4 ms·
This looks great, they have some nice properties. If you're interested in this you'll probably also be interested in Peergos [1][2] (disclaimer: I'm a co-founde
by ianopolous 6y ago
This looks great, they have some nice properties. If you're interested in this you'll probably also be interested in Peergos [1][2] (disclaimer: I'm a co-founder), which has stronger privacy properties.
Peergos is an E2EE P2P global filesystem built on top of IPFS, and we have a built in photo/video/audio gallery/player (and other apps too). We don't expose the social graph (who is sharing with who) to the server, and we also obscure things like the number of files, number of directories, size of individual files, even whether something is a directory or file. We are also designed to be resistant to exposure by a quantum computer (mainly we don't rely on asymmetric encryption for privacy, only for sharing, and even for sharing we take measures to protect against a future quantum computer). We also don't rely on DNS or the TLS certificate authorities for security (unless you choose to use the web interface to a public server). We do fine-grained server-less access control using a structure called cryptree [3].
It's P2P so you can mirror your data as many times as you like or just self-host. It's also 100% open source, both client side and server side.
[1] https://peergos.org https://peergos.org
[2] https://github.com/peergos/peergos https://github.com/peergos/peergos
[3] https://book.peergos.org/security/cryptree.html https://book.peergos.org/security/cryptree.html
- anderspitman 6y agoWhat's your alternative for DNS/CAs? Let's say someone wanted to host the source code for youtube-dl. How would that look on Peergos, and would it be an improvement over the current system?
- ianopolous 6y agoIt is effectively routing by public key - similar to how a Tor hidden service doesn't require DNS or TLS CAs for you to connect securely to it. The underlying tech we use is p2p streams in libp2p (part of IPFS) which allow you to dial a public key. The actual IPs of the node are looked up in a DHT, and then the connection can be authenticated without a CA because you already have the public key (the stream itself is TLS1.3). Any file/dir chunk in Peergos has an address which has 3 parts (owner public key, writer public key, and a random 32 byte label). Most data is content addressed, so no need for location based addressing at all. Modifications need to be routed to the owners storage server, which is done using the p2p stream method just described.
- anderspitman 6y agoThanks for the reply. That answers the technical side of it, but I'm more interested in whether you could use Peergos to build a censorship-resistant system that still allows easy collaboration. It's a problem I have yet to see solved.
- ianopolous 6y agoIt depends what kind of censorship you're trying to fight against, but we can already do that to a certain degree. You can grant other users read or write access to individual files/folders, and as long as you can reach them (their storage server) over a p2p stream (which could be over the LAN for example, or any protocol that libp2p supports) you can collaborate.