5 ms·
Greetings, I develop Stealthy with the OP. After reading a lot of the HN dApp posts, I want to address two frequently occurring topics from the comments: 1. Ho
by ac4tw 8y ago
Greetings, I develop Stealthy with the OP. After reading a lot of the HN dApp posts, I want to address two frequently occurring topics from the comments:
1. How decentralized is this dAPP?
Stealthy is decentralized in two main ways. The first is that it does not require a centralized signaling server to establish connections, when two people have added each other as contacts. That of course requires that they initially co-ordinate outside of stealthy (though we do however have a convenience mode that does a one-time centralized introduction / discovery service if both users have that enabled). The second is our storage, which is built atop Blockstack's GAIA storage system (more info here: https://github.com/blockstack/gaia https://github.com/blockstack/gaia).
2. How secure is Clientside javascript crypto?
In other HN posts, I've seen quotes like: 'Nobody who's serious about security is going to use an app that does crypto in javascript. Why not make browser plugins to avoid this complication?' and posted the classic Javascript cryptography being considered harmful article. Blockstack gets around this in a way similar to being a plug-in with their one-time browser download (which is essentially a node process that also has your crypto keys/generation capabilities so you're not transmitting those back and forth for acquisition purposes). You can find more information on that subject in this forum post: https://forum.blockstack.org/t/blockstack-vs-clientside-js-encryption-concerns/4677 https://forum.blockstack.org/t/blockstack-vs-clientside-js-e...
- chrisco255 8y agoCurious about the choice to use cloud storage vs. IPFS or something similar. What was behind that?
- prabhaav 8y agoWith Stealthy, everything is encrypted client side. Therefore, cloud storage acts as a 'dumb' storage for all your encrypted files. You can store your files redundantly on S3, Azure, Google Cloud, Dropbox, and even IPFS. We just have to enable all those drivers :)
- nunyabuizness 8y agoI think these are more questions about Gaia than Stealthy, but apply to any multi-user application on Blockstack: - How are my messages to another user retrieved from my encrypted storage? - Does sending you a message push the message into your storage? - Do I (i.e., my Blockstack node) have to be online for my message to you to be retrieved later (say, the next time you're online)?
- prabhaav 8y agoAll the messages user A sends to user B is stored in user A's storage. User B poll's user A's storage for the messages. We have offline messaging (file polling) and online messaging via WebRTC. You don't have to be online, your contacts are polling your storage and as long as your storage is online, the messages will be sent.
- prabhaav 8y agoOnce User B receives the message, it is also stored in User B’s storage too. We're also considering ephemeral messages so the messages aren't stored at all.
- 18pfsmt 8y agoI'm curious if you all could implement some sort of "mixing service" so as to minimize metadata?
- ac4tw 8y ago18pfsmt, that's an interesting question. Do you have any specific examples you can point us to? When I think about a network drawn atop of say WebRTC connections, it's possible for a message to travel realtime via hops from person A to person B via persons C, D & E even though persons A & B have no direct connection, obfuscating the path and connection information that lawl alluded to with STUN/TURN/ICE servers. A similar situation exists for offline messaging polling between data storage where we could obfuscate that transaction via another user's client (i.e get person C to poll for messages from Person B to Person A offline). I'm not sure if this is what you had imagined or if you were thinking of something else?
- lawl 8y agoI don't understand what a blockchain is needed for. Resolving registered identities to a public key? Because I can't seem to sign up without an e-mail address, which seems... weird to me. What is the centralized storage used for? Offline messages and history sync between devices? edit: i didn't see the dAPP part, is it also used in P2P messaging? How does your decentralized lookup avoid leaking friend requests out into the open? On your website it also sais you use WebRTC for P2P communication. Am I correct in my assumption then that the STUN/TURN/ICE server at least knows who started talking to whom and when? I really miss a detailed architecture/protocol overview. It doesn't have to be as detailed as for example the signal docs[0], but just something to be able to understand your architecture and the choices you made on a high level. [0] https://signal.org/docs/specifications/doubleratchet/ https://signal.org/docs/specifications/doubleratchet/
- ac4tw 8y agoGood questions lawl. I'll try to address them in order: 1. "A blockchain, implemented using virtualchains [6], is used to bind digital property, like domain names, to public keys. Blockstack’s blockchain solves the problem of bootstrapping trust in a decentralized way i.e., a new node on the network can independently verify all data bindings." [https://blockstack.org/whitepaper.pdf https://blockstack.org/whitepaper.pdf] 2. I believe collecting an email is required in case you need to recover your 12 word pass phrase. 3. The default storage that comes with a Blockstack account is a Microsoft Azure Blob. If you implement your own GAIA hub, you can circumvent that with a number of other options, but conventionally you would refer to the other options as 'centralized' too. Consider this though: "We decentralize data storage with relationship to trusted 3rd parties - remove control from app developers, cloud storage providers, etc and give it to users." [https://forum.blockstack.org/t/gaia-decentralisation/4275/2 https://forum.blockstack.org/t/gaia-decentralisation/4275/2]. Anyway, each user's storage is used for the following things: - contact lists - conversations - offline messaging - initiating WebRTC connections It is all encrypted client side. 4. We have two forms of discovering users. The first is where the users coordinate outside of Stealthy to add eachother as contacts--at this point communication is established only between the two chat clients with no third party, consequently there is not traditional leakage that may occur in this mode. The second (which can be disabled from options) uses a centralized DB and listeners to simply exchange the notion that someone wishes to talk to you. If that centralized DB were to be hacked, that request could theoretically be leaked. The invitation to talk only occurs initially when both parties are not within eachother's contact lists. 5. We do use WebRTC for P2P communication and it can be disabled from the options or during initial configuration. The STUN/TURN/ICE server could certainly acquire some of the information that you mention. 6. We agree with your notion of an architecture / protocol overview and are currently considering precisely how we will proceed with that. Earlier this month we spoke with a representative from the EFF and their advice was to publish a paper on the subject and then commence with formal review of our work, similar to Signal. Hopefully this helps.