Reticulum Is Unstoppable Networks for the People
reticulum.network
reticulum.network
These implementations are not secure against side-channels, for example, here's their AES implementation indexing an array with a secret index: https://github.com/markqvist/Reticulum/blob/6ded42edd7ae203e...
Their ed25519 implementation doesn't even attempt to be constant-time: https://github.com/markqvist/Reticulum/blob/6ded42edd7ae203e...
Their X25519 implementation tries to be constant time by using... time.sleep() https://github.com/markqvist/Reticulum/blob/6ded42edd7ae203e...
There are also pure-python implementations of sha256 and sha512, which I haven't looked at closely, but they're already available as part of hashlib (part of the standard library, and already used as a dependency), so they serve no practical purpose.
Ditto for hmac.
I am struggling to understand who the overlap between people who can accurately assess the risk of each of these implementations and correctly find them ok (graduate level cryptography?) and people who cannot get pyca or openssl to compile is.
For offline operation maybe a case could be made that timing side channels aren't an issue in practice, but this is explicitly network software.
Per https://minerva.crocs.fi.muni.cz/,
> The EdDSA scalar multiplication code in libgcrypt was leaking, however due to the way it was used, it was likely not exploitable. It did not reduce the scalar which was a SHA512 digest by the curve order, but used the digest directly, thus the leakage did not represent the bit-length of the reduced scalar.
(Extended discussion: https://blog.cr.yp.to/20191024-eddsa.html)
Reticulum's implementation is similar in that it doesn't reduce the scalar.
From a users perspective, Reticulum allows the creation of applications that respect and empower the autonomy and sovereignty of communities and individuals. Reticulum provides secure digital communication that cannot be subjected to outside control, manipulation or censorship.
Oh yes it can! Unless you control every aspect of this network, including hardware, firmware etc., you are subject to outside control.Please stick to the actual facts.
That would help me quickly understand the properties of this system.
So there is no way to reply to a packet? Sounds useless except for some very rare usecases and spam.
Even in China? When I used to live there, I'd sometimes hear about some fancy anti-censorship software or service and it invariably didn't actually work and turned out only to be meant for comfortable free places like America.
For many authoritarian countries, the challenge isn't "how do I get the information out", but rather "how do I not get arrested for spreading this". Tor, with the necessary oppression proxies, works remarkably well, but is easily recognisable.
https://pubmed.ncbi.nlm.nih.gov/23089042/ https://www.dictionary.com/e/typoglycemia/
So is this a Python-only, Linux-only project? It appears that way from what I can see so far, but it's far from clear.
Someone could set up a directory server with a well known destination address, and then there would be a way to find destinations that will talk to you. Not finding anything like that yet. This seems to be intended for private comms within a group, such as your militia or drug cartel. They went so far in the privacy direction that there's nobody to talk to.
Try Reddit's "r/reticulum". Maybe someone will offer to talk to you.
How does it solve name collisions?
The days before NickServ were a pain in IRC.
Destination IDs are randomly chosen large values, like UUIDs and crypto addresses.
Definitely gives it a serious tone.