Live data from Hacker News

ZeroNet – Uncensorable websites using Bitcoin crypto and BitTorrent network

zeronet.io

111–120 of 171 posts

Re: ZeroNet – Uncensorable websites using Bitcoin crypto and BitTorrent network

#111
post #57
post #38

Speaking of which, what's the progress on IPFS?

We're moving forward as always. Latest features would include distributed pubsub, filestore (allows you to add files without duplicating them) and interop between the browser and desktop nodes. Any specific part you're looking at?

1) What's the status of (supported as a real feature, not just manually changing the bootstrap nodes and hoping everyone else does too) private IPFS networks? If it's there already, how stable is its configuration (i.e. if I get my friends on a private IPFS network will I likely have to get them all to update a bunch of config in 6 months or a year)?

2) Does filestore also let you store, say, newly pinned files in your regular file tree? That is, can you pin a hash for a file (or tree) you don't already have and provide an ordinary file system location where it should go when it's downloaded? Or do you have to copy it out of IPFS' normal repo manually, then re-add it in the new location? Also: how does filestore behave if files are moved/deleted?

3) What rate of repo changes requiring upgrades can we expect for the future? That is, how stable is the current repo structure expected to be? Is the upgrade process expected to improve and/or become automated any time soon?

4) Is there a table of typical resource requirements somewhere? I'm looking for "if you want to host 10TB and a few 10s of thousands of files, you need a machine X GB of memory. If you want to host 500MB, you only need Y GB of memory. If you have 2TB but it's in many, many small files, you need Z GB of memory", or else a formula for a achieving a best-guess for that. For that matter, how predictable is that at this point?

The use case I've been excited to use IPFS for since I found out about it is a private, distributed filesystem for my friends and family. Easy automated distributed backups/integrity checking on multiple operating systems, access your files at someone else's house easily, that sort of thing. Filestore finally landed, which was a big piece of the puzzle (the files have to remain accessible to ordinary tools and programs or I'll never get buy-in from anyone else), so that's exciting. Now I'm just waiting for docs to improve (so I'm not searching through issue notes to learn which features exist and how to use them) and for a sense that it's stable enough that I won't be fixing brokenness on everyone's nodes several times a year.

Re: ZeroNet – Uncensorable websites using Bitcoin crypto and BitTorrent network

#112
post #58

Earlier quoted context omitted.

> At least IPFS is working hard towards Tor integration. That might be something one day. Actually, that day is today already! OpenBazaar had the same need of a Tor transport and made one! It's available here: https://github.com/OpenBazaar/go-onion-transport/ Basically a plug-and-play transport for IPFS.

I hope they get a chance to add a better README to that, looks interesting.

Yeah, it's not the most documented repository. In the absence of that, you can check out the following document and implementation for some better understanding:

- https://github.com/OpenBazaar/openbazaar-go/blob/4a9ee8de8fd...

- https://github.com/OpenBazaar/openbazaar-go/blob/4a9ee8de8fd...

Hope that helps a bit. Keep in mind that none of this have been verified and might not work as advertised. Just a warning.

Re: ZeroNet – Uncensorable websites using Bitcoin crypto and BitTorrent network

#113

Earlier quoted context omitted.

Wait, did they reveal how their exploit worked? I thought they had already dropped two cases rather than reveal the internals of the NIT? Like Tor Browser could still be unpatched for this?

Yes, they didn't reveal the Firefox bug or the details of NIT. And yes, Tor browser could still be vulnerable. You must isolate Tor process and userland in separate VMs, or even separate physical devices. Even if the browser gets pwned, and the NIT gets dropped, you'll be OK, because the Internet is reachable only through Tor. Whonix is an easy to use implementation. I've been ragging on Tor Project about this for ye…

If Tor is too difficult to use, people won't use it. Edward Snowden and Laura Poitras had to dedicate a significant amount of time to get Glenn Greenwald to just use TAILS, a plug and play Tor operating system. Someone like that is not going to use Whonix, even if maybe they should be.

Re: ZeroNet – Uncensorable websites using Bitcoin crypto and BitTorrent network

#114

Love the ZeroNet project! Been following them for a year and they've made great progress. One thing that's concerning is the use of Namecoin for registering domains. Little known fact: A single miner has close to 65% or more mining power on Namecoin. Reported in this USENIX ATC'16 paper: https://www.usenix.org/node/196209 . Due to this reason some other projects have stopped using Namecoin. I'm curious what the ZeroN…

Also, if you ever lose control of a namecoin domain you can say goodbye to it forever. A squatter will take it instantly and hold on to it forever unless you buy it from them for actual money.

Has squatting gotten worse on Namecoin? Squatting is fairly hard to handle in decentralized naming systems in general. Namecoin got a lot of squatting issues mostly because of the pricing function (price of names dropped over x years, and now it's almost free to register names). Here is another paper from WEIS'15 that studied squatting in Namecoin: http://randomwalker.info/publications/namespaces.pdf

Re: ZeroNet – Uncensorable websites using Bitcoin crypto and BitTorrent network

#115

Earlier quoted context omitted.

Yes, they didn't reveal the Firefox bug or the details of NIT. And yes, Tor browser could still be vulnerable. You must isolate Tor process and userland in separate VMs, or even separate physical devices. Even if the browser gets pwned, and the NIT gets dropped, you'll be OK, because the Internet is reachable only through Tor. Whonix is an easy to use implementation. I've been ragging on Tor Project about this for ye…

If Tor is too difficult to use, people won't use it. Edward Snowden and Laura Poitras had to dedicate a significant amount of time to get Glenn Greenwald to just use TAILS, a plug and play Tor operating system. Someone like that is not going to use Whonix, even if maybe they should be.

Yeah, I get that. And I realize that I've gone off the deep end. It's hard to imagine anymore how easily people's eyes glaze over. I've written guides that lay everything out, step by step. And many people still can't seem to get it.

But Whonix really is trivial. You install VirtualBox. You download the Whonix gateway and workstation appliances. You import them in VirtualBox. You start them. You work in the workstation VM. There's nothing to configure. That literally should be enough information to use Whonix. Plus there's a wiki and a support forum.

Re: ZeroNet – Uncensorable websites using Bitcoin crypto and BitTorrent network

#116
post #94

We need more projects like these. Whether this project solves the question of a truly distributed Internet* is out of question. What we need is a movement, a big cognitive investment towards solving the Big Brother problem. *I am referring to concentrated power of the big players here, country-wide firewalls, and bureaucracy towards how/what we use.

We need multiple internets, a big confusion, governments can't handle confusion, but if everything is standardized over Facebook and WhatsApp it's easy for them.

Re: ZeroNet – Uncensorable websites using Bitcoin crypto and BitTorrent network

#117
post #23

Has the code quality improved since I was told to screw off for bringing up security? * 2 years out of date gevent-websocket * Year old Python-RSA, which included some worrying security bugs in that time. [0](Vulnerable to side-channel attacks on decryption and signing.) * PyElliptic is both out of date, and actually an unmaintained library. But it's okay, it's just the OpenSSL library! * 2 years out of date Pybitcoi…

Well, it is better to concentrate on getting users in than to solve some small quirks.

Nobody is going to attack ZeroNet if it doesn't have users anyway.

Re: ZeroNet – Uncensorable websites using Bitcoin crypto and BitTorrent network

#118

I would recommend use of Freenet over ZeroNet. More or less the same concept/functionality however with 15 years more experience. Freenet: https://freenetproject.org/

Freenet is a great idea with 15 years of failure to get traction with sane (by which I mean non-paedophile) people.

Also, it's written in Java.

Re: ZeroNet – Uncensorable websites using Bitcoin crypto and BitTorrent network

#119

Earlier quoted context omitted.

Yes, for Whonix it's a VirtualBox internal network. There's no direct routing through the host, only among VMs. You can do much the same on VMware. Edit: I forget that I'm writing on HN. When I say VM, I'm referring to full OS-level VMs, not namespace, Java, etc VMs.

That sounds like a pretty neat setup. I know I can just google all this so please forgive me the inane questions; it depends on virtualbox though? That's a bit of a nonstarter for a few of. We probably aren't the target base for the project though so maybe it doesn't matter...

Yes, it depends on VirtualBox. But there are versions for KVM, and for Qubes. More of a nonstarter, though. Or even using physical devices, such as Raspberry or Banana Pi.

Years ago, I created a LiveDVD with VirtualBox plus Whonix gateway and workstation VMs. I had to hack at both Whonix VMs to reduce size and RAM requirements. But I got a LiveDVD that would run with 8GB RAM. It took maybe 20 minutes to boot, but was quite responsive.

Re: ZeroNet – Uncensorable websites using Bitcoin crypto and BitTorrent network

#120
post #68
post #50

Earlier quoted context omitted.

It's not supported by ZeroNet.

You sure about that? Their presentation [says][1] "Tracker-less peer exchange is also supported". Any idea what that's referring to? [1]: https://docs.google.com/presentation/d/1_2qK1IuOKJ51pgBvllZ9...

That one peer can send their peers. It's called peer exchange.
Post reply on HN