Yggdrasil – Early-stage implementation of an end-to-end encrypted IPv6 network
github.com
github.com
These accounts are heavily colored by the expectations and the worldview of those monks, and we do not know where the ideas that the Norse actually believed in end and where the ideas of what the monks thought religion is supposed to be begin. For example, much of the popular conception of Ragnarok is heavily influenced by Christian eschatology, instead of the original Norse beliefs. To complicate it even further, the Norse beliefs were in no way static, and as the influence of Christianity spread, the beliefs might have morphed to absorb concepts from Christianity.
In more easy words: christians believe that one day the world really ends with judgment day/apocalypse, and interpreted Ragnarok similar as the end of the world, which is what many people today think of Ragnarok (and that view that gets reinforced by the popular movies)
But Ragnarok is not the end of the world, just the end of a cycle and start of a new beginning. The snake that bites its own tail. Endless cycle of seasons. Really a different philosophy.
https://www.youtube.com/watch?v=zbT8vzX4sZY
(Einar Selvik from Band Wardruna explains it, before performing a song about it)
There is also the interpretation that we live in a post-Ragnarok world, which conveniently allows the Christian narrative to perfectly mate to the end of the Norse gods’ reign.
There are even 6th century writings referencing a germanic mythology with many similarities to the norse mythology.
First of all, it's a branch of Indo-European mythology, as are the Greek, Roman, and Hindu pantheons. So it has existed in some form for thousands of years. But "Norse mythology" as we know it was mostly written down in the 13th century - so 700+ years ago.
I recommend you studying it a little, it's really not that hard, just looks weird.
-noob language nerd
Sidenote: I had a bit of trouble locating an IPA transcription for Yggdrasil. The pronunciation guide in the Wikipedia article for Yggdrasil Linux/GNU/X is not IPA, it's using English pronunciation rules to try to emulate the correct pronunciation. The pronunciation in dictionaries (at least Merriam Webster) is also not quite IPA, though it is close. I came up with this pronunciation by merging those sources. I is probably correct, as I found a matching transcription in an old version of the Yggdrasil Wikipedia article which was removed for being original research.
Don’t need to be a language nerd to understand that.
Not even at GNU/Linux, but a Linux/GNU system... Would Stallman accept that or does GNU have to be first?
Those were the days.
> the root is the node with the lowest ed25519 public key, rather than the highest sha512sum hash of the public key
With this scheme, could a bad actor decide to choose a poor key just to be the neighbor of a target in (edit) keyspace? Ordering by the hash of a public key means that the order is protected by the hash function's preimage resistance; does the generation of a ed25519 key have a similar protection?
Dealing with attackers in a system like this seems very challenging, though very worthwhile in the end! Maybe something web-of-trust-y...
Yggdrasil network throughput vs plain.
Yggdrasil processor load and memory overhead vs plain.
Yggdrasil latency vs plain.
No matter how bad that numbers look. One can at least know beforehand what to expect.Based on documentation, it sounds that they have some kind of own crypto implementation in the end. I found the whitepaper describing used algorithms, but I would need to know more how exactly they are applied and why they are selected, before I could trust the encryption.
It's designed to be as minimal-configuration as possible and scalable in a way that many other mesh routing protocols aren't.
YG is decentralized, direct peer to peer and multi hop routing, manual key exchange for direct peering, virtual internet (each node is a router to another nodes)
ZT (and Tailscale) requires a central node coordinator for automatic config and peer key exchanges, peers directly to each node to create a flat virtual network, not multi hop routing, between two peers you need a reachable IP or port mapping (supports UPNP) by one of them (fixed in config there are private TCP relays when carrier NAT/double NAT/ restrictive firewalls are in place, very slow), Uses UDP for the links, mimics a virtual switch and support custom IPV4 / IPV6, good for virtual private networks.
YG (and CJDNS) is kinda an overlay public network, is fully decentralized, it supports automatic routing between nodes to mimic a virtual Internet, each node is a router too, needs to register each key for every direct peer node connection (config needs peer key, reachable ip and port, but supports automatic key exchange for local networks), YG uses TCP for the links, support self-healing routing, every peer has an IPV6 address derived by its public key.
ZT (and Tailscale) can mimic a mesh network and node routing because supports bridge nodes between networks (routing between virtual switches), but is not self-healing and somewhat heavy work to config. ZT is fully open source, can be config with your own node coordinator and discovery helpers (Controllers and Moons in ZT), not easy. Only Taislcale client is open source, can't be config with your own node coordinators for free.
You can mix ZT and YG, weird side effects warranted but works. (Edited post - some grammar fixes)
It's closer to bittorent than a VPN. It has end-to-end encryption and each node (the app that runs on your PC) distributes routes to each other (similar to how routing works on the Internet between large networks). It appears to be a flat spanning-tree style network.
They mention that it is using similar code and ideas as the cjdns project.
I use yggdrasil for NAT hole punching my VPN, for example.
>People often ask us for an overview of how Tailscale works. We’ve been putting off answering that, because we kept changing it!
Yggdrasil is fully peer to peer and doesn't require a central coordinator like tailscale does. Ygg is closer to a global network than a private one. You can make a private network, but if any peers on the network peer to the global net then your whole network is now peered. this should be handled at the firewall level, or with an overlay VPN.
I still facepalm whenever I think about this.
Could you elaborate with some specific examples on what you see being "very reasonable latencies"?
YG uses it own crypto and routing, wintun is used here only to expose the virtual network interface on Windows.
YG puts more "magic" on protocol (autorouting, mesh making, etc), but is not that clean on design (crypto not formally tested, latency prone TCP links, not good enough NAT punching, etc).
Wireguard and YG are different tools on the SDN network toolbox, and can be mixed for special porpoises.
- bandwidth bottleneck at the root
- single point of failure at the root
- any node failure partitions its subtrees
- slow, complicated reconfiguration after node or link failure
So while usability is pretty similar, they're pretty different underneath.
I've never seen anyone need to check the top byte of a nonce before. This looks very odd to me.
Here is the relevant comment/code from Samba.
* CCM and GCM algorithms must never have their
* nonce wrap, or the security of the whole
* communication and the keys is destroyed.
* We must drop the connection once we have
* transfered too much data.
*
* NOTE: We assume nonces greater than 8 bytes.
*/
...
switch (xconn->smb2.server.cipher) {
case SMB2_ENCRYPTION_AES128_CCM:
nonce_size = SMB2_AES_128_CCM_NONCE_SIZE;
break;
case SMB2_ENCRYPTION_AES128_GCM:
nonce_size = gnutls_cipher_get_iv_size(GNUTLS_CIPHER_AES_128_GCM);
break;
default:
nonce_size = 0;
break;
}
x->nonce_high_max = SMB2_NONCE_HIGH_MAX(nonce_size);
x->nonce_high = 0;
x->nonce_low = 0;Where the definition of SMB2_NONCE_HIGH_MAX is:
#define SMB2_NONCE_HIGH_MAX(nonce_len_bytes) ((uint64_t)(\ ((nonce_len_bytes) >= 16) ? UINT64_MAX : \ ((nonce_len_bytes) <= 8) ? 0 : \ (((uint64_t)1 << (((nonce_len_bytes) - 8)*8)) - 1) \ ))
What commercial application will this have for an average consumer that isn't tech-savvy?
"Magic VPN" or "Magic E2EE LAN" kinda IPSEC for commoners, depends on how you config it.
(asking with tongue in cheek)