An Anomaly in the μTorrent network
cert.pl
cert.pl
Discussion: http://news.ycombinator.com/item?id=3966774
"For a month Pirate Pay’s technology protected the film “Vysotsky. Thanks to God, I’m alive,” (distributed by The Walt Disney Studios Sony Pictures Releasing company) with moderate success."
Sounds likely to me
The solution would be to have a trust of clients. Where every clients vouches for another. The most important thing is that it has to use certificates, if not you get the following problem.
I am client 'c'. I heard from client 'a' that client 'b' is dirty. So I tell this to client 'd', but the truth is I'm lying. However now the problem is: Is 'a' lying about 'b' or am I ('c') lying about 'a'? However having the messages signed by the clients solves this problem.
Virus writers seem to like this technique, uploading garbage to usenet. (50Kb files pretending to be a feature film, etc). I've always wondered why movie studios didn't do more of that.
For arbitrary data you could possibly have a rating/tagging system. I guess the content industries could fudge the votes, but if the votes were tied to identity/pseudonyms they'd have to be clever to beat any kind of data analysis.
The effectiveness would probably depend on how many garbage alternatives you provided, and how sophisticated/varied their uploading is. Too many bad files and voting and signing might not be practicable, and you'd have to resort to some kind of automated spam-detection. White-listed sources are workable in the worst case, but I'm sure there would be other, better ideas around.
Essentially, the way it works is that for a given group there are two keys: A private key `P` (that only the group has), and a public key `Q` (that everyone has). For a file `F` the "signature" is the output of some function `sign(P, Q, F)`. The function `sign` is specially chosen so that the output can be validated without access to `P`, but cannot be efficiently forged without it.
As other posters have pointed out, this means that if `P` is kept secret then all signed releases can be authoritatively linked to the people who provided them. Finding `P` on someone's thumb drive is a smoking gun. To be honest, I don't think this would be a big worry, but I'm not in the scene and I don't know how the people in it think.
That said, a third party could add a signature. But in practice a cryptographically secure signature isn't even needed. It boils down to a reputation system, so that you can associate a torrent file with quality and this has already existed since forever on sites like the piratebay in the form of uploader usernames. A lot of torrents are uploaded by the same users, users who have a history of quality torrents. In contrast, a hollywood uploader would never have any actual quality torrents in the account history. So in conclusion, this problem was already solved ages ago.
http://news.bbc.co.uk/1/hi/2962475.stm
I still have a copy of the file somewhere.
That's half the story. Piracy is a hard habit to break - even when it does get easy to get content cheaply, some people take a while to come around.
It definitely works on usenet - virus spam can make some things impossible to find.
http://www.seba14.org/2012/01/03/hacked-sb-innovation-vuze-e...
http://news.cnet.com/8301-31001_3-57397452-261/riaa-chief-is...
In other words, this isn't a threat to Bittorrent as a technology alone, yet. I wonder how much of an impact it makes on uTP-enabled clients and if you'd be better off disabling it if you connect to an affected swarm.
Can anyone translate this article into language that those of us not familiar with traffic analysis can understand?
Those guys really are great journalists.
I'm sure the DoJ will be handing out indictments in the very near future. <sarcasm/>
It's unfortunate that the only data that really gets protected in the US is Hollywood's.
It's easy to forget how young a medium the Internet is and that there are going to be a lot of pitfalls along the way that we haven't begun to imagine. This seems to be one of those. I guess the question that I have is simple: what happens next?
But, strictly speaking, somethin' ain't right.