I2P: End-to-end encrypted and anonymous internet
github.com
github.com
Sadly, outside of torrenting I2P doesn't seem to have much traction, losing out to the better funded tor project
I recall hearing that it was vaguely frowned upon with Tor back in the day for saturating the networ and it didn't seem like there was much reason to use it over basically any VPN, especially speed wise, assuming your motive was to avoid copyright notices.
That's because a copyright holder could easily host a copy of some pirate film on your new network, and then just see the destination of the data packets.
AFAIK, cops can't deal you actual drugs and then arrest you for it.
Sometimes its legal, depends where you are and how it was done.
> An expert witness affidavit stated that IP addresses linked to Prenda's Minnesota and Florida offices and John Steele, had themselves been identified in 2013 as the initial "seeders" (sharers) of some pornographic media, tagged for "fast" sharing on file-sharing networks, which would be followed up by threat of legal action
Why not? This sounds like a misunderstanding of entrapment
"Entrapment" is actually quite narrow. IANAL, but my understanding is it requires showing that you wouldn't have done the illegal activity without the involvement of the police.
Harassing a person for months to buy weed qualifies; posing as a drug dealer and offering drugs to the people who pass by you, does not.
I understand that is unheard of from someone living in the "instant access era" but their protocol has a cost.
Even if charges get dropped, or you win in court, that's quite a burden.
I am pretty sure not blaming the messenger for the message is a legal notion that predates Hammurabi's code.
There are trade-offs. The Tor Project has its reasons for not doing this (from https://support.torproject.org/alternate-designs/):
"...many Tor users cannot be good relays — for example, some Tor clients operate from behind restrictive firewalls, connect via modem, or otherwise aren't in a position where they can relay traffic. Providing service to these clients is a critical part of providing effective anonymity for everyone, since many Tor users are subject to these or similar constraints and including these clients increases the size of the anonymity set..."
"...we need to better understand the risks from letting the attacker send traffic through your relay while you're also initiating your own anonymized traffic. Three different research papers describe ways to identify the relays in a circuit by running traffic through candidate relays and looking for dips in the traffic while the circuit is active. These clogging attacks are not that scary in the Tor context so long as relays are never clients too..."
Neat point. I wonder if the percentage of bandwidth shared could be relative to the speed or openness of network available?
Ultimately until someone can satisfy a user’s concern about the privacy and security of what flows through their connection there will be scrutiny on this piece. Being able to interject one’s own proxy or vpn tunnel could be interesting.
> Being able to interject one’s own proxy... could be interesting.
I think this is essentially what the Tor Project wants to see instead: if you're in a position to do so, operate your own relay and make it your entry guard. That adds capacity for the network and helps you by mitigating the risk of connecting to a malicious guard.
You’re right as well as this is one way it could be, and there could be other ways.
Tor might want to see that, but I’m not entirely sure how well it’s going when hosting exit relays can be an issue for the hoster.
Both stopped using them because it worked so badly.
I think even though there were many things that could've lead to the demise of Skype's P2P network, it was pretty undoubtedly the rise of mobile phones. Android or iOS, Skype was just dreadful; they were clearly ducktaping mobile support in. Sometimes you'd be sending messages and everything would appear to be working, little did you know the other person was responding but you weren't actually seeing anything. Push notifications? Sometimes you get them, but it was a crapshoot as to when you would get them. It probably was expensive to try to bridge their P2P network to mobile phones, and it definitely didn't work very well.
I guess anyone can just say these things and it's really difficult to back them up since a large part of it is subjective (and aside from some reverse engineering efforts, I am not really intimately familiar with much of the details behind Skype and its transition off of P2P) but I think there is one thing that most people would definitely not disagree with: Skype was far more relevant and well-regarded when it was peer to peer. That's not to say that the move off had anything to do with its downfall, more just to say that if it was so awful, I think it would've been the other way around.
Skype has a much worse quality now after the switch for all people I know who used Skype at the time.
The real reason for switching was iPhone. First, Apple did not allow long-running apps in favour of centralized notifications. Periodically start Skype to check events did not help recwicing calls. Second, users moved to smartphones, which depleted the active nodes network. So there has been an increase of short-lived nodes without balanced increase in long-lived. So to prevent the p2p network model to start failing, Skype moved to a centralized one. And probably the government regulations (to store and decrypt messages) took place, but this was probably not very public.
Microsoft’s acquisition changed Skype to centralize it through their servers (and introduce all sorts of call quality issues).
It’s less about focusing on tinfoil and more about how creating $ for cloud usage allowed for centralization and surveillance.
Skype has been enough of a turn off from the performance issues it has / had hat many people moved elsewhere.
So I don't think it's all that tinfoily to think that once Skype became a US company, the government might have pressured them into making wiretaps possible, since there was a specific law that arguably required it. Considering all that Snowden revealed later, I'm not sure I'd put any digital surveillance in the tinfoil category.
I2P was invented to give people with relatively good, usually excellent, connectivity a way to access forbidden stuff untracked. Think media "piracy" first and foremost, also dark-grey market stuff, etc. Everything else is better served by either your own VPN, or the public Internet.
There's a theory that intelligence agencies control many relays. I've haven't seen evidence of it. Tor does its best to be secure even when it can't trust the relays.
What a bold statement. r/onions has 400k members. Where else would you sell someone's credit card or fentanyl? Ebay?
You are likely referring to awful enterprise frameworks like Spring that make a lot of noise. Some ten years ago it was JBoss giving a bad fame to Java. You won't be finding those enterprise frameworks being used by most open source projects.
For those cases Java is kept clean and fast, as it should.
Then, I started slinging C++ for the Google indexing system.
I still hope we get to a point where compiling to native code is as rare as hand-writing assembler is today. I hope we distribute code primarily in a format optimized for native translation, SafeTSA or similar. (Though, I'd hope we get install-time caching of native code generation, similar to AS/400 TIMI / current Android Runtime.)
However, until compilers get very good at statically inferring lifetimes and statically scheduling object collection, I hope garbage collection is optional and freely mixable with manually managed objects. (Yes, statically determining minimal lifetimes in the general case is equivalent to solving the halting problem, but we can be conservative and fall back on GC in the statically-unsolvable cases.)
The main drawback of Java for most applications is that with garbage collection there's a time-space tradeoff. As a rule of thumb in order to avoid frequent major collections, a Java program is going to use about twice as much memory as an equivalent C/C++ program.
When it really counts, we're still not at the point where Java is faster (even after warm-up) than expert-written hand-optimized C/C++ with profile-guided optimization.
Don't get me wrong. I understand the development velocity advantages of Java over C/C++ can often more than make up for performance differences, and good C/C++ developers (especially with domain-specific skills) are rather expensive to employ. I worked on equity trading systems in an interpreted language, where we replaced a lower latency system written in Java. The high-level interpreted language enabled a very rapid turnaround time and was easier for Statistics/Physics PhDs to implement models. The better models resulted in better average prices despite the system reacting more slowly to incoming data.
Ideally, I'd like to see something Elixir-like with good interoperability with something Rust-like for the parts that use a lot of CPU time and/or a lot of memory, all compiling down to a SafeTSA-like compressed control flow graph representation designed for fast native code generation.
Compiled as JVM bytecode the same app is around 16 MB. For my standards this is quite OK when considering the maintainability across the next centuries.
yggdrasil is a "greynet". End-to-end encrypted, self-organizing via DHT, but no onion/garlic routing. Has interop capabilities with both Tor and I2P though, and some yggdrasil nodes are I2P- or Tor-only. A world-tree with roots (tunnels) going in all the spheres of existence (nets)
Hands out IPv6 addresses to its users. These addresses are generated automatically from the signature of your public key, so essentially impossible to spoof, and automatic authentication, plus end-to-end encryption. As if IPsec was pervasive and completely transparent
Invisible Internet Project (I2P) - https://news.ycombinator.com/item?id=25734254 - Jan 2021 (23 comments)
Kovri – A secure, private, untraceable C++ implementation of the I2P network - https://news.ycombinator.com/item?id=14963044 - Aug 2017 (53 comments)
I2P-Bote – Email plugin for the I2P network that uses a distributed hash table -https://news.ycombinator.com/item?id=14236331 - May 2017 (20 comments)
I2P: Invisible Internet Protocol - https://news.ycombinator.com/item?id=12022917 - July 2016 (56 comments)
However, I would say that Rust/Go already moving out of the spotlight for that purpose. For the hype we'd look towards Zig or Nim or something I've yet to hear.
For context, I'm developing a voting system [1] where votes are signed pseudonymously and must be transmitted over an anonymous channel. Additionally, it's vital that no two pseudonyms use the same anonymous channel, as this would weaken the anonymity.
[1]: https://janiserdmanis.org/artefacts/EVOTEID-2023-poster.pdf
I interviewed Ian Clarke, the creator of Freenet: https://www.youtube.com/watch?v=JWrRqUkJpMQ
PerfectDark was another interesting one.
And my favorite is http://maidsafe.net/ -- they are finally close to releasing, after 14 years! (Disclaimer: I am not affiliated with them)
As I said, the favoured course of action for some dissident communities is instead retreating into the private sphere and trying to live one’s best life there. I have heard that this is a common attitude among dissidents in China, too.
I'm not sure that this kind of passivity can properly be described as "dissidence". Surely dissidents are people who speak up, taking a risk with their own security?
At any rate, I don't want to quibble about semantics. If you disagree with your government, but aren't prepared to speak up, then you're at best getting in the way. Passivity is what authoritarian governments depend on, so passive "dissidents" are like collaborators.
The claim that such dissidents are collaborators is, again, Western-centric. Dissidents can and have argued that the regime's internal contradictions will eventually undermine it, without them having to take actions that put themselves at risk or leave them open to accusations of aiding the enemy.
I count that as "speaking up". GP spoke of people who retreat into what seems to be passive silence.
Incidentally, I said they're like collaborators; I didn't say they were collaborators. I meant they're part of the problem, not part of the solution.
I said people who retreat into private words. Samizdat was a private world. Events held in people’s homes was private worlds. Writing non-conforming literature or music “for one’s desk drawer” was a private world. Modern dissidents using censorship-evading, privacy-guaranteeing software to enjoy community are in private worlds.
Calling such dissidents “part of the problem” is not helpful. There have been famous cases where Westerners’ demands for how dissidents should behave, actually pushed dissidents closer to the regime.
Quick note on it vs Tor
I2P excels inside of the I2P garden. Unfortunately when I last checked there were only a few exit nodes which is where Tor excels.
Normal browsers being used is a massive downside for anonymity of I2P. The Tor browser tries to make everyone on the Tor network look the same.
Easy anonymous file sharing using I2P technology - https://news.ycombinator.com/item?id=31790940 - June 2022 (1 comment)
Guide to I2P and How It Differs from Tor/VPN and Setup Guide - https://news.ycombinator.com/item?id=29547676 - Dec 2021 (1 comment)
I2P celebrates the 20 years of the project with version 1.5.0 release - https://news.ycombinator.com/item?id=28302808 - Aug 2021 (1 comment)
Invisible Internet Project (I2P) - https://news.ycombinator.com/item?id=25734254 - Jan 2021 (23 comments)
I2P - https://news.ycombinator.com/item?id=22985995 - April 2020 (1 comment)
NTCP2 – An authenticated key agreement protocol for I2P - https://news.ycombinator.com/item?id=17749865 - Aug 2018 (4 comments)
Kovri – A secure, private, untraceable C++ implementation of the I2P network - https://news.ycombinator.com/item?id=14963044 - Aug 2017 (51 comments)
I2P-Bote – Email plugin for the I2P network that uses a distributed hash table - https://news.ycombinator.com/item?id=14236331 - May 2017 (20 comments)
I2P: The Invisible Internet Project - https://news.ycombinator.com/item?id=12882790 - Nov 2016 (3 comments)
I2P: Invisible Internet Protocol - https://news.ycombinator.com/item?id=12022917 - July 2016 (55 comments)
I2P – An anonymous overlay network - https://news.ycombinator.com/item?id=8871740 - Jan 2015 (3 comments)
'Silk Road Reloaded' Just Launched on a Network More Secret Than Tor - https://news.ycombinator.com/item?id=8871023 - Jan 2015 (27 comments)
Tor is simpler, better audited, and I don't mind too much the little centralization of the authority TOR nodes, plus the pluggable transports.
I2P is more complete (UDP, protocol libraries, nice hidden service client and server port handling, etc) its somewhat chaotic decentralization is a mixed bless, but that's the point. I like the tradeoff of mixing my bandwidth with others bandwidth (pay with some bandwidth now to save my rear-end later when needed).
I2PD c++ node is pleasant for me because it is compact and clean for my needs (authenticated hidden service SSH access and self-hosted web services) and I can manage it almost like the TOR node. The original IP2 Java node is good for end users, handy with integrated IRC, email, and file sharing services.
Outside of the practical, I2P is built entirely in Java, Veilid is built in Rust, so potentially more performant, Veilid uses modern ciphers so is potentially more secure, Weilid is potentially easier to modify and integrate into apps, and Veilid locally encrypts its storage, I2P does not.
So, realistically, it's a more modern take on I2P, designed to work on mobile, improvements are subtle, but might help create additional adoption if they can get it into people's hands.
The post links to the C++ implementation of I2P.