Instant.io – Streaming file transfer over WebTorrent
instant.io
instant.io
What if a website uses the technology to spread copyrighted material in the background without me knowing about it? Maybe the website had a simple XSS hole that allowed an attacker to do it?
So later I will get a fine for spreading copyrighted material and I don't even know where it came from?
(Provided the page stayed open, of course)
There was a case in Germany recently where thousands of internet users got cease-and-desist letters and were asked to pay a fine based on an ad-injection. The people behind it made hundreds of thousands and ran off with the money.
On the other hand: If malicious driveby torrenting happens regularly, it will be harder to fine people for it, because it gives them a good excuse.
And when you pay, it's almost impossible to get the money back, because you basically admit your guilt, even when the claim was not legit.
There's more to this case, you can read about it here:
https://torrentfreak.com/viewing-pirated-streams-is-not-ille...
tl;dr: They got users' IPs through ads and misled the courts into thinking the users committed a crime by watching the videos. Courts ordered the ISPs to give out the users' info, the law firm CD'd the users and ran off when shit hit the fan.
The same thing can happen with JS torrenting and it's even easier to do.
After all, what if the JavaScript on a website makes an AJAX request to fetch illegal content and store it in your HTML5 LocalStorage?
Bam, you are now a criminal in possession of illegal content of some sort.
A person to whom a section 49 notice has been given is guilty of an offence if he knowingly fails, in accordance with the notice, to make the disclosure required by virtue of the giving of the notice.
In proceedings against any person for an offence under this section, if it is shown that that person was in possession of a key to any protected information at any time before the time of the giving of the section 49 notice, that person shall be taken for the purposes of those proceedings to have continued to be in possession of that key at all subsequent times, unless it is shown that the key was not in his possession after the giving of the notice and before the time by which he was required to disclose it.
For the purposes of this section a person shall be taken to have shown that he was not in possession of a key to protected information at a particular time if:
* sufficient evidence of that fact is adduced to raise an issue with respect to it; and
* the contrary is not proved beyond a reasonable doubt.
There's also a 2/5 year sentence maximum.
http://en.wikipedia.org/wiki/Key_disclosure_law#United_State...
TL;DR: Case law is mixed on the matter but it sure seems clear to me at least. I don't understand why people can't just say, "I forgot it. Sorry."
chrome://flags
disable webrtc
Even if you enjoy having JavaScript enabled for many sites, something like NoScript is still a good idea---it at least gives you a chance to question whether it's needed at all, or verify what it's doing yourself.
LibreJS will list every script and its contents if it's not marked with a free license, but since it will refuse to execute it, it will not load anything that is dynamically loaded at runtime. But a malicious script could just mark itself as free to get around that.
It's a bad situation all-around.
Chrome canary + uBlock *uMatrix (which lets you allow images / scripts / css / XHR selectively per-domain) is about as much as I can stand to maintain.
https://instant.io/#1cee1045f0ceebcc56bc416da566d5006b58e156
Photo Source: https://unsplash.com/nelly
Unfortunately now that the W3C has made the MPAA a member of its board, I assume it will oppose any and all such protocols with both hands.
I know it's possible in theory to have UDP-like sockets via WebRTC data channels today, but it's really hard.
This is the same for the DNS system. We have chosen to let the system be run like it is. But systems such as OpenDNS and Tor has proven that there are workarounds (with their own set of issues). The question basically boils down to having enough of a userbase for the new system to go mainstream.
[1] https://developer.chrome.com/apps/sockets_udp
The reason I like torrents over regular downloads is that I can pause and resume at any point. In the browser it's not always reliable.
Nightmare for connection monitoring - just like bittorrent.