Researchers Develop Proxy-Less Anonymity System
threatpost.com
threatpost.com
* "proxy-less" is a bad term, it sounds like they're still using a proxy, it's just using https encapsulation along the way to hide this from the first few hops.
* The participating entry-nodes (proxies?) could be systematically determined with a scanner for future blacklisting or investigation by someone trying to stop this circumvention of censorship.
* You have to trust the people running the entry nodes, if they have the key to decrypt your traffic. This sounds like a design that governments can use for monitoring.
How, exactly? Measuring the run-time of packets and comparing to the expected run-time? I suspect this could be masked by the proxy, but I'm not sure.
You have to trust the people running the entry nodes
You can encrypt the payload independently and then re-encrypt it for the HTTPS tunnel. But as with any proxy, they know the ultimate destination for your traffic, even if they can't get at the data itself.
> * The participating entry-nodes (proxies?) could be systematically determined with a scanner for future blacklisting or investigation by someone trying to stop this circumvention of censorship.
The "entry nodes" are positioned at ISPs outside the censoring country. By assumption, they are on-path from the censor's network to popular Internet destinations that the censor has left untouched.
> * You have to trust the people running the entry nodes, if they have the key to decrypt your traffic. This sounds like a design that governments can use for monitoring.
This came up in our discussions pre-release, and we think it's an interesting feature of Telex. You're effectively able to select which government's Internet policy you'd like to live under.
Sounds like more work to be done.
It is heavier on the math than I would like for my "wha?" level curiosity, but given the audience here it may be a hit.
I suppose you could solve this by generating a good number of key pairs and only deploying new secret keys to ISPs when there was evidence of disclosure, but if the government in question eavesdropped instead of blocked I'm not sure you'd find out quickly enough. It's unclear what advantages you'd get by eavesdropping, presumably little if it's really just used as a tunnel to tor.