HNHacker News
TopNewBestAskShowJobs

dustindecker

4 karma · joined May 29, 2018

submissionscomments
dustindecker··on TLS – Cert + DHT = DH-RPC
Okay, I'll do a bit more reading on it.

I found the paper you referenced here: http://www.spovnet.de/files/publications/SKademlia2007.pdf

Also found your overview here: https://github.com/CovenantSQL/research/wiki/Secure-Kademlia

Thanks for sharing.

dustindecker··on TLS – Cert + DHT = DH-RPC
Not a crypto, DHT, or any expert, but this sounds interesting very to me.

It definitely sounds like there are some potential security concerns with DHT: https://en.wikipedia.org/wiki/Distributed_hash_table#Securit... A new implementation called Tonika is mentioned that sounds promising to defend against the sybil attack but I don't see much activity on the project post-2012.

As you mentioned, nodeID becomes the URI (You can CNAME a domain to that) and protects from node spoofing, but it seems like a if someone could affect the DHT, they could cause a DOS. I supposed that'd be analagous to BGP spoofing routes? If the only way to falsely modify the DHT is a mount a sybil attack (I have no idea), then it could actually be an improvement over the current state with BGP.

The other concern of course, is if the DHT implementation is intergalactic-internet scale.

dustindecker··on Blooming Password – A banned password check using a bloom filter
Intercepting TLS on a device running rebranded CentOS 5 (11 year old distro that stopped getting security updates over a year ago) does not seem like a safe idea.