4 ms·
If you want to tamper with content on the web, the idea that content is fingerprinted in IPFS is a huge deal. IPNS (the name service) then becomes the vulnerab
by msane 10y ago
If you want to tamper with content on the web, the idea that content is fingerprinted in IPFS is a huge deal.
IPNS (the name service) then becomes the vulnerability, but that is also distributed.
- tscs37 10y agoWell, as I understood IPNS is a bit limited; it only has one resource and there is only one authority that can change content, the node in this case. It does protect against DDOS, since old content remains visible and online but if the private key is leaked or the node is malicious, it has exactly 0 protection. Even worse, if the private key is stolen, you can't do much about it unless you have DNS setup... which brings you back to centralized.
- IanCal 10y agoIf the key is leaked, it means someone can alter what the name points to, but all previous versions would still be available as far as I understand it. No content is changed, only the pointer to the "newest" data.
- tscs37 10y agoThat is true but most external or IPFS-external sites will probably want to point at the IPNS link, bookmarks are gonna point at the IPNS link, etc. In the same way you could still use the old IP + header manipulation if someone took over a Domain in DNS, it's possible and you can use the old site but in reality you're gonna have lots of people on the malicious attacker's site.
- IanCal 10y agoI think that's an important distinction though, and it doesn't mesh with what I thought you meant by > since old content remains visible and online but if the private key is leaked or the node is malicious, it has exactly 0 protection The old content remains visible and online if the private key is leaked, afaik. I think there was some discussion about having there be a chain, so each updated entry would point back to the previous one. I'm not sure where that is (and if it is) on the roadmap now, but that would also allow users to go back to a known good version. This mitigates some, though not all, problems.
- tscs37 10y ago>The old content remains visible and online if the private key is leaked, afaik. The problem is that content that is not access becomes garbage collected and that links and listings will most likely not point towards the hash itself and instead at the IPNS entry. It doesn't have much more protection than a DNS entry if the private key is stolen; you could use the last known IP but it's not very practical and might eventually become dead if the IP changes. In the same way, the old content may remain online after an attacker takes over and people could continue using it but it only remains online if people are using it. If the attack remains unknown for long enough there is no previous version IIRC. >I think there was some discussion about having there be a chain Still same problem, if the private key gets leaked, a malicious attacker can manipulate the entries on the chain. The real solution is something like Swarm or Filecoin where Users can actually encourage keeping old versions around, something IPFS lacks atm. Theoretically any IPFS link can become dead once it's no longer used, which is a problem. Merely putting the entries on chain solves little, you need to actually encourage archiving of data to get resilient against attacks. Even then, you would also need some sort of PKI, where someone can set a master key which authorizes other nodes to manipulate content and can also revoke that. This allows to easily fight off attacks based on leaked private keys. However, the PKI should remain largely private, not much different to Bitcoin Cold and Hot Wallets.
- IanCal 10y agoI'm not sure what attack you're talking about then. If someone steals my key and points my IPNS location to a new file, I'd likely still be hosting the files right? > you need to actually encourage archiving of data to get resilient against attacks. Yes, but this feels like a distinct issue. Neither of these things are enough on their own (encouraging mirrors or providing the tech to distribute the hosting).
- tscs37 10y ago>I'd likely still be hosting the files right? Yes but the entire web points to the wrong files since you no longer own the IPNS location. It's similar to loosing access to your DNS configuration or loosing your GPG keys to an attacker.
- Kubuxu 10y agoIPNS is bug Proof of Concept that mutable content is possible in IPFS, there is long running goal of InterPlanetary Record System that would include much more complex validity schemes including revokeation.
- jbpetersen 10y agoI'm curious what the impact will be of the upcoming improvements to easily support multiple IPNS entries on a single node, along with navigating the Ethereum blockchain, which I'm guessing will make more complex authority schemes easier?
- tscs37 10y agoProbably not but it should make them more robust. On Ethereum you can model complex PKI which IPFS nodes can utilize to validate IPNS data. IPNS data should be signed by external keys you can revoke and manage. Or ideally even encrypted.