4 ms·
Reading that, I was prompted (translation: nerdsniped) into thinking about the Same Network Problem: how do you identify two machines that are actually on the s
by captaincrowbar 9y ago
Reading that, I was prompted (translation: nerdsniped) into thinking about the Same Network Problem: how do you identify two machines that are actually on the same LAN and can communicate without NAT, without the risk of revealing any information about your LAN to a third party? (See the article linked above for a fuller explanation of why this is nontrivial.) Here's my plan:
The client enumerates all the machines it can see on its local LAN, and for each one, assembles a list of information about it, probably something like IP address, machine name, assigned user, maybe MAC address, etc. Hash this using SHA256 or something (unlike the suggestion in the ZeroTier article about IP addresses, this approach has enough information that brute force reversal is out of the question). Assemble a list of, say, 20 of these hashes - the client's own hash is first, followed by the rest of the LAN. If you have less than 20 nodes, fill out the list with random numbers; if you have more than 20, include yourself and 19 others at random (it's important that you pick them at random, not just the first 19 in your LAN listing). Send the list to the server - this reveals nothing about your LAN to it.
The server compares the hash lists sent by clients. If any two lists have any hashes in common, send a message to each of the clients that sent those lists: "You seem to be on the same LAN as the client with hash XYZ." The client can then look up the hash in its local table, and try to contact the corresponding node. (The list intersection check is why it's important to pick your sample at random - the birthday paradox is now working for us, and there's a good chance of at least one match even if your LAN has hundreds of nodes.)