System for generic, decentralized, unstoppable Internet anonymity
code.google.com
code.google.com
The problem with this stuff is that immediately tossing all the possible anonymity features onto to your app makes it so utterly seperate from the net that you can't get a critical of mass interest (and your speed really bogs-down but that is secondary/solvable).
What I'd like to see instead is something like an escalating series of counter-measures that each user can trigger at the point they're cut-off from "ordinary" communication - alternative dns when regular dns is messed-with, alternative pipes when they start filtering ordinary sockets, etc.
But make it one app that initially does simple for the user so it get widespread but with the proviso that the apps would do enough discovery that you could "go stealth" when the time came - and have the apps be doing discovery in the meantime.
Attaching MAFIA-Fire to a "social sharing" app like "tribler" http://www.tribler.org/trac seems like a start.
All levels of stealth would be able to be active, but what levels you decide to enable determines which secure network you are on.
Plus you could deploy an app like this in a place like China to immediately get interest/users...
If Google's serious opposing the DNS crocking, they could do something like this now.
The nice things about phantom are its compatibility with applications we use and the distributed design which can make it much harder to cut it off. It was designed for this.
Other internet infrastructure projects would be Netsukuku http://netsukuku.freaknet.org/ (looks great, but inactive) B.A.T.M.A.N. http://www.open-mesh.org/ (a mesh thing, active, working, but with somewhat different goals)
Well, I'm not really familiar with this sort of distributed scheme, so that might be old hat, insanely insecure, or what have you.
If they're both actively sending data out to other nodes, you're more protected, but odds are you won't be giving the network as much bandwidth as your buddy, much less significantly enough to hide your communication in the noise.
If your messages are small, yeah, you're lost in the noise and completely deniable. Which is an interesting advantage.
Anytime you are not actively sending something yourself, it would still saturate the uploads with other people's data.
Then the question remains, "What did you send to that guy?"
I do not think it would ever allow a direct full transfer. But hopping between a dozen or so users with each serving as dual node types would be enough, particularly if all are within the same ISP network.
http://docs.google.com/viewer?a=v&q=cache:mQa724u3AvoJ:w...
and the whitepaper:
A state-level adversary can instrument their major ISPs, put a bunch of nodes on the network, push traffic through the network and do analyze the resulting traffic. Once they figure out who they want to question it's pretty simple, the mere presence of the software on your computer would be incriminating.
I think right now social networking sites are the best game in town because they have legitimate non-activist uses so they won't automatically get you in trouble. To improve on them resistance to traffic analysis and on-client footprint both need to be dealt with or the tool needs to be really popular for some innocuous application.
It is a really interesting set of problems though.
In the 60s the Diggers/Yippie type group http://en.wikipedia.org/wiki/UAW/MF chose their name very aware that it would not be able to be written in print. They knew that they would not be controlling the message in the coverage of their group in the traditional media and so they attempted to embed a message in their name itself.
Likewise, rather than call this scheme Phantom, it might be wiser to name it after a member of the old http://en.wikipedia.org/wiki/Committee_of_correspondence for embedded patriotism and appeal to authority type connotation. Perhaps "Jefferson". In this way, if the government were to target the protocol, they would have to take questions from the press as to why they were targeting JeffersonNet, etc.
"Oh? Safenet?Is it like a safer Internet? Interesting. Where do I find it?"
Plus, you could almost see what the news headlines would be like: "Government tries to take down the Safenet". "Government wants to make Safenet illegal", "Why the Government doesn't want you to be Safe online", "What's so wrong about wanting to be safe online?" etc
Pretty much anyway you'd spin it, it would make the Government the bad guy. Why do you think RIAA names bills like "Protect IP", which is about censoring the Internet, or Homeland security wanted to make the SHIELD law, which is about catching whistleblowers and such. They named them so anyone who "dares" to go against them would be looked at as the bad guy. "How could you want to stop something like SHIELD as its name??"
Naming is not everything, but it can definitely have a big impact on perception of the general population, which is all that matters in the end.
Confusingly on page 10 it is claimed that such abuses are not possible because the network is isolated. But I don't really see the difference between configuring your Tor node as an exit node, or running a proxy reachable over Phantom.
For instance, how is this an improvement over I2P? Phantom should really take a note from I2P's website on what constitutes an adequate amount of exposition to get people to learn about and try your anonymous network.
I remember seeing this a while ago, but I didn't pay much attention to it then, because punishing those who understand the problems with a lengthy verbose soliloquy isn't a good strategy for disseminating information.
:-)
The other problem is that something 60 pages long without any references or citations beyond an occasional casual link to wikipedia, smacks of reinventing the wheel. This would be why he can go for 60 pages without mentioning known terms like "Cybil Attack", or "Onion Routing".
This white paper smells more of bikeshedding - there was no code and right at the bottom of the document, you can see the caveat & apology "This white paper is in no way a complete protocol specification, far from it actually. Its main goal is rather to provide suggestions for solutions for several typical problems [...] which could hopefully work as some kind of reference point for any discussions that may be inspired by it."
I think my favourite part of the paper is where he handwaves PKI & Voting atop of a DHT to 'solve' lots of problems, without realising those are the genuinely hard problems people are still working on.
A close runner-up is in the slides he talks about "no central point of failure" and then explains his "Manual Override Command Support", which is a central point of abuse.
It is nice to see that someone is finally writing code for it, and I wish them luck working out all of the details left out in the paper, especially the organisation and management of addresses.
Facebook is a typical example of how important is to have people adopt a technology. Prior to Facebook was MySpace, yet the former managed to impose and finally replaced the latter because more and more people started using Facebook. With Twitter it's pretty much the same adoption process. Because most people into micro-blogging use it, it is now virtually impossible to come up with another micro-blogging platform that can replace Twitter. And the conversation could go on forever with countless examples.
I'm sure there are so many great ideas out there that get wasted just because people won't start adopting them.
http://www.magnusbrading.com/phantom/phantom-design-paper.pd...
Anonymity/privacy software written by a bunch of people with gmail addresses? Does that strike anyone else as weird?
Can't speak for their domestic philosophy, though.
What did happen to the torrent anonymity proxies, that was in the media a year or two ago? Are they used, but not discussed in the media?