either paid me to keep quiet, or I still like them. Best I've got for you.

> Ok, I wasted a few hours reading the whitepaper. It was just as idiotic as you'd expect. Here are a few notes:

Thank you very much for your feedback, sorry you felt it wasn't worth the time. Maybe next draft? :p

Re: Orchid: a new surveillance-free layer on top of the existing Internet

#140
post #123

Earlier quoted context omitted.

[deleted]

Here's the tl;dr: a practical encrypted mesh network that can work over the traditional internet protocol (IP) or over real-world links and radio antennas.

Two questions about mesh networks:

1. at some point there will be an expensive hop across the ocean, or between cities, that will likely only be built once, then shared. Won't whoever owns that hop have similar centralized control of any non-local traffic, similar to an isp?

2. how meshy should mesh networks be? On one extreme, every computer can be directly connected to every other computer in the world. On the other, every computer can be connected to just one neighbor, and requests are routed through many hops. What is the prevailing wisdom on the optimal amount of peers nodes should have on average in a mesh network?

Post reply on HN