13 ms·
VPN⁰: A Privacy-Preserving Distributed VPN
- snagglegaggle 7y agoWhy not Tor? Providing more bandwidth to that network seems the most advantageous option. You also get stronger privacy guarantees.
- ViViDboarder 7y agoThey explain that in the first paragraph or so. This allows edit nodes to decide what types of content will be routed to their node.
- snagglegaggle 7y agoAnd opens the network to abuses Tor was meant to protect against. If proof-of-destination is built into the network then that is a huge step towards invalidating the main benefit of using a VPN -- you don't want someone (your local authority) knowing where you've been. Current VPNs sort-of work by not being in your local jurisdiction. Decentralizing it makes it easier to attack.
- deleted 7y ago[deleted]
- mlyle 7y agoIt uses zero knowledge proofs, so it doesn't really give anyone on the way proof-of-destination.
- snagglegaggle 7y agoYou have proof that someone visited a specific site because it uses a value derived from that site's SSL cert. You just don't have any more knowledge than that.
- mlyle 7y agoNo.. You wouldn't need a ZKP for that. From the paper: > Note that such a proof is not straightforward. We firstly prove that a ciphertext, CS N I , is the result of an encryption without disclosing the public key nor the plaintext. This causes the highest overhead in our construction. We use the construction presented in [7] for this purpose. > Then we need to link the public key encrypted in clause two, with the one used in clause one. For this we use a proof that two commitments hide the same secret [5]. > Finally the third clause can be openly computed by A given that it received the public key from R. > Using this, S can convince A that the tunnel created is to a domain that the latter considers valid, without disclosing which one.
- ddtaylor 7y agoTor can also have whitelist for clearnet domains.
- noah-kun 7y agoTor is funded by the US government, probably as a way of disseminating US propaganda during government overthrows. When conducting psyops, governments sometimes block the online channels the US uses. With them also controlling so many nodes, they can use Tor for surveillance.
- earenndil 7y agoTor is funded by the us government. Why is very unclear. They may have backdoored it. They may be using it for surveillance. They are probably not using it to disseminate propaganda (they can do that over traditional channels). However, the likeliest reason (imo) for funding tor is simply that they need it themselves. There's a famous--and possibly apocryphal--anecdote from a security researcher who met an FBI agent at defcon. The security researcher brought up tor, and the FBI agent said 'oh, yeah, we have our own anonymity network like that--except it's just for the FBI'. The security researcher was unable to explain to the FBI agent why that made no sense.
- noah-kun 7y agoIt was revealed the FBI poses as Russians when doing their digital operations; maybe that's what they meant. Tor absolutely spreads US propaganda. The "clear net" does too. The utility of Tor is that it prevents that clear net propaganda from being firewalled. In the case of Hong Kong, we know who funds the terrorists. They meet with them in person and have been photographed, and the US makes no secret of how much they spend on terrorism in Hong Kong. But I still wonder how guides and instructions are given to the right people. Having read many CIA documents written to terrorist groups, I do wonder how they send these to HK terror leaders in the digital age. Tor is a candidate. Number stations, I kinda doubt.
- swinglock 7y agoTor doesn't use BAT.
- phs318u 7y agoUsing zero-knowledge proofs to get around the "I don't want to carry <content-I-dont-like>" barrier to entry of distributed relay tech, is really very clever. The performance sounds like it might suck though.
- bArray 7y agoThis is the sort of feature that could get me using Brave instead of Firefox. Great job by those guys, I've been wanting something like this for a while now!
- cbluth 7y agoSame here, now I'm interested in brave. I wonder what kind of cool thing they'll come out with next.
- dimator 7y agoThe whitelist based approach seems pretty limiting, doesn't it? If every exit node is expected to enumerate the domains it will carry traffic to, what happens if a client needs to connect to a new site? Are exit nodes intended to keep massive, curated whitelists? Something isn't adding up, to me. If the assumption is that all "good" sites _can_ be enumerated, then wouldn't Tor (or other systems) exit nodes already be capable of blocking CP? Someone connect the dots for me....
- luckylion 7y agoThe CP, Drug markets etc on Tor is typically on hidden services, not on the clearweb. The whitelist approach may work similarly to adblocker lists, where you say "I trust Jim's List Of Friendly Websites". I don't know how good it is for performance though.
- sdan 7y agoObviously you can do a block for *.onion. But suppose someone searches up "how to make a [insert bad thing]" or something else inappropriate on something as simple as Google. It'd be somewhat hard to block all urls from Google or DDG that contain some text (not to mention that I've heard that people who are in this business use acronyms or other slang... which to the general user (like me) probably won't know. Don't want to take that risk.
- luckylion 7y agoI believe the blocking is done on a domain/host level, so you'd block google.com in that case. That's likely not required, because google.com is generally thought to be okay, but you are correct that even that may be problematic. If your IP has searched for "$governmentBuilding blueprints" and there's a bomb planted at that building a week later, you could become a person of interest (provided that Google saves the ip for queries). Blocking *.onion on the other hand wouldn't be necessary from a "legal protection" standpoint: hidden services don't see the original IP of the client.
- 7y ago
- sdan 7y agoGreat idea. Was thinking of doing something like this for a while, but obviously the drawback is that you're suspect to being the exit node for someone who's doing something illegal, which is a risk I'm not willing to take for the sake of privacy. Obviously you can start a whitelist, but as some other comment said, it's pretty limited... and I don't want the hassle to add in every domain I go to (given the number of different blogs posts from different domains that show up on HN). For now, I'll be sticking to AlgoVPN because I can't imagine how they'll protect the safety of users too (maybe a blacklist... although that'd be hard to given the numerous "bad" websites out there that make you suspect of further surveillance).
- mirimir 7y agoBut would you be more OK sharing your AlgoVPN exit? With the same sort of blacklist/whitelisr approach?
- sdan 7y agoProbably. Given that AWS/GCP can't trace back to me then maybe. But at the same time I'm afraid government surveillance is government surveillance and petty tactics around hiding your identity to AWS/GCP won't cut it.
- mirimir 7y agoMe too, think. What about sharing it as an internal non-exit VPN in a nested chain?
- sdan 7y agoCan you elaborate? Not sure what an internal non-exit VPN nested chain is... although I some vague idea on what that may constitute to be.
- mirimir 7y agoIn this diagram, VPN1 is what I'm calling the "internal non-exit VPN": https://keybase.pub/mirimir/VBox-Two-VPNs.png https://keybase.pub/mirimir/VBox-Two-VPNs.png It's not as much "non-exit" as Tor middle relays. Because it just connects to the VPN2 server using OpenVPN over standard TCP/IP. Instead of some proprietary protocol. But at least it's locked down with pf rules, so that it can only connect to the VPN2 server. The diagram shows a nested chain with just two VPNs. But you can add more layers. As I recall, as many as six or so. Latency goes up, and MTU goes down. But throughput doesn't crash as much as you might think. I don't know why. But maybe it's caching. So basically, you have a NAT chain locally in VirtualBox or whatever. And each NAT router includes a remote VPN server. In order to share it, you'd need to open a port for incoming OpenVPN connections. Either locally, or forwarded to one or more VPN servers. And then you could route traffic through another VPN server in the chain.
- deleted 7y ago[deleted]
- vasanthv 7y agoHow is it different from Cloudflares 1.1.1.1?
- progval 7y agoThey have nothing in common. Cloudflare's 1.1.1.1 is a DNS resolver.
- traderjane 7y agoCloudflare's Warp VPN service is provided under an app of that 1.1.1.1 name, which may be the confusion here.
- dewey 7y agoIt's a VPN now: https://blog.cloudflare.com/1111-warp-better-vpn/ https://blog.cloudflare.com/1111-warp-better-vpn/
- kzrdude 7y agoIt's like a half VPN, https://blog.cloudflare.com/announcing-warp-plus/ https://blog.cloudflare.com/announcing-warp-plus/ see "What WARP Is Not"
- NGINX95 7y agohttps://www.facebook.com/litar.tarbps https://www.facebook.com/litar.tarbps
- randaouser 7y agoOne step further that Ive prototyped is Encrypted and Distributed Search. The VPN relays willing to take the traffic can also double as Web crawlers. The vpn clients encrypt their search terms and vpn relays encrypt their search indexes, and perform ElGamal Homomorphic private set intersection with MINHASH in Elliptic Curve Field. This leads to better then key word, worse then current age context search from google but with Strong Elliptic Curve privacy guarantees.
- WC3w6pXxgGd 7y ago> The vpn clients encrypt their search terms and vpn relays encrypt their search indexes, and perform ElGamal Homomorphic private set intersection with MINHASH in Elliptic Curve Field. Can I get this phrase on a T-shirt?
- bubersson 7y agoTo make this type of search higher precision&recall you would have to focus especially on the indexing part (e.g. improve NLU of concepts in the pages), right? The training of such ML models could be federated across the nodes in a private way.
- randaouser 7y agoIndexing is important for sure. The problem is to preserve privacy and not falling back to heavy weight general purpose Multi-party computation we have to give up a bit on the precision and recall of modern search engines. Minhash, more specifically Locality Sensitive Hashing (LSH) is a good first approximation (Better then Term Freqency, worse them ML based search). Right now much of the web is unqueryable, my first goal was to allow the deep web and TOR services to be searched even at just a rudimentary level.
- ackbar03 7y agoIs there an open source version or something of this? I had similar ideas and this is something I would have liked to contribute to. I was thinking of approaching the white listing problem by whitelisting users, I. E. I share my node with friends I trust, and that gets propagated through the network depending on trust levels.
- colordrops 7y agoIsn't Brave open source?
- yalooze 7y agoHow do you say VPN⁰ out loud? Would be good to clarify that in the opening paragraph.
- geoah 7y agoI would assume “zero vpn” or “vpn zero”, as it most likely a reference to “zero knowledge”.
- Uhuhreally 7y agowith a high voice for "zero"
- mirimir 7y ago"VPN Zero" I'm sure. Me, I'd just say zero.
- OJFord 7y ago'one'
- zingermc 7y agoVP
- notduncansmith 7y agoWhy?
- superkuh 7y agoI came here to make this joke. Basically, any number taken to the zeroth power is 1.
- notduncansmith 7y agoThanks for taking the time to explain!
- 7y ago
- mirimir 7y agoThis is not a new idea. Hola has been around for years. Trying to protect users through access control is foolish. It's like running a Tor exit from home.
- dewey 7y agoI guess it's a bit different for two reasons: 1) Here users are using the bandwidth and it's not resold to companies like Hola does is with https://luminati.io https://luminati.io. At least for now. 2) They whitelist domains, so they could only whitelist example.com and you know it's not like Tor where everything goes or Hola where someone is web scraping things through your IP.
- uasm 7y ago> "They whitelist domains" That's not a bad idea, actually. Who maintains those whitelists and how do they get updated? If you want to make the web somewhat usable for others, is it enough to whitelist "google.com"/"youtube.com" only (for example)?
- mirimir 7y agoTrue, nothing like Luminati, I gather. But the very idea of sharing my uplink is anathema. Maybe if everyone curated their own whitelists. But once people rely on whitelists from "trusted" peers, all bets are off. A safer alternative would have users sharing access to each others VPN service connections. That would at least insulate users somewhat from malicious/illegal traffic routed through them. Indeed, I routinely route traffic through nested chains of 3-5 VPN services. A common criticism is the cost of multiple accounts. And I typically have even more accounts at any given time, for variety. But if a bunch of people pooled access to their VPN services, or to VPNs that they ran privately on anonymously leased VPS, each one could have a much larger variety of VPN paths and exit IPs. And you could multiplex and split traffic through the VPN network, to increase anonymity. Or aggregate links, using MPTCP, to increase throughput. And you could even implement something like Tor's process of switching circuits every 10 minutes. I bet that I could implement a simple version of that with routing tables and iptables rules. And some shell scripts. Perhaps with network namespaces, for a little more security. Even Docker, maybe. But not just sharing ISP uplinks. That will end in tears.
- deleted 7y ago[deleted]
- pl3w5y 7y agosubscribing to shared lists like we do now with adblock but for exit capabilties would work very well. I think an auto meshing VPN system like Tinc or N2N would be better for the network too
- bunkydoo 7y agoCheck out mysterium network or sentinel - better solutions that are actually implemented. Brave was a neat idea, but I just never saw the execution piece come in. It's a glorified fork of Chrome as far as I understand.
- johnpowell 7y agoI refuse to use a browser with a cryptocurrency attached to it. It feels like the only reason it is being pushed so hard is so BAT holders can make a buck. It might be a great browser but I will always think of it as onecoin with a some chrome tossed in.
- olah_1 7y agoAttaching a crypt coin to it only makes sense if it's more fully decentralized. The fact that it is centralized is why it's confusing. We run the VPN and they get the money. In something like Lokinet, the whole thing is distributed and the people that run the service nodes get rewarded with coins. But normal end users don't have to think about the coin at all.
- bufferoverflow 7y agoWho cares? You don't have to use the crypto part of it at all.
- atoav 7y agoIdk – with something as crucial as a browser I want the people who give it to me to have a clear and obvious incentive structure.
- bufferoverflow 7y agoYou still didn't explain how a feature that you'd never use affects you in any negative way. Every browser has features that you don't use.
- 3solarmasses 7y agoA lot of HN users can't stand crypto simply because they missed out. Envy leads to childlike refusals.
- mhluongo 7y agoWith other browsers, the clear and obvious incentive is "to get paid to spy on users". I'm not a big Brave fan but saying their incentives are worse than Chrome or even Firefox is ridiculous.
- buboard 7y agoHow about sharing blacklists instead? Whitelisting sounds like a performance bottleneck
- olah_1 7y ago>we noted that existing dVPN designs fail to provide strong privacy guarantees...their decentralized nature requires strong guarantees on the traffic a dVPN node carries without violating a user's privacy, at any time. I suggest looking into the Loki project https://loki.network/ https://loki.network/ I'm not completely sure how these two efforts compare, but Lokinet is essentially a more privacy protecting version of Tor.
- godelmachine 7y agoDoes it support OpenVPN?
- deleted 7y ago[deleted]
- saurik 7y ago(I am technically involved in a project called Orchid that would be considered a direct competitor to this idea, were this idea a product; but I would like to think my cynicism isn't related to that ;P.) So, a more complete--and somewhat more balanced--description of this is in the actual paper, for which this is just a blog post summary; I would think the paper is way more valuable than this blog post, and maybe should even be the Hacker News post target. https://arxiv.org/abs/1910.00159 https://arxiv.org/abs/1910.00159 First off, the DHT here is unlikely to scale well to large whitelists; yet, for small whitelists, you will (of course) end up knowing the target domain to high probability--which, even for large whitelists, is going to be possible given just the target IP address almost all of the time anyway: even with a CDN, the set of websites you get overlapped with tends to not be extremely large; and, even when it is, it is almost always with a bunch of niche websites that are unlikely to be on your whitelist--so, the premise that this is all hiding from the exit node who you are connecting to is extremely weak. Oh: and when it does even sort of work with the CDN (due to having the shared endpoint), the user can usually then use domain fronting to trick the SNI, which would bypass this proof and let you connect to any other website behind that IP address; so, really, the way they are doing whitelists is just wrong: the IP address you are connecting to and the totality of what is behind it is way more important than the SNI. Essentially, while you can do this (prove, in zero knowledge, the SNI of an HTTPS connection), it doesn't seem like it really helps a real-world problem (as the situations where the technique works correlate with situations where you failed to hide anything). Meanwhile, this paper admits to taking 10-30 seconds per HTTPS connection (not per VPN tunnel!) as the DHT lookups and zero knowledge proofs are both slow operations. Somehow, before that completes, it sounds like you just get to use a different node to send "unauthorized traffic"? Why can't I just sit in that regime forever? I am hoping I just don't understand this part, but they say it multiple times as if it isn't such a big deal, and have a bunch of space dedicated to trying to make it sound like the unauthorized traffic would be a small portion of the total traffic (which doesn't exactly sound comforting). And finally, domain whitelists don't work in the first place: I can post horrible things that get you in trouble to the comments section of a news site (their best example of a kind of website you might whitelist) quite easily; and, for their example of Facebook, it is actively dangerous: Facebook is an entire Internet unto itself that proactively scans for evil things, and so if you whitelist that you are essentially admitting "I would be willing to let you do anything". I could see a URL-based whitelist potentially having value, but not a domain-based one. We shouldn't be making users feel safer with systems that don't even slightly help :(. (It is maybe also worth reminding that before the advent of encrypted SNI, this data could easily have been used to filter and whitelist traffic... and yet people working on projects like Tor still don't use it for filtering, as it just isn't enough, as you still don't know what the user is doing. It frankly just feels likely to me that the two goals that people want to simultaneously achieve here--"I don't know exactly what you are doing" and "I do know, to some reasonably high certainty, that you aren't doing something that would harm me"--are simply philosophically incompatible without some form of reputation/trust... which then makes achieving a third goal that people want--"I don't know who you are"--much harder.) Regardless, back to the paper itself, I would argue that this is a single maybe-novel idea--that you can do a zero knowledge proof over the SNI packet of a TLS 1.3 connection with encrypted SNI--that is, as is common in academic papers, trying to be described in the context of a full-scale solution by surrounding it with the minimally-viable wrapper required to turn it into a product for an under-specified use case and then trying to type quickly past the serious downsides (such as the latency), all without being extremely critical of whether the idea itself is useful.
- spassbold 7y agoThis idea of a dVPN based on cryptocurrency is not new, see for example sentinel, mysterium or privatix.
- deleted 7y ago[deleted]