Live data from Hacker News

A Botnet Accidentally Destroyed I2P

sambent.com

91–100 of 101 posts

Re: A Botnet Accidentally Destroyed I2P

#91
> The operators admitted on Discord they accidentally disrupted I2P while attempting to use the network as backup command-and-control infrastructure ...

This is crazy to me. Discord is letting literal criminals use it's corporate services in full view to commit crimes?

Re: A Botnet Accidentally Destroyed I2P

#92

This article (with high slop vibes) and another article on their site (linked in the comments) seem to suggest that post quantum encryption mitigated the Sybil attack, without explanation. I fail to understand how the two are even related.

Came here to say this. Seems like the attack was an accident and it ended. Nothing was mitigated

Re: A Botnet Accidentally Destroyed I2P

#93
post #62
post #59

Earlier quoted context omitted.

While anyone can run a Tor node and register it as available, the tags that Tor relays get assigned and the list of relays is controlled by 9 consensus servers[1] that are run by different members the Tor project (in different countries). They can thus easily block nodes. [1]: https://consensus-health.torproject.org/

It's 10, not 9. And there are severe problems with having a total of 10 DA be the essential source of truth for whole network. It would be trivial to DDoS the DAs and bring down the Tor network or at the very least, disrupt it: https://arxiv.org/abs/2509.10755 . It's the only complaint I have of the current state of Tor. Anyone should be able to run directory authority, regardless if you trust the operator or not (sa…

Couldn't you

A: Run your own network that trusts the existing plus whatever nodes you think ought to be and convince everyone that this is better if it is

B: Run a node and convince others to trust yours so that eventually there is 11 then 12 and so forth?

Re: A Botnet Accidentally Destroyed I2P

#95
Also rewriting i2pd in Go would be the sanest step. From Java to Go is not a big challenge and you gain even more portability. Just look at Yggdrasil on how these people created meshnets running even under Android and cheap i386 netbooks.

Thus, something like this in Go should be the norm. The GC it's ideal for this, it comes with batteries charged for networking and it can be for sure be made compatible with stuff like NNCP like nothing.

It wouldn't run many times slower than i2pd in C++, it should be perfectly bearable.

Re: A Botnet Accidentally Destroyed I2P

#96
post #19

Earlier quoted context omitted.

This answer is missing the key "regularity" part of their questions, which I would love to know more about.

That’s a great question… Currently we’re in the main Chinese holiday period with the Lunar New Year/Spring Festival/Chinese New Year, so perhaps people traveling back home from foreign lands might use the service more during this time?

I know no one using this in China. And people who can afford to travel (and have visa and passport) will have foreign sim/phone. The timing is just a coincidence

Re: A Botnet Accidentally Destroyed I2P

#97
post #4

From the main article, I2P has 55,000 computers, the botnet tried to add 700,000 infected routers to I2P to use it as a backup command-and-control system. https://news.ycombinator.com/item?id=46976825 This, predictably, broke I2P.

I guess "predictably" is valid but what actually went wrong? After going through multiple sources I can't tell if the botnet nodes were breaking the protocol on purpose, breaking the protocol on accident, or correct implementations that nevertheless overwhelmed something.

As I understand they weren't building tunnels, so every time a legit client wanted to it has to wade through all the bad nodes to find a good one, so everything slowed right down. I was building at about 3% success rate during the issue which enables general eepsite browsing but torrenting was essentially dead

Re: A Botnet Accidentally Destroyed I2P

#98
post #59

Earlier quoted context omitted.

> so that they can take action like cutting out malicious nodes if needed How does that work?

While anyone can run a Tor node and register it as available, the tags that Tor relays get assigned and the list of relays is controlled by 9 consensus servers[1] that are run by different members the Tor project (in different countries). They can thus easily block nodes. [1]: https://consensus-health.torproject.org/

Interesting, thank you so much! Yeah, if those 9 really are independent entities, I’d say I don’t see many issues here.

Re: A Botnet Accidentally Destroyed I2P

#99

This article (with high slop vibes) and another article on their site (linked in the comments) seem to suggest that post quantum encryption mitigated the Sybil attack, without explanation. I fail to understand how the two are even related.

Definitely generated, testing a ML model I'm training. it flags as claude mostly.

Re: A Botnet Accidentally Destroyed I2P

#100
post #87

Earlier quoted context omitted.

So? At least the reporting used to be mostly accurate and trustworthy. Here we can see that Krebs is now willing to publish stories he hasn’t even attempted to verify

[flagged]

Please don't post insinuations about astroturfing, shilling, brigading, foreign agents, and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinator.com and we'll look at the data.

https://news.ycombinator.com/newsguidelines.html

Post reply on HN