Vuvuzela: private messaging system that protects metadata
vuvuzela.io
vuvuzela.io
I'm interested to learn more about these servers. Can anyone host one? How are they discovered/networked? Personally I'm still more inclined to stick with Ricochet.IM since it piggybacks Tor so there are already tons of servers out there.
Ricochet works by essentially starting up a Tor Hidden Service and then listening for messages from other users, so there's no exposure to browser-based attacks. It's end-to-end encrypted and less susceptible to traffic analysis attacks because it never hits an exit node.
For those who didn't watch the 2010 world cup, or have blocked out the memory: https://www.youtube.com/watch?v=bKCIFXqhLzo
I imagine this would work better for Matrix due to its federated nature than it would for Signal.
The sub-2 seconds latency doesn't seem that bad, if it actually offers strong anonymity at that level. I would've thought it would be more like 15-20 seconds, which would probably be useless for all but the actively under attack targets.
Also, previous discussion: https://news.ycombinator.com/item?id=10668494
Their server is throwing a 500 error
Those servers need to independently operated and resistant to global compromise.
We don't really have a good template for a system like this. We have centralized HA systems and decentralized high churn systems like Bittorrent and Tor.
I've been intrigued by the observation that forthcoming "proof of stake" blockchain systems have very similar requirements in terms of availability and capacity to anonymous messaging systems. I wonder if we can use the nodes in a PoS system to bootstrap an anonymity system like Vuvuzela.
Diverse, hardened OS's & CPU's too. Verified protocol stack. The usual.
As to the proof of stake algorithms - the efforts to do it in a strict way all fail - I have a feeling that it might be impossible.
Sounds like the distributed trust system Apache Milagro (incubating). http://milagro.incubator.apache.org/
I've been working on a follow-up system called Alpenhorn that addresses the bootstrapping problem in Vuvuzela: https://vuvuzela.io/alpenhorn-extended.pdf
I will release Alpenhorn and a new version of Vuvuzela in January.
Typically bootstrapping a list of a few thousand nodes with top uptime is a good starting point, then using peer exchange between the nodes to find more, store them and prefer them when possible. Bittorrent DHT could also be (ab)used as a discovery mechanism.
Yes, an ISP who's willing to block a few thousand nodes will be able to take your shit down no matter what. That's why Tor uses private "bridge" servers for people in highly censored countries and tries to mask traffic as some other type. There's no way around that. But that doesn't mean decentralization is useless - it's incredibly useful in most countries and with most ISPs.
If you need to scan IPv4 space randomly to find a node, you can easily find all nodes. This takes about a day or two on a cheap VPS.
The idea with projects such as Vuvuzela is to make metadata less usable.
if ( days between acct creation and last check-in > N Days ): archive record; rm prod record;
There may be less identifiable means for these boring operations though. Just the first thing that popped into my head.
Here's the GitHub page: https://github.com/vuvuzela/vuvuzela
I'm trying to imagine how I would hide that I downloaded an app on a phone using the appstore (unless you want this to end up like PGP, which is used by the crypto community and no one else because of the perceived complications vis-a-vis implementation.)
In my understanding, the set of all communiqués between every user and the Vuvuzela network approaches pseudorandom noise, among which the actual conversations are hidden.
If you transmit something that looks like noise, and no one else sends something that looks like that particular kind of noise, then you are raising a flag that says "No, really, please, capture this data, it's interesting."
Message length, relative timing, average bandwidth, ports used, source/destination addresses, activity punch-card.
I'd assume that this kind of traffic is identifiable to within near perfect certainty, which would also make it easy to block.
The situation is a bit similar to early crypto-analysis: it's totally easy to devise a cipher that makes text look random to the eye, but is still easily cracked using statistics (eg. frequency method). Just because traffic patterns look all complex and random doesn't mean that there is a meaningful amount of entropy in it (but you need a lot of entropy to hide all the metadata - who with whom and when). Just because bandwidth or packet frequency looks independent of user activity it doesn't mean that it actually is.