4 ms·
Peer-to-peer has benefits... and cons. It's not a magical cure-all. How would _you_ implement a secure P2P where you (and only you) can rapidly change content
by katastic 9y ago
Peer-to-peer has benefits... and cons. It's not a magical cure-all.
How would _you_ implement a secure P2P where you (and only you) can rapidly change content (dynamic web pages) and control who has access to authorized pages?
What about credit card info? Passwords?
I imagine there "are" implementations that solve many of those issues. But it's sure-as-heck not common knowledge if there are "easy" answers to all those problems.
I can't help but feel "Reflections on Trusting Trust" by Ken Thompson screaming at me. How do you ensure every bit of the web stack isn't hacked on every computer in the network, as opposed to your own?
[1] [PDF] http://vxer.org/lib/pdf/Reflections%20on%20Trusting%20Trust.pdf http://vxer.org/lib/pdf/Reflections%20on%20Trusting%20Trust....
In fact, when dealing with P2P, you're more likely than not, to be full of compromised programs. Many unintentional, but many others intentionally. Torrent users who run clients that don't upload. Every P2P game ever made being hacked. (See the entire purpose behind QuakeWorld moving to a client-server model over P2P, over the original quake.) And every Kazaa uploader had viruses on his PC back-in-the-day.
I'm not saying P2P is impossible. But first, you've got to define what application you want to implement (webpage, vs public video hosting) because the solutions are completely different. And even then, you're still walking into dangerous territory when you can't control the machines your relying on.
What happens if you need more bandwidth than your usernet can give? You can't simply "install more servers" or "buy more bandwidth" when your "server" is every user connected to your site.
And what happens when you roll out new versions, and some users don't upgrade?
The list goes on. And I say all of this as someone who has considered using distributed computing model for game hosting, where machines assist in computations and bandwidth. It's possible to do, but it opens up entire dimensions of additional problems to solve.
- loup-vaillant 9y agoMany of the problems you talk about are off topic. --- The trust problem still applies to HTTP. We still download viruses on the web, and we still lose our credit card numbers to con artists. The only reason there's more malware on current P2P network is because those networks are disproportionately used to infringe copyright. The risk doesn't come from the distributed nature of the network, but from the lack of legality of the content. Securing peer to peer communications to current web levels is trivially easy: just sign the damn data, and have a certificate authority ascertain the identity of the signer. For static content such as YouTube videos, you can also use a content addressable system. While that would require some level of centralisation, it woulndn't exceed that of DNS, and would definitely solve the bandwidth issue. > What happens if you need more bandwidth than your usernet can give? I won't happen, because we enjoy symmetric bandwidth, thanks to our regulators being sensible, competent people. (At least that's the case in my rainbows & unicorns world). Seriously, though, symmetric bandwidth is the ultimate and only solution to many problems: it ensures total upload keeps up with total download, so we get the equilibrium we want.