HNHacker News
TopNewBestAskShowJobs

cgtzczykldpq

171 karma · joined March 26, 2019

submissionscomments
cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
If y'all only try to see if there is CSAM and then uninstall when you succeed, then of course the CSAM percentage will become high because only the CSAM perverts do not leave!

So instead keep using it and actually put the other content onto it yourself!

Hosting on Freenet is free and easy, you just upload a site and post it to FMS and it will be online for many years if people keep accessing it.

You don't need any server whatsoever: The machines of the other users store content which you upload (in an encrypted fashion so they cannot censor it and aren't legally culpable for it). It automatically gets replicated to more machines as it becomes more popular, thus good content stays available for a very long time and unpopular content gets garbage-collected.

So put your "money", i.e. effort, where your mouth is:

Don't just only constantly criticize FAANG for lack of privacy and censorship.

Instead, also take care of actively maintaining the spaces which provide privacy & freedom so they don't become barren.

A free public space which is only controlled by the general public needs the general public to take care of it.

cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
So we must shut down all hotels because they all unknowingly hosted some illegal activities in their rooms, e.g. if someone met a prostitute there?

In fact we cannot have people rent out condos or houses anymore either because illegal stuff will happen there and the owner is responsible even if they don't know!

Also we need to shut down all ISPs because at some point in time illegal data was cached on their machines during transit!?

cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
The anonymized routing prevents them from tracking the source to your computer.

If someone downloads something on Freenet they don't know where it is coming from.

cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
Freenet does not give you the decryption keys to the data you host, you don't know what you're hosting, hence you're not responsible for what it could be decrypted to.

And even if law enforcement could successfully convince a court that you're doing something illegal by hosting data which you cannot look into:

They couldn't first acquire the necessary search warrant because they couldn't prove that you are the one who is hosting the particular piece of illegal data: Freenet's routing algorithm is anonymized, both the people who retrieve data and the people who store it are anonymous. (Disclaimer: The security of the anonymization depends on how you've configured Freenet. In the less secure modes a well-funded attacker can de-anonymize you.)

So if law enforcement knows a certain file is evil then they cannot easily find out the IP addresses of the people who store it, and the people who store it don't know that they are doing so.

Hence it is censorship-resistant :)

cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
If I read this correctly it implies that Freenet's opennet does not work anymore?

So you can only connect to Freenet with this setup if you already know someone else who uses Freenet and peer with them manually ("darknet").

cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
Yeah there are no official flatpaks or docker images so you were using 3rd-party software and this is not Freenet's fault :)

Perhaps you can update your topmost post to mention that?

The official installers are here: https://freenetproject.org/pages/download.html

Thanks for clarifying though!

cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
So the issue was that the default bookmarks contained a site directory - "index" in Freenet terminology - which was not properly filtered by its author.

IIRC Freenet's current policy is to only add indexes to the default bookmarks if their authors do label them as filtered.

Perhaps this was a slip-up of whoever the anonymous maintainer of the index was.

It is also possible that in the past the bookmarks contained both the filtered version of an index as well as another one of the same index which was explicitly labeled as unfiltered with a big warning. Then the users could decide on their own if they want filtered content or unfiltered content for the sake of avoiding censorship.

In any case: The default bookmarks are here, you can check the git history yourself:

https://github.com/freenet/fred/blob/master/src/freenet/clie...

cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
> I tried to connect to freenet last year and I literally couldn't work it out.

Sorry but that must have been a bug or misconfiguration on your machine:

It should connect to the network by default without any tinkering.

Perhaps you didn't pay close attention to the first-time wizard and told it to only connect to manually chosen peers instead of connecting to random strangers? If you then don't add peers manually you won't have any connections.

> The GUI didn't make much sense, I couldn't work out where I was meant to go to browse content.

The default feature is browsing HTML content just like on the regular web.

By default it ships some bookmarks to "index" sites, i.e. sites which list links to plenty of other sites.

Those bookmarks should be right at the main page of the UI at http://127.0.0.1:8888

cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
There is a merged pull request to migrate to libera.chat, it seems it just has not been deployed to the webserver yet:

https://github.com/freenet/website/pull/98

I would blindguess that this was caused by Travis CI shutting down its free service for open source, the website was deployed using Travis IIRC.

cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
I've been using Freenet for 12 years and have not run into CSAM involuntarily, and of course also not voluntarily!

So I don't know how you get the impression that "public servers are off limits"?

It is possible that CSAM exists in certain forums on Freenet which might indicate the specific goal of sharing CSAM by their name.

But if it were to be posted into non-CSAM forums then the community's web of trust would flag it as spam and thus make it disappear. So you're unlikely to just run into CSAM involuntarily.

Also, IMHO saying "public / private servers" in the context of Freenet is wrong because Freenet is not organized into "servers". Basically the whole of Freenet is connected into one big public network.

And it addresses files, not machines: https://news.ycombinator.com/item?id=28588336

"Private" happens in terms of a file being "private" if you don't share the link to it with anyone.

(A separate Freenet network which is fully private would be possible if every participant configures his instance to not connect to the outside. But one participant disobeying that and it is not private anymore, so it's unlikely that such networks exist.)

cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
Freenet has been in development for 21 years.
cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
Freenet is not affiliated with Maidsafe.
cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
Freenet is not a point-to-point network. I.e. you cannot address a specific computer on Freenet by something like an IP.

(Well you can, but you shouldn't want to, will explain below.)

Freenet is a datastore: It addresses content, not computers.

So a Freenet address points to a file or a directory of files (a zip). The addresses can be versioned so files/dirs can be updated.

A file/dir may be stored anywhere in Freenet. Where it is stored is not known - the machines which store it are anonymous so censorship is prevented. If many people request a file, it will get stored on more machines automatically.

Now of course you can make a specific computer constantly publish new versions of a file to "send" data like on IP and poll for a remote file to receive data. This can emulate direct connections and does work.

But it invalidates the whole point of Freenet:

Freenet wants to be censorship-resistant, so content should not rely on a single computer to keep existing because that is a single point of failure.

cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
Freenet's default feature is HTML sites - just like the regular web but fully hosted on Freenet and only accessible through it.

The content of those sites is whatever their authors want it to be :)

Further, dynamic applications such as forums are also available. Here's a list of apps built on top of Freenet: https://github.com/freenet/wiki/wiki/Projects

Freenet needs UDP so it likely won't work on Tails as Tails tunnels everything through Tor - which does not support UDP AFAIK.

cgtzczykldpq··on Freenet is a peer-to-peer platform for censorship-resistant communication
Freenet development is NOT dead! :)

I have been contributing for ~ 12 years and now have acquired long-term funding (independent of Freenet's own funding!) to continue my contributions in a more intense fashion.

The core network which serves static HTML sites + audio/video is stable and usable. It has a bunch of reliable long-term contributors working on it.

Hence development on my personal side is focused on polishing existing dynamic applications which are built on top of Freenet, and implementing some new ones.

Basic implementations of notably forums, social networking, blogging and mail exist already, the goal is to make them easy to use (integrate them into the main UI instead of being standalone), add much more features, improve performance and security.

Here's a list of these and dozens of other apps built on Freenet: https://github.com/freenet/wiki/wiki/Projects

Developing dynamic stuff is taking so long because it is a complex endeavor:

On the regular Internet, censorship happens by "look up who owns the IP, go to their address, remove the computer."

Since this is not possible on Freenet as everyone is anonymous, censorship will happen by denial of service: For example forum systems would be spammed to death to get rid of unwanted content.

Thus the architecture of censorship-resistant systems has to be reinvented from scratch, you can't just take a regular forum system and stick Freenet on top of it.

It has to be decentralized to be resistant against DoS - there must not be Tor-alike central servers ("hidden sites" / .onion sites). Instead messages are stored across the whole network and replicated automatically if they are downloaded more often and thus need more bandwidth (the added redundance also makes them more censorship-resistant).

And spam filtering need to be a first-class application, I have worked for years only on that.

So the different architecture is the primary pitfall which many projects which decided "Freenet is too old, we're gonna build this from scratch with nice Javascript etc." fell into IMHO: First it's "we'll develop a regular app, we can bolt Tor onto it later", then they realize that the threat-model is so different that this is just not possible and the projects never become anonymous/censorship-resistant.

So privacy needs to be built in from the start.

Luckily, Freenet did that right (even though it was the first anti-censorship + privacy network!), and I don't mind that it's taking decades to develop because of the extended threat model:

That's still better than being one of wheel-reinventing post-Freenet projects which then abandon the privacy idea in the end anyway, or postpone it forever.

cgtzczykldpq··on European Parliament approves copyright reform
> It's a ~20 year old P2P network that relies on traffic obfuscation for plausible deniability. But peers see each other's IP addresses.

Traffic is not just obfuscated, it is encrypted. Sure, you see the IP of a peer which transfers stuff across your client - but you do not know what the stuff is as it is encrypted.

So the IP address is worthless unless you figure out a way to guess what the stuff is, and who requested is.

See my other reply in this thread for further details.

cgtzczykldpq··on European Parliament approves copyright reform
> So Opennet allows law enforcement to connect to your Freenet potentially and thus analyze your traffic.

Further, it should be clarified that this is not a problem specific to Freenet:

ANY network which tries to be anonymous will suffer from the so-called "sybil" attack if it connects to random strangers:

If an attacker runs e.g. 100 000 machines on a network of only 1000 actual users then the probability that a single user only has connections to them is very high.

And anonymization must rely upon redirecting traffic across multiple peers - but it cannot if all peers belong to the attacker.

To my understanding Tor addresses this problem by heuristics, e.g. closely monitoring important, big machines in their network, trying to ensure they are in fact distinct entities - but that is really just guesswork, not hard mathematical security.

If Tor wanted to be truly secure it would have to add a darknet mode as well.

cgtzczykldpq··on European Parliament approves copyright reform
> But Freenet is still around, although it's too risky to use it, except via Tor.

Hi, I'm a Freenet developer of the past ~ 10 years, so I'd like to clarify upon this :) (The project is still active, there was a release just this week!)

While there technically were indeed lawsuits in the US, the situation is not as black and white as "it's dangerous".

It is an anonymizing peer-to-peer network as well! What is dangerous under certain circumstances is only one of the three modes to use it: 1) Opennet, where Freenet uses random strangers as peers. 2) Darknet, where you only connect to peers you manually select, e.g. your friends. 3) Opennet with some Darknet peers in addition (I'll call it "mixed mode").

So Opennet allows law enforcement to connect to your Freenet potentially and thus analyze your traffic. Still, this does not mean that your Freenet will plainly tell its peers what you are downloading! Traffic is always redirected across a random number of peers, none of which tells the others who requested it - which provides plausible deniability. All traffic is encrypted, only the recipient can decrypt it. So you cannot just watch traffic and filter out illegal JPEGs or whatever.

What LEA did then is to come up some math and then claim to deduct from it that there is a certain probability that the illegal downloads were requested by the people they claim it came from. Their math is known and discussed by the Freenet core team, it may be addressed eventually - but from watching the discussion (not the math) I can say it should be taken with a grain of salt. It's not absolute proof that the claimed downloaders were in fact the downloaders. It's just a probabilistic assumption, which may possibly be wrong because the way Freenet works is rather complex (>200 000 LOC).

So as Freenet stores content encrypted on random user's machines (which is the advantage over Tor, Freenet is completely decentralized!), it is imaginable that law enforcement accusses people who did not willingly download it, but just happened to store it.

But: You can use Freenet in Darknet or mixed mode to be reasonably safe: The more of your peers are not controlled by attackers, the lower the probability that a statistical attack can be conducted.

Further, the said legal cases only happened in the US to my knowledge, and I'd argue that the legal system of that country seems a bit flawed. Outside of the US you can just run Opennet and probably be at the same risk as some random non-exit Tor node. You transport traffic which you cannot look into (because its encrypted) and store files which you cannot look into (because they are encrypted), so what's illegal about it anyway?