5 ms·
No difference ICANN or blockchain TLD for making an SSL certificate. Where can this MITM stick his foot in? The blockchain domain record is encrypted and conta
by dudehere 5y ago
No difference ICANN or blockchain TLD for making an SSL certificate.
Where can this MITM stick his foot in? The blockchain domain record is encrypted and contains the publicly visible target IP-address. Even if accessed via http, it can be instantaneously checked. And upon visiting that IP address, the site forces https encryption. Nobody can know from mere traffic analysis what exactly you are doing within the site, since it's encrypted by SSL.
IPFS encryption isn't necessary either, since content is addressed by its hash which automatically guarantees its authenticity. It doesn't matter if you use https or http.
It's only imperfect in the transition during DNS resolution. A 3rd party can know what site you go to, but not more than that. Suspecting a public generic blockchain-domain resolving node set up for freedom in defacing would be a bit too much. Usually those are OpenNIC servers or huge DNS providers, unless you specify a custom DNS resolver in your settings.
For a book site it's a pretty decently protected transition, actually maximal available for a non-expiring (unmanned) service which it is. Legit certificates expire or cost money. The system behind libgen.crypto is fully unmanned, i.e. eternal, except the files themselves which need hosting.
- cmeacham98 5y ago> And upon visiting that IP address, the site forces https encryption. This isn't true if there is a MITM attacker. When you visit an HTTP website, the website doesn't get to redirect you to HTTPS or anything else, because the game is already lost. When you visit a website over HTTP the attacker goes first. The legit response never made it to the client, because it was replaced in transit with a redirect to the attacker's scam/phishing/malware website.
- dudehere 5y agoHow do you get a wrong IP from the blockchain in the first place? The legit software suggested to use reads out the blockchain record and forwards you to the only IP. Unclear to me where you can pick crabs on the way.
- stavros 5y agoSomeone is sitting between you and the legit software.
- dudehere 5y agoUse antivirus ))
- brenns10 5y agoA MITM attack requires an attacker is able to intercept and inject messages between you and the other side of your connection. So when you connect via HTTP to the IP, the attacker just masquerades as the intended target and either doesn't redirect to HTTPS or does so with their own self signed certificate.
- dudehere 5y agoOk, true. I think realistically, just use a community approved (and actually the only) software from the company who risks its huge business, if they become a MITM.
- cmeacham98 5y agoTons of people have an opportunity to MITM you and there's nothing any community approval can do about it because it's not their end of the connection. The random on the coffee shop wifi. Or the hacker on your apartment/university's poorly configured network. Or your shady ISP. Or your own government (especially likely in authoritarian countries decentralized solutions are supposed to help). I see elsewhere you mentioned certificates on the blockchain. That could work, but someone has to actually create a standard and write the code to validate the certificate and get other people to use it, which hasn't happened yet.
- dudehere 5y agoI am aware of SSL on blockchain domains, but this is pain in the ass. As I mention somewhere in this thread, if random downloaders lose the same concerns about privacy as serial killers and child traffickers, I think it's better to buy a book, than to actually satisfy such demands. It can be a good joke for stand-up, though, but since there have been only a few individuals caught in the entire mankind history for making or hosting such libraries, it's not more than a joke which should not detail the world from using high tech. No need to be afraid as an academic exercise. In reality nobody needs users. At all. A few owners vs a billion users... No, bro, no. We are wasting time discussing how a book without any private data is "defaced". It is possible, if to stick a dynamite up the ass, but likely without real exposure or, let alone, the interest of all those 12 lawyers in the world fighting with piracy. Have a glass of wine and relax. There is a long line of people to catch before you get on the list.