Without knowing too much about the drama discussed here, I think the bottom line is that the "old" Freenet was a bit on life support as far as I could tell and absolutely needed this kind of innovation from its founder.
HN user
adamfisk
Exciting to see Freenet innovating so much, Ian! I haven't really dug in too deep but love that it's in Rust. What's it look like over the wire? How conspicuous is it in the face of, say government censors who can see and control every packet?
Been chatting a lot with the HolePunch/Tether folks, and their work is impressive, particularly the use of the DHT for all signaling, Tailscale-inspired (aka Birthday Paradox) NAT hole-punching, an entire JavaScript runtime, etc. I'm curious about some of those details in Freenet. In particular, does it do fully decentralized hole punching?
Either way, congrats!
Author here, but one piece I didn't dive into is CEF vs CDP. Things like Browserbase use Chrome Devtools Protocol, which is useful for manipulating the browser for some use cases, but it's also detectable in a variety of ways. Wick Pro uses Chrome Embedded Framework with tie-ins at the C++ layer. So it is actual Chrome, not a detectable protocol manipulating Chrome. Some details at https://getwick.dev/blog/cef-vs-cdp, but I'm curious if other folks have experience in this area or thoughts in general.
Wick is also local-first. So it's designed for local agents crawling successfully vs larger scale crawls simply because we haven't built out the infra.
Tor is used relatively little in Iran - https://metrics.torproject.org/userstats-bridge-country.html...
Other tools are much, much more popular, such as Psiphon, Lantern, MahsaNG, etc.
Theoretically this is true, but in practice it's not. Most p2p services rely on the global internet in some way. The BitTorrent DHT, for example, is unlikely so self-heal in the event of a completely inaccessible global internet.
Things like HolePunch have a lot of potential here, but you'd need an Iran-only DHT, and it's just not deployed at scale.
You're dramatically underestimating the sophistication of these groups. Think about it: these people are risking their freedom by working on this technology in any capacity. They are not naive to the risks of the work nor are they naive to the technical threats facing the software. In fact, the opposite is true. Western VPN companies are very much naive because the risks their users face are much less severe, and at a technical level they don't require anywhere near the same level of sophistication. They're primarily just WireGuard and OpenVPN, which are trivial for censors to block.
Tor is great, and they do great research on censorship circumvention, but it isn't used at any significant scale in these countries.
@reisse is 100% right. Most people outside of heavily censored regions have no clue what technology is actually used in those countries. The well-known, well-established providers don't actually work in censored regions because:
1) The problem is very difficult and requires a lot of engineering resources 2) It's very hard to make money in these countries for many reasons, including sanctions or the government restricting payments (Alipay, WeChatPay, etc)
The immediate response would be: "If the problem is so difficult, how can it be solved if not be well-known, well-established providers?"
The answer is simple: the crowdsourcing power of open source combined with billions of people with a huge incentive to get around government blocking.
Oh it's also worth noting that Cloudflare is actually more aggressive in blocking domain fronting than almost anyone else. Lots of folks match the SNI to the Host header, but Cloudflare takes it a step further and also makes sure that TLS connections without SNI have a Host header that's scoped to the IP/server they're actually visiting. That means you can't, for example (not that we would ever, ever do this hehehe), scan the whole Cloudflare IP space for IPs to front through without SNI.
Fascinating, Filippo. We stayed silent on it at the time primarily because we were keeping a low profile particularly as more and more Chinese were using Lantern, but there was also back channel pressure through various contacts, to be honest related to the pending Cloudflare expansion in China.
There was also a prelude to all of this that I think made things stickier and bizarrely personal. Prince and I share a mutual friend who introduced us just a few weeks prior. Prince said he supported what we were doing, but asked that I not talk about it publicly, presumably because of the pending China deal. The problem was that literally moments after our friend had introduced us via email, and before he made that request, I had a call with the WSJ where I talked about precisely this. I did everything I could to walk back the article, but Prince didn't buy it and seemed to go ballistic over it. After the WSJ piece, we pulled back from talking more publicly in general.
Oh, I forgot! We also partly stayed silent because they didn't actually shut down what we were doing at all =). They matched the SNI to the Host header, sure, but they missed a little detail: we weren't using SNI. Hehe. Lantern worked for another six months or so, and then, through a similarly bizarre sequence of events, we essentially tipped them/you off to what was happening. We remained a customer throughout, and we're a customer to this day.
Either way, though, Cloudflare does great work, and everyone has their faults, so I'm generally sympathetic over the whole thing with the one caveat that I am truly unclear how much ultimately did relate to China, most clearly in terms of any public support for these internet freedom techniques.
Oh, and I've wanted you to work on Lantern forever btw. Oooh actually if you're not aware of it, the uTLS Go TLS fork is a hugely impactful project that's in widespread use (I would guess maybe 50 million monthly active users rely on it in censored regions via various projects) but needs updating - https://github.com/refraction-networking/utls
Oh, and if you think we were effective in China then, you should see what we're doing in Russia and especially Iran now!
Yes they’ve received funding from DARPA. I realized I forgot that after I posted. Good catch. To my knowledge, that funding is for new anti-censorship transports to sneak traffic in and out of censored countries.
First, there’s a vast difference between the state department and the pentagon. Lumping those two together just reflects an unsophisticated understanding of the federal government. Signal has never received any state department or pentagon money. Tor had a significant early contribution from a researcher at Naval Research. That’s the extent of any pentagon funding. They have received significant state department funding, but to call the state department “warmongers” is just not accurate.
Um, ok. All of the above projects use not only reproducible builds for many platforms, but they’re all open source, and they all have public security audits. Those three pillars are about as good as it gets. Is there something you would add?
I’m not claiming PBS and the BBC are perfect entities, but they do offer an alternative source of information that runs against the grain of corporate media. You would prefer…what exactly?
I’m certainly not defending all US government actions. That’s exactly the point. Levine tries to lump all of this in with surveillance. The US government funds the NSA, that is true. It also funds food stamps. And torture. The trick is to untangle it.
“The Navy built it” is a bit of an exaggeration. Paul Syverson did early work on it at the Naval Research Lab, and Roger Dingledine and Nick Mathewson added to the collaboration at approximately the same time, with neither having anything to do with the Navy. That’s the extent of the military connection - some relationship in the first year or so of an 18 year or so project.
Yasha Levine is a conspiracy theorist hack. There’s really no other way to say it. His narrative is attractive to a left leaning audience with shallow knowledge in this area, but the reality is that without publicly funded software like Tor, Signal, OTF, and my own Lantern, our world would be more fully saturated with corporate control of the internet. We need more public funding for open source software (with public security audits, mind you), not less. Without them, we’d basically be left with Wikipedia as the only popular entity on the internet outside of corporate control.
All of these projects are more properly grouped with government funding in other spheres, such as the BBC or PBS in media, than they are with the surveillance state or the NSA. Levine overlooks basic details, such as reproducible builds, that quickly collapse the house of cards that is his narrative. He tries to paint them all with the NSA brush, when, in fact, they’re simply projects that have historically received some of their funding from the government while fulfilling missions with extraordinary humanitarian benefits. Levine’s own knowledge and experience in this area is shallow. Look elsewhere.
Wireguard traffic is easy to identify and therefore easy to block.
Having two NATs is really the only case worth mentioning. Considering almost all internet traffic involves at least one NAT, if you can’t handle a single NAT case, you’ve got issues!
Many Gnutella clients were also using Merkle Trees by about 2002.
His p2p research group was extremely influential in the design of second generation Gnutella search algorithms around 2002, particularly those integrated into LimeWire. Sad to hear of his passing.
Or encrypted traffic for that matter -- a lot of VPNs install root certs on your OS.
Full disclosure: I work on Lantern at https://www.getlantern.org.
That said, you should just use Lantern. Recently international links out of China are insanely unreliable, but we’re continuing to improve it. There are hiccups, but it works.
This risk is generally exaggerated. Every once in awhile someone is fined for using a VPN or circumvention tool. Even that is rare, however, and the consequences are relatively benign.
The practice is also so common that it would likely be impractical to make the penalty more severe.
Very few people use Signal or Psiphon in China just FYI
Does Aliyun support path-based file storage? That could be handy!
S3 is hardly the only example of collateral freedom in China. There are many other cases where the concept works.
Have you tried Lantern? It’s free up to 500MBs per month and works well in many censoring countries around the world. It has lots of features that make it fast, such as automatically optimizing server selection and using BBR, and it does many things to stay unblocked, including the use of pluggable transports.
Full disclosure: I’m part of the team that builds it.
For us it’s hard to conceptually free ourselves from our existing points system with Chase. We spend about $125k/month on our card and get something like 1% in points back. So we blow past the $5k AWS thing (which I agree is a cool concept) in about half a month!
I’d encourage you guys to try to keep innovating on the rewards side though (like you are with the current rewards). It seems like one trick is that it has to scale to businesses like ours that are still smallish but have significant spend.
Yup that’s the type of thing we do with Lantern. In particular we:
1) Bind to a random port
2) Require a securely random base path for all requests. Anything without that path is rejected.
The backend just opens the browser at the random port and base path.
This is a complete misunderstanding of what is happening in higher education. The increase in tuitions for need-blind schools like Brown is essentially forced donations for the families that can afford to pay. Everyone is already given financial aid to meet whatever their need is. Now, however, some of that is in the form of loans.
Alongside the increase in tuitions has been a massive increase in financial aid. Princeton really kicked this off around 2000 when they started drastically reducing loans and increasing grants, essentially competing for the top talent among lower income students.
Yeah exactly. This signaling protocol doesn't really matter, and both SIP and XMPP to me are way over engineered and super inefficient- silly that they're text based at all. Essentially like HTTP 1.0 and 1.1 vs HTTP/2 - we just don't have the latter in the signaling case yet, or at least not standardized that I know of.