3 ms·
With Stealthy, everything is encrypted client side. Therefore, cloud storage acts as a 'dumb' storage for all your encrypted files. You can store your files re
by prabhaav 8y ago
With Stealthy, everything is encrypted client side. Therefore, cloud storage acts as a 'dumb' storage for all your encrypted files.
You can store your files redundantly on S3, Azure, Google Cloud, Dropbox, and even IPFS. We just have to enable all those drivers :)
- nunyabuizness 8y agoI think these are more questions about Gaia than Stealthy, but apply to any multi-user application on Blockstack: - How are my messages to another user retrieved from my encrypted storage? - Does sending you a message push the message into your storage? - Do I (i.e., my Blockstack node) have to be online for my message to you to be retrieved later (say, the next time you're online)?
- prabhaav 8y agoAll the messages user A sends to user B is stored in user A's storage. User B poll's user A's storage for the messages. We have offline messaging (file polling) and online messaging via WebRTC. You don't have to be online, your contacts are polling your storage and as long as your storage is online, the messages will be sent.
- prabhaav 8y agoOnce User B receives the message, it is also stored in User B’s storage too. We're also considering ephemeral messages so the messages aren't stored at all.
- 18pfsmt 8y agoI'm curious if you all could implement some sort of "mixing service" so as to minimize metadata?
- ac4tw 8y ago18pfsmt, that's an interesting question. Do you have any specific examples you can point us to? When I think about a network drawn atop of say WebRTC connections, it's possible for a message to travel realtime via hops from person A to person B via persons C, D & E even though persons A & B have no direct connection, obfuscating the path and connection information that lawl alluded to with STUN/TURN/ICE servers. A similar situation exists for offline messaging polling between data storage where we could obfuscate that transaction via another user's client (i.e get person C to poll for messages from Person B to Person A offline). I'm not sure if this is what you had imagined or if you were thinking of something else?
- 18pfsmt 8y agoYes, that's similar to what I had in mind. Have you all looked at https://en.wikipedia.org/wiki/Zerocoin https://en.wikipedia.org/wiki/Zerocoin ? My understanding is that Zerocoin eventually developed their own protocol/ blockchain, but originally they operated a mixing service on top of Bitcoin. I admit to being out of my element on this, so I may not be phrasing things correctly, but reading through this discussion it seemed like there would be lots of public metadata for a would-be attacker to work with.
- ac4tw 8y agoIndeed if one was observing the entire network, they might be able to piece together useful metadata as you both suggest. The kind of thing you might do with a NarusInsight. Tox and Zerocoin have done some interesting work towards this end and it's definitely something for us to consider going forward. Thank you lawl & 18pfsmt for highlighting protection of metadata vs. content. At this time protecting content seems like the minimum bar by which one should measure, with metadata protection being the ultimate goal without sacrificing performance or convenience.
- lawl 8y agoI totally get security/privacy vs. usability. I'm not trying to shoot you down btw. I just think we need to openly talk about these trade-offs or rather, make them clear to people who care about them (me). Signal for example is great when it comes to confidentiality and actually easy enough to use so my mom messages me on signal, not so great when it comes to not leaking metadata. Nobody else I know uses Tox. But I know that when I use Signal it's a trade-off I'm fine with, but I'm aware of it.
- deleted 8y ago[deleted]