Anyway, I'm very interested in knowing if the used crypto is sound or not, and stirring a discussion around possible alternative approaches.
Ask me anything if you want to know further!
Anyway, I'm very interested in knowing if the used crypto is sound or not, and stirring a discussion around possible alternative approaches.
Ask me anything if you want to know further!
The situation is very similar to password storage, where you want to not make it trivial to brute-force moderate-entropy passwords even if your database gets breached. We have functions designed specifically for that: scrypt, argon2 etc. https://www.npmjs.com/package/scryptsy is a pure JS implementation of scrypt for example.
Even with scrypt the situation is not great, but using sha for this kind of thing is no longer state of the art. If people are willing to (a) download and run a program rather than rely on the browser and (b) willing to wait half a minute or so for the result then you could easily tune the scrypt/argon parameters up to 11 but at the cost of quite a bit in the way of usability. If "must work on smartphones without extra app downloads" is a requirement you're pretty limited in what you can do this way.
Another solution might be to use real servers but host them on the "dark web" - get Tor a bit of publicity in Catalunya!
EDIT: in response to a few posts that briefly appeared and then disappeared again - IPFS is fine. SHA256 for authenticating a page is fine. I'm only objecting to using raw SHA-anything as a key derivation function as in the section "A static database".
Only for SHA-1 (which has 160 bit hashes) https://en.wikipedia.org/wiki/SHA-1#Attacks
"it can be used to “fill the gaps” of information about any citizen. If you know someone’s birth date and the area where they live, you can obtain their government ID by trial-and-error on that website."
The mitigation is slowing down the number of guesses/second that an attacker can try. In a well-designed key derivation function, an attacker with 100x the resources should only be able to try out guesses 100x as fast. That's what scrypt/argon2/bcrypt/PBKDF2/... try and achieve.
SHA and other general-purpose hash functions tend to be easy to parallelize, at least in parts, and you can get huge speedups on GPUs or even better, FPGAs/ASICs. That's why no-one serious still mines bitcoins on CPUs and the big mining syndicates [hire planes](http://uk.businessinsider.com/cryptocurrency-miners-rent-boe...) to ship GPUs a little bit faster.
This has nothing to do with collisions. It's to do with hash functions being designed to be fast, and key derivation functions are designed to be slow and memory-hard.
Jeasus!! Gibson was far more prescient than acknowledged;
"the future is already here, but not evenly distributed yet"
Wow...
I had such opportunity and ability to buy bitcoins in 2012... and I missed that boat.
That quote also isn’t from Gibson. :)
You also have opportunity and ability to buy bitcoins now. And, just like in 2012, you have no idea what the price will be five years into the future.
And, they probably should’ve used HMAC-SHA2 to derive the public primary index key insead of a hash function directly.
If anyone wants the scripts I used to build up the system, let me know. Here's the Kubernetes YAML I used: https://gist.github.com/kordless/5625ae8abf3d3f14dd3f9c9d500...
I live in Catalunya and wrote this tool for doing just that, in a easy way. It 1) starts a go-ipfs daemon locally, 2) opens up the referendum website in your default browser, via localhost.
If you're interested in accessing the website from inside Catalunya, give it a try: https://git.io/vdGUx
I am not familiar with IPFS internals, but is there no pattern to the IPFS traffic that the ISPs can shape/block?
Too bad about the entire IPFS domain being blocked, because besides the host, HTTPS traffic has safety in numbers. If only there was a way to proxy through google.com or some other popular domain too important to block.
Host IPFS nodes with http proxies on GCP and point the domain with multiple A records at those instances?
The magic term for others to google is "domain fronting". Here is a bit more info:
http://www.geektime.com/2016/12/23/signal-updates-protect-th...
There is. Domain fronting is used in China to circumvent the Great Firewall. The concept you are talking about is collateral freedom.
Fun fact: advanced networking setups like domain fronting are impossible to address in a URL/URI scheme. Check out multiaddr :) [3] A domain-fronted service could be addressed as something like `/dns4/google.com/tcp/443/tls/sni/google.com/http/example.com/ws`
[1] https://signal.org/blog/doodles-stickers-censorship/
go get github.com/whyrusleeping/gx
go get github.com/whyrusleeping/gx-go
cd your-project/
gx install
go build // or whatever you were doing :)(I would rather GB stayed in one piece but if push came to shove, I'd probably do the same here in similar circumstances - there is no excuse for this heavy handed nonsense)
For example, secession (not to mention sedition or treason) is illegal in many jurisdictions, and is a natural thing for sovereign countries to want to prevent. It is also natural for the sovereign central government of a country to put limits on what a regional government can and cannot do, with the usual principle being that the regional government cannot do anything outside of the powers specifically given it by the central government (regardless of what powers the inhabitants of that region want).
You're right that "people" could "get together and conduct a poll on something", but if this was informally conducted it would be hard to prevent double voting, and not accidentally disenfranchising certain people, and there would be little recourse against these self-appointed pollsters stuffing their home-made ballot boxes.
At the same time, if a regional government spent money, or used people's personal information, for a purpose they were not legally permitted to, then those would potentially be crimes themselves, regardless of the issue of secession.
The questions worth debating are "How much autonomy should regions of sovereign countries be given?", and "If a region isn't legally given that much autonomy, what is most peaceful and just means for that region to attain it?"
As far as I can tell, Spain is going to great lengths to curtail the rights of citizens to express their opinions on secession. They're free to ignore the outcome of this vote, but raiding ISPs, shutting down political pamphlets, and reading private mail are not the actions of a democratic country—they're tactics straight out of an authoritarian regime.
Secession is also illegal in the US (and we fought a war to prove it), but you don't see federal agents arresting people for starting ballot initiatives in California or shutting down Vermont secession websites.
Texas has had secessionist movements also for some time, but it'd be also illegal to do a binding referendum, and Washington would take the required steps to stop it.
https://www.texastribune.org/2016/06/24/can-texas-legally-se...
There's a set of them on the pinning service I run (https://www.eternum.io/ipns/QmZxWEBJBVkGDGaKdYPQUXX4KC5TCWbv...), so they're in no danger of disappearing, but you'd help in case Spain banned the eternum.io node.
What exactly does this mean?
Do you mean by accessing this address:
https://ipfs.io/ipns/QmZxWEBJBVkGDGaKdYPQUXX4KC5TCWbvuR4iYZr...
So far it seems it is delivering on its promise: I was able to find my voting station. Too bad I am a continent and and ocean away from home :(
How does the hash of the main page guarantee that content linked from that page is authentic?
It seems weird that the sensitive part (ID number + birth date + post code) would be encrypted the most weakly, and the public part (voting station) would be encrypted the most strongly. Maybe I'm reading this wrong or the code author involuntarily made his encryption quite weaker.
The only information you would get by knowing some of that data is where somebody is supposed to vote. An information you can already infer from the Zip code. There are, at most, four possible voting sites for each zip code. In some (several) small/medium villages there is only one voting site, so, not to much to learn from decrypting.
Besides, the census (voting places) information is usually (in normal elections), placed (via paper printed listings) on voting places. And there there is more information (full name, for example).
Also how are they distributing the initial hash - physical signs? I figure the easiest threat from Spain is to get people to show up to the wrong polling stations, which don't have them on the voter rolls, and then cast doubts on the validity of a referendum that has a huge number of provisional ballots. Since you don't actually need to staff polling stations, this attack only really requires a single person setting up a cloned website and distributing a different hash (although it gets easier if e.g. the postal service is willing to help you send out the wrong hash).
The hash was distributed in URL form through twitter by both the Catalan president [2] and the catalan economy minister (who is the 2nd in command actually) [3].
[1] https://ipfs.io/ipns/QmZxWEBJBVkGDGaKdYPQUXX4KC5TCWbvuR4iYZr...
Thanks! This is a great read