Live data from Hacker News

VPN⁰: A Privacy-Preserving Distributed VPN

brave.com

121–130 of 142 posts

Re: VPN⁰: A Privacy-Preserving Distributed VPN

#121

Earlier quoted context omitted.

With other browsers, the clear and obvious incentive is "to get paid to spy on users". I'm not a big Brave fan but saying their incentives are worse than Chrome or even Firefox is ridiculous.

Have you ever heard of open source browsers like ungoogled chromium or pale moon? They have no incentives and are far better than brave’s, who wants to sell you advertising.

If only it were possible to have no incentives.

Re: VPN⁰: A Privacy-Preserving Distributed VPN

#122

Earlier quoted context omitted.

Given that IP address, user agent, fonts, screen dimensions, and a few other data points easily found via JavaScript can create a fingerprint [0], isn't a bit disingenuous to suggest any browser can truly block tracking, especially if JavaScript is enabled? I could use cURL to perform all web browsing, but my IP Address + User Agent could still be tracked by the website I visit. With time, what seems to be occurring…

To extend your comment; Even your mouse movements can be used to form an identity of you. Not only that, your mouse movements even correlate to demographic information about you (eg age/gender/etc) . With that said, I think you're correct in that it'll be a game of cat and mouse, but I'm not sure what the alternative is. Are you implying that there is anything that can be done beyond the traditional cat and mouse? Be…

Browsers need to rethink what is available via JavaScript. Scroll position, cursor location, etc. should not be readable. CSS Media queries for building responsive should still be fine to write, but the JavaScript API should be silent as to what styles are actually applied (to prevent workarounds for say, inferring the screen height/width from media query styles).

If we go back to basics, where I can make a network request, and the body includes a useful response (e.g., no need for running JS to populate the DOM, as is the case with SPAs that aren't server-side rendered), we can free ourselves from those more advanced heuristics.

It will likely always be cat-and-mouse, but we can rethink the universe of data available within the browser (that can be reported back via XHR requests), and make that universe much smaller.

Re: VPN⁰: A Privacy-Preserving Distributed VPN

#124

Earlier quoted context omitted.

Have you ever heard of open source browsers like ungoogled chromium or pale moon? They have no incentives and are far better than brave’s, who wants to sell you advertising.

If only it were possible to have no incentives.

Okay, not no incentives, but incentives that match up with our own. I doubt the maintainers of ungoogled chromium have a secret agenda to take over the browser market. Their incentive is that they dislike google and they want a good browser without google spying on them.

Re: VPN⁰: A Privacy-Preserving Distributed VPN

#125

I refuse to use a browser with a cryptocurrency attached to it. It feels like the only reason it is being pushed so hard is so BAT holders can make a buck. It might be a great browser but I will always think of it as onecoin with a some chrome tossed in.

> I refuse to use a browser with a cryptocurrency attached to it.

The optional rewards program that happens to use a distributed ledger for settlement?

Lets see how that sounds when it is rephrased

“I refuse to use an airline with a rewards program attached to it”

“I refuse to use a credit card with a rewards program attached to it”

But since nobody says that, you lose your mind when a blockchain based one is used? Which is also as entirely optional as the above programs? Which you use as an ad hominem attack to add non-sequiturs to any contribution under the “Brave” brand such as this ZK VPN system which doesn't even use the digital currency? Fascinating, lets revisit this “taboo” next year to see!

Re: VPN⁰: A Privacy-Preserving Distributed VPN

#126
post #112
post #48

Earlier quoted context omitted.

Me too, think. What about sharing it as an internal non-exit VPN in a nested chain?

Can you elaborate? Not sure what an internal non-exit VPN nested chain is... although I some vague idea on what that may constitute to be.

In this diagram, VPN1 is what I'm calling the "internal non-exit VPN": https://keybase.pub/mirimir/VBox-Two-VPNs.png

It's not as much "non-exit" as Tor middle relays. Because it just connects to the VPN2 server using OpenVPN over standard TCP/IP. Instead of some proprietary protocol. But at least it's locked down with pf rules, so that it can only connect to the VPN2 server.

The diagram shows a nested chain with just two VPNs. But you can add more layers. As I recall, as many as six or so. Latency goes up, and MTU goes down. But throughput doesn't crash as much as you might think. I don't know why. But maybe it's caching.

So basically, you have a NAT chain locally in VirtualBox or whatever. And each NAT router includes a remote VPN server.

In order to share it, you'd need to open a port for incoming OpenVPN connections. Either locally, or forwarded to one or more VPN servers. And then you could route traffic through another VPN server in the chain.

Re: VPN⁰: A Privacy-Preserving Distributed VPN

#127

Earlier quoted context omitted.

If it's not a currency, what value does it have to the holder? It should also be noted that the law determines what qualifies as a currency, not the issuer. If it looks like a duck, quacks like a duck - you know the rest.

Utility tokens are, like arcade game tokens or food and drink tickets at a fair, valuable for their use with a particular venue or service -- not for their exchange value. Generally, the law does not recognise these kinds of things as currency.

I'm reminded of Itchy and Scratchy Money, themselves a parody of Disney Dollars: https://www.youtube.com/watch?v=dErRj6V8_xQ

I'm not sure why Brave thinks the public will seriously value these.

Re: VPN⁰: A Privacy-Preserving Distributed VPN

#128

Earlier quoted context omitted.

Exactly. I am a big hater of everything that even remotely feels like a shitcoin. BAT is a silly useless project; I would not hate it if there was no conflict of interests, even if it's a silly project; but there is a huge conflict of interest - the developers want to make money out of thin air by issuing their tokens. I already wrote this before in another comment. Basic Attention Token is not a secure cryptographic…

There seems to be some confusion here; users aren't paid for watching ads in Brave. When an ad notification has been delivered, the user is paid. There's a subtle difference there. Brave (because it is the browser) is able to determine when an ad has been displayed, better than any JavaScript-based client that exists today on the Web. Presently, ads are only shown as desktop notifications (no publisher ads at this ti…

I'm not willing to really try to prove that BAT embedded in Brave is a fundamentally flawed project. Because there are so many project of this kind in the current blockchain industry that I dislike very much, that I don't have enough time and motivation to dispute every such project. People who see what kind of clownade current blockchain industry is, will see it on their own. Those who don't think so, I don't want to convince (I tried before a lot, but marketing of big "blockchain" projects overpowers any words of a couple of geeks).

1. The power of blockchain is in its cryptographic strength. Without cryptographic strength a blockchain is worthless. Strength of a system is defined by the weakest link. The weak link of Brave + BAT is in inability to mathematically prove an ad view. Neither there is a known way to cryptographically mine coins by viewing ads. This means, there are no cryptographically secure methods to pay for ads. What you made is a program that displays an ad and ask your server to send coins to the user. Of course, this can be spoofed. Hackers can reverse engineer how Brave communicates with your backend and spoof it. There is no cryptographic way to prove that an ad has been shown. Hackers can make the windows with ads invisible etc, and still receive reward. And I'm sure they are doing it, but as long as spoofing rates are within your business model, you don't mind because everyone is making money and you don't want to ruin the party.

2. I'm not a proponent of Bitcoin particularly. I dislike everyone who creates a new coin for a fake reason, for something that doesn't need a new coin and issues a trillion tokens. I am for progress, and I don't mind when a new really innovative coins appears with a separate blockchain, but I hate when a new coin is created just to issue a trillion of tokens, give it away for free, and in this way giving it perceivable value. It at least must be mined, and some resources (electricity and hardware) must be spent to back up its value; a trillion token issued out of nothing don't have value. I would not care if it was just a silly useless project, which GitHub is full of, but there is an irresistible temptation to create a heap of tokens, keep a little bit, give the rest away, apply some sleazy marketing and make people believe that there is some value behind the tokens. A decent project must avoid at all cost creation of a new token without a reason that absolutely requires a new token, and instead use an existing token that has value behind it (resources are being spent on creation of that heap of digital money).

I always liked blockchain, I will always like it. I use Monero much. But the current blockchain industry is full of projects that are fake blockchains, centralized blockchains and especially systems where a blockchain and a product cannot be cryptographically linked. Such as reselling electricity through blockchain, track fruits from a farm to a shop through blockchain etc. I only don't understand if people pretend that they don't see this because everyone has a share in the growing industry, or they are really so stupid that they don't see the fundamental problem.

Re: VPN⁰: A Privacy-Preserving Distributed VPN

#129
post #84

Earlier quoted context omitted.

It’s not really one or the other. Firefox and Safari both exist and the incentives of the companies that run them are reasonably aligned with user privacy.

Our CEO co-founded Mozilla and Firefox. There is still a problem of invasive tracking and surveillance capitalism on the Web, and neither or these are hit as hard in Safari and Firefox as they are in a default install of Brave. The BAT component is off-by-default in Brave. Only enabled when the user explicitly opts-in to the feature. This is a necessary component, as blocking-alone is not a solution to the sustainabi…

your ceo? the same guy who was kicked out of mozilla?

Re: VPN⁰: A Privacy-Preserving Distributed VPN

#130

One step further that Ive prototyped is Encrypted and Distributed Search. The VPN relays willing to take the traffic can also double as Web crawlers. The vpn clients encrypt their search terms and vpn relays encrypt their search indexes, and perform ElGamal Homomorphic private set intersection with MINHASH in Elliptic Curve Field. This leads to better then key word, worse then current age context search from google b…

To make this type of search higher precision&recall you would have to focus especially on the indexing part (e.g. improve NLU of concepts in the pages), right? The training of such ML models could be federated across the nodes in a private way.

Indexing is important for sure. The problem is to preserve privacy and not falling back to heavy weight general purpose Multi-party computation we have to give up a bit on the precision and recall of modern search engines. Minhash, more specifically Locality Sensitive Hashing (LSH) is a good first approximation (Better then Term Freqency, worse them ML based search). Right now much of the web is unqueryable, my first goal was to allow the deep web and TOR services to be searched even at just a rudimentary level.
Post reply on HN