Bitmessage – Send messages without leaking metadata
bitmessage.org
Bitmessage – Send messages without leaking metadata
1–10 of 67 posts
Re: Bitmessage – Send messages without leaking metadata
#2Re: Bitmessage – Send messages without leaking metadata
#3Re: Bitmessage – Send messages without leaking metadata
#4According to the white paper, "all users receive all messages." How, then is the system scalable to a large network?
Re: Bitmessage – Send messages without leaking metadata
#5According to the white paper, "all users receive all messages." How, then is the system scalable to a large network?
The whitepaper proposes to handle this by having nodes join separate clusters once their databases reach a certain size.
The whitepaper describes a simple and focused system relying on partitioning in an attempt to preserve scalability.
Bitmessage has many architectural similarities to Usenet and also offers no valid response to spam. Using a proof-of-work system to combat spam is proposed, but to-date science has not yet seen a working approach anywhere. Details are missing on this vital element plus defenses against the Sybil attack are missing from this design.
Mechanisms such as the "averageProofOfWorkNonceTrialsPerByte" in this system only slow down attacks and do not stop them. Check the impossibility proof by Harvard to see that systems like Bitmessage which react to any message cannot build an effective Sybil defense: http://dash.harvard.edu/handle/1/4907301 So this is known as a hard unsolved problem. Further diving into the scalability issue is this project thread on their forum: https://bitmessage.org/forum/index.php?PHPSESSID=8cl6qeafitk... It would be great if the partitioning concept and algorithms could be explained in detail. It's again a hard problem, even group size estimation in a hostile environment is already non-trivial. So how group consensus is formed to do a break-up is difficult and prone to attacks. This design is not incentive compatible. TOR has over 50% Bittorrent traffic, it's difficult to stop users from using(abusing?) TOR like that. Systems like Bittorrent and Bitcoin have some incentives, but Bitmessage with broadcasts and proof-of-work might even have a negative incentive for participation. I have seen no mechanism to prevent it's users broadcasting Blueray rips. This would bring down the system, one cluster at a time. Please check this work, it shows how to bring this type of P2P networks down: www.christian-rossow.de/publications/p2pwned-ieee2013.pdf
Publicity like "Bitmessage Sends Secure, Encrypted, P2P Instant Messages" might be nice. It creates a false sense of safety. If you want to protect against NSA snooping, you're up against a real army of crypto experts with decades of experience each.
Nice to see that this project has such an active Github community, 480 closed issues and 1159 commits. But, in my opinion it's back to the drawing boards... Sorry.
Disclaimer: working for 8 years on Tribler, a streaming Bittorrent client.
Re: Bitmessage – Send messages without leaking metadata
#6Earlier quoted context omitted.
The whitepaper proposes to handle this by having nodes join separate clusters once their databases reach a certain size.
Please consider this a security review by a tenured P2P professor: The whitepaper describes a simple and focused system relying on partitioning in an attempt to preserve scalability. Bitmessage has many architectural similarities to Usenet and also offers no valid response to spam. Using a proof-of-work system to combat spam is proposed, but to-date science has not yet seen a working approach anywhere. Details are mi…
Re: Bitmessage – Send messages without leaking metadata
#7According to the white paper, "all users receive all messages." How, then is the system scalable to a large network?
The whitepaper proposes to handle this by having nodes join separate clusters once their databases reach a certain size.
Re: Bitmessage – Send messages without leaking metadata
#8Earlier quoted context omitted.
The whitepaper proposes to handle this by having nodes join separate clusters once their databases reach a certain size.
Please consider this a security review by a tenured P2P professor: The whitepaper describes a simple and focused system relying on partitioning in an attempt to preserve scalability. Bitmessage has many architectural similarities to Usenet and also offers no valid response to spam. Using a proof-of-work system to combat spam is proposed, but to-date science has not yet seen a working approach anywhere. Details are mi…
Re: Bitmessage – Send messages without leaking metadata
#9According to the white paper, "all users receive all messages." How, then is the system scalable to a large network?
Also they have some major security issues that I pointed out to them, but they simply ignored. I am sure bitmessage will never be a success because it is fundamentally broken.
Re: Bitmessage – Send messages without leaking metadata
#10This is one of my addresses, I feel lonely HN :-) BM-2cUHuH7sJdt3GchrqSikvzWP4w7Vm2cjhK (so much for not disclosing to the whole world, but this is just for fun)