Live data from Hacker News

I2P: End-to-end encrypted and anonymous internet

github.com

101–110 of 124 posts

Re: I2P: End-to-end encrypted and anonymous internet

#101
post #77
post #72

Earlier quoted context omitted.

> it worked so badly. Skype has a much worse quality now after the switch for all people I know who used Skype at the time. The real reason for switching was iPhone. First, Apple did not allow long-running apps in favour of centralized notifications. Periodically start Skype to check events did not help recwicing calls. Second, users moved to smartphones, which depleted the active nodes network. So there has been an…

Microsoft buying Skype must have added additional incentives to centralize. Regulatory, organizational control, auditing, etc. And tinfoil take would include surveiling.

Skype was P2P pre-acquisition.

Microsoft’s acquisition changed Skype to centralize it through their servers (and introduce all sorts of call quality issues).

It’s less about focusing on tinfoil and more about how creating $ for cloud usage allowed for centralization and surveillance.

Skype has been enough of a turn off from the performance issues it has / had hat many people moved elsewhere.

Re: I2P: End-to-end encrypted and anonymous internet

#102
post #66

Earlier quoted context omitted.

Not often a network protocol / communication thread breaks out Neat point. I wonder if the percentage of bandwidth shared could be relative to the speed or openness of network available?

I think it would be exactly like that, because that's how it already works for relays. The Tor Project operates a measurement system that tests relays in various ways and records their status in the public consensus document. Clients then use weighted random selection (along with some screening criteria) to choose relays in proportion to how much bandwidth they provide, according to the consensus.

Having something like that turned on by default but being able to disable it would be a good choice.

Ultimately until someone can satisfy a user’s concern about the privacy and security of what flows through their connection there will be scrutiny on this piece. Being able to interject one’s own proxy or vpn tunnel could be interesting.

Re: I2P: End-to-end encrypted and anonymous internet

#103

Earlier quoted context omitted.

That inclusion statement seems very badly thought out and quite Western-centric. For many people in oppressive states who rely on censorship-resistant and privacy-guaranteeing software, being a dissident isn’t necessarily about defending minorities or trying to make the world a better place. It’s often about retreating into a private world with your fellows and trying to live your life as best you can under the circu…

I disagree, because I think in the definition of the word dissident it's not enough to oppose a system mentally. It needs to be challenged actively. What you describe sounds more like what I would describe as society dropouts

In English, "dissident" has been commonly used for decades to describe opponents of a regime (usually the USSR or other Eastern Bloc regimes) whose activity has been limited to distributing underground literature, or organizing cultural events in the private sphere instead of in the state-controlled venues. Only a small minority of dissidents publicly challenged the regime.

Re: I2P: End-to-end encrypted and anonymous internet

#104
post #93

Earlier quoted context omitted.

We will still need VPNs to get good connectivity to other residential ISPs until some government entity (or market condition) inspires ISPs to invest in more hardware and peering with each other. CDNs and VPN providers are now sadly a requirement for the internet to work the way we expect it to.

How do VPNs improve connectivity between residential ISPs?

Not OP, but I'd expect it's so that separate residential locations can communicate directly with another, bypassing limitations imposed by the ISP, double NAT, dynamic IPs, etc. Depending on region ISPs have purposefully blocked residential users from exposing public Internet services.

Re: I2P: End-to-end encrypted and anonymous internet

#105
post #77
post #72

Earlier quoted context omitted.

> it worked so badly. Skype has a much worse quality now after the switch for all people I know who used Skype at the time. The real reason for switching was iPhone. First, Apple did not allow long-running apps in favour of centralized notifications. Periodically start Skype to check events did not help recwicing calls. Second, users moved to smartphones, which depleted the active nodes network. So there has been an…

Microsoft buying Skype must have added additional incentives to centralize. Regulatory, organizational control, auditing, etc. And tinfoil take would include surveiling.

In the early 2000s there was a lot of discussion about a US law that required phone providers to provide for wiretapping, with no mention of the underlying tech. Being P2P, that wouldn't work for Skype, so a journalist asked the Skype CEO whether they would comply with the law and he said "We're not US company. Why would we?"

So I don't think it's all that tinfoily to think that once Skype became a US company, the government might have pressured them into making wiretaps possible, since there was a specific law that arguably required it. Considering all that Snowden revealed later, I'm not sure I'd put any digital surveillance in the tinfoil category.

Re: I2P: End-to-end encrypted and anonymous internet

#106
post #3

I really like I2P as a project, and I think it gets a lot of things right. For example having every network participant relay some internal traffic, instead of relying on altruism from relay operators, makes it much harder for a single entity to control enough hops to deanonymize users. Sadly, outside of torrenting I2P doesn't seem to have much traction, losing out to the better funded tor project

One of the reasons people were wary of Freenet, where every user would participate in the hosting, was that if the encryption algorithm was ever broken, people would undoubtedly be revealed to have been passing CSAM along. Unwittingly, but still. Does I2P’s model not spark the same concerns?

There is a big difference between storing CSAM (Freenet) and transiently transferring it (I2P).

Re: I2P: End-to-end encrypted and anonymous internet

#107
post #102

Earlier quoted context omitted.

I think it would be exactly like that, because that's how it already works for relays. The Tor Project operates a measurement system that tests relays in various ways and records their status in the public consensus document. Clients then use weighted random selection (along with some screening criteria) to choose relays in proportion to how much bandwidth they provide, according to the consensus.

Having something like that turned on by default but being able to disable it would be a good choice. Ultimately until someone can satisfy a user’s concern about the privacy and security of what flows through their connection there will be scrutiny on this piece. Being able to interject one’s own proxy or vpn tunnel could be interesting.

Right, I think that it could be good. But it's not obvious that it would be good while it would definitely add complexity, bugs, and attack surface, and discourage at least some people from using Tor.

> Being able to interject one’s own proxy... could be interesting.

I think this is essentially what the Tor Project wants to see instead: if you're in a position to do so, operate your own relay and make it your entry guard. That adds capacity for the network and helps you by mitigating the risk of connecting to a malicious guard.

Re: I2P: End-to-end encrypted and anonymous internet

#108
post #29

Earlier quoted context omitted.

I remember I2p torrents being horrendously slow, like 20kbps at max(do you even remember the last time someone used kbps as units?) for popular stuff. Has that changed in the last few years?

I get on the regular up to 200-500kbps depending on number of peers, and their router configuration (I have my bandwidth configured above the defaults, which are very low). I understand that is unheard of from someone living in the "instant access era" but their protocol has a cost.

Hm. Regular torrents tend to touch the 100 Mbps to gpbs range - so not really an alternative?

Re: I2P: End-to-end encrypted and anonymous internet

#109

Earlier quoted context omitted.

With modern tech I should never have any identifier that doesn’t change whatsoever. Mac,ip,etc should randomize every nth second lol

It's already possible (and quite easy) to assign a static IPv6 for incoming traffic e.g. webserver, then configure a private and constantly rotating IPv6 for all outgoing traffic.

Can you share a link, please?

Re: I2P: End-to-end encrypted and anonymous internet

#110
post #76

Earlier quoted context omitted.

> gets a lot of things right... having every network participant relay some internal traffic There are trade-offs. The Tor Project has its reasons for not doing this (from https://support.torproject.org/alternate-designs/ ): "...many Tor users cannot be good relays — for example, some Tor clients operate from behind restrictive firewalls, connect via modem, or otherwise aren't in a position where they can relay traff…

Doesn’t that make i2p less vulnerable to an issue tor suffers from - that of hostile-owned relays and exit points? I remember reading something about how a large part of them were controlled by US intel.

That was the parent comment's point. My point is that there are trade-offs. You make the network less vulnerable to that particular attack, and open up other vulnerabilities instead. Anonymous communication service design is full of such trade-offs.

There's a theory that intelligence agencies control many relays. I've haven't seen evidence of it. Tor does its best to be secure even when it can't trust the relays.

Post reply on HN