22 ms·
Avoiding Internet Centralization
- superkuh 5y ago> 5.2. Encrypt, Always: When deployed at scale, encryption can be an effective technique to reduce many inherited centralization risks. ... The problem here is the word "Always". Encryption is good for just the reasons they say. But only encryption, always encryption, not having an option for plain text is highly centralizing in itself. This is because the current status quo for encryption is to use TLS based on certificate authorities. And CAs are always highly centralized and highly centralizing. If Lets Encrypt ever goes corrupt like dot Org did it would cause an incredible amount of trouble and that entity would have power over a large portion of the web, if not the entire internet. There's an easy solution to this though. Don't throw alway plain protocls. Plain and TLS wrapped are synergistic. Use both. There's no need for, and it is damaging, to always encrypt without an option for plain text. A hypothetical downgrade attack is not an excuse for using only highly centralized TLS CA based protocols in this context.
- gefhfff 5y agoEncryption does not imply authentication, does it?
- superkuh 5y agoBrowsers scaremonger really hard about self-signed SSL certs. And browsers are starting to implement HTTPS only as a default. It won't be too long before HTTP is blocked by mega-corp browsers and not having a CA TLS cert means your website is now un-visitable by non-technical people (and not indexed by search engines).
- midasuni 5y agoThe concern about http over https is that a bad actor can intercept and change traffic. If you allow self signed certificates, anyone who can MITM traffic can masquerade your site just like with http Self signed does however stop passive fibre taps - to intercept you need to MITM. There then the “remember this cert” option. If I visit www.selfsigned.com on a secure network, my browser remembers the certificate. If I then travel to another network with a MITM, my browser can flag up a warning. This is how SSH works. However I’m not too concerned by SSL certificates as a centralised point - my browser trusts dozens, probably more than 100, root certificates. That’s not centralisation.
- mistrial9 5y agothis seems to be a well-known list of trusted Certificate Authorities https://ccadb-public.secure.force.com/mozilla/CAInformationReport https://ccadb-public.secure.force.com/mozilla/CAInformationR...
- immibis 5y agoSelf-signed certs should be no scarier than unencrypted connections. If self-signed certs are allowed then you can have a case for banning unencrypted connections - the way Mozilla tried to do in the past, but they didn't allow self-signed certs. If we're not going to show interstitial warning pages for HTTP-not-S sites, so you can't see if it's HTTPS without checking the address bar, then a red open padlock and a red strike through the "https" seems sufficient for self-signed HTTPS sites. Some indication is needed, otherwise you'd see the "https" and think it was secure, but the indication shouldn't be scarier than HTTP-not-S!
- AnthonyMouse 5y ago> This is because the current status quo for encryption is to use TLS based on certificate authorities. Not everything has to be TLS or even HTTP. Look at messaging apps. Signal is encrypted, but the end-to-end encryption it uses isn't TLS and doesn't use certificate authorities. > If Lets Encrypt ever goes corrupt like dot Org did it would cause an incredible amount of trouble and that entity would have power over a large portion of the web, if not the entire internet. Not really. Let's Encrypt doesn't have a monopoly over anything. They use an open protocol (ACME) that any other CA could implement. If they went evil, someone else would implement the same protocol and everybody would switch to them. Which also implies that they won't, because why bother if that's what will happen? This is kind of a problem with the CA system the other way -- if you have one bad CA they can sign any domain even if they shouldn't -- but in this case it prevents what you're worried about.
- judge2020 5y ago> that any other CA could implement. For reference, many CAs (even paid ones) have implemented it: Digicert https://docs.digicert.com/certificate-tools/Certificate-lifecycle-automation-index/acme-user-guide/ https://docs.digicert.com/certificate-tools/Certificate-life... Sectigo (formerly Comodo) https://sectigo.com/resource-library/sectigo-adds-acme-protocol-support-in-certificate-manager-platform-to-automate-ssl-lifecycle-management https://sectigo.com/resource-library/sectigo-adds-acme-proto...
- judge2020 5y ago> if you have one bad CA they can sign any domain even if they shouldn't -- but in this case it prevents what you're worried about. This is why certificate transparency is a thing and most browsers require it for public internet domains[0,1]. 0: https://chromium.googlesource.com/chromium/src/+/refs/heads/main/net/docs/certificate-transparency.md#Chrome-Policies https://chromium.googlesource.com/chromium/src/+/refs/heads/... 1: https://support.apple.com/en-us/HT205280 https://support.apple.com/en-us/HT205280
- immibis 5y agoI'm surprised if Signal doesn't use TLS, considering that Android tries to force apps to always use TLS, which is because of the point the parent comment is making.
- foxfluff 5y agoLE also forces you to rely on DNS, which is highly centralized..
- xxpor 5y agoWhat CA doesn't?
- hackmiester 5y agoI don't think it was meant as a criticism, just a statement of the current status quo, which is inherently rooted in the centralized DNS.
- foxfluff 5y agoThere are many CAs that give certs for IPs. LE won't. Not that it's much better. IPs are still granted to you by someone in a centralized hierarchy.
- deleted 5y ago[deleted]
- midasuni 5y agoHow is DNS centralised?
- judge2020 5y agoAll roads lead to . [0], ie. IANA. Many IANA-approved entities run them[1], but they all only resolve TLDs ICANN authorizes (and those TLD operators control what domains are registered under their TLD, of course). 0: https://dns.google/query?name=.&rr_type=NS&ecs= https://dns.google/query?name=.&rr_type=NS&ecs= 1: https://www.iana.org/domains/root/servers https://www.iana.org/domains/root/servers
- im3w1l 5y agoWell on a technical level there are root servers. But DNS is a hierarchy and so if the root servers ever tried to pull a fast one there are second-in-command authorities that could take over: the cctld orgs. People would rather follow their lead than ICANN, so they have the real power. I'm pretty sure this is by design.
- nathias 5y ago> Some protocols require the introduction of centralization risk that is unavoidable by nature. For example, when there is a need a single, globally coordinated 'source of truth', that facility is by nature centralized. No, there is nothing unavoidable in making a centralized DNS system.
- ggm 5y agoYou convert a single point of truth to a set of the point of truth and a voting system. The current cryptographically signed model uses a single signing authority. I suppose you could argue for multiple independent signing but it begs the question how you arrived at what was to be signed. That's a process to a unitary decision.
- deleted 5y ago[deleted]
- AnthonyMouse 5y agoRight. Even putting aside blockchain-based systems, you can have systems without a dictator because they're based on voting. Suppose the root is a set of public keys, each with a top level domain. Adding one requires a supermajority of the others to agree. Removing one is impossible; it can sign its own successor and that's it. You now have a federated system with no single chokepoint.
- mindslight 5y agoI'd say blockchain naming and the system you describe are still both centralized. The authorities are distributed, but they're still collectively responsible for deciding on a single coherent root. Compare with systems that don't revolve around making any coherent global view, like Petnames. In the context of Zooko's triangle - do the human readable name lookup once as part of a manual process, and then persist the relationship as decentralized/secure but not human-readable.
- notriddle 5y ago> because they're based on voting All voting systems require protection against Sybil attacks. The best methods to protect against Sybil attacks are centralized. The not-best methods use proof of work, which has extreme downsides and only makes Sybil attacks expensive, not impossible.
- gefhfff 5y agoA recent example is "Message Layer Security". While Wire and Matrix are working on a decentralized version the IETF is, unfortunately, working towards one based on a central entity. Source: https://news.ycombinator.com/item?id=25102916 https://news.ycombinator.com/item?id=25102916 https://matrix.org/blog/2021/06/25/this-week-in-matrix-2021-06-25#new-paper-key-agreement-for-decentralized-secure-group-messaging-with-strong-security-guarantees https://matrix.org/blog/2021/06/25/this-week-in-matrix-2021-...
- rvz 5y agoInteresting to see Wire, and Matrix making an effort in this. Unlike Signal which still requires your phone number and is completely centralized to their servers whist promoting their 85% pre-mined cryptocurrency that they can dump at any time.
- deleted 5y ago[deleted]
- Arathorn 5y agoAs far as we know, the Wire version is still logically centralised, using a centralised sequencing server. On the Matrix side we’re working on fully decentralising it (as per https://matrix.uhoreg.ca/mls/ordering.html https://matrix.uhoreg.ca/mls/ordering.html). There’s also a cool similar project from Matthew Weidner: https://dl.acm.org/doi/10.1145/3460120.3484542 https://dl.acm.org/doi/10.1145/3460120.3484542 It’s a bit perplexing that mnot’s draft cites XMPP as decentralised, given MUCs are very much centralised to a single provider which entirely controls that conversation, and if that provider goes down the conversation is dead. But I guess that’s because XMPP is submitted to the IETF, and Matrix isn’t yet.
- zaik 5y agoXMPP is still a decentralized protocol by design. That you can't send messages to a conference hosted on a server that is offline doesn't make it 'centralized'.
- walrus01 5y ago1970: we're going to build an unbreakable worldwide network to survive a nuclear war 2021: AWS and amazon US-EAST-1 is down, this means my coffee maker doesn't work
- acdha 5y agoSource: https://twitter.com/VessOnSecurity/status/1468457819296968705 https://twitter.com/VessOnSecurity/status/146845781929696870...
- contingencies 5y agoAdded attributed original to https://github.com/globalcitizen/taoup https://github.com/globalcitizen/taoup
- deleted 5y ago[deleted]
- betterunix2 5y agoUh... 1970: Early networks suffered from congestive collapse problems, routing protocols were slow to converge, computed suboptimal routes, and had count-to-infinity problems, only a handful of transit networks existed, domain names were managed by one dude broadcasting a file to everyone, little to no security infrastructure, etc. 2021: We have robust congestion control and queue management, scalable routing protocols that find optimal routes and have no count-to-infinity problems, DNS, large numbers of transit networks with a high level of redundancy, and at least some security infrastructure in key places (DNSSEC, RPKI, etc.). Don't confuse web infrastructure and hosting services with the Internet itself, which is the network and which has never been more distributed or more robust than it is today.
- walrus01 5y agoIt wasn't supposed to be serious, but for anyone that's ever seen a catastrophic level3 failure as a peer or large customer of AS3356... It's less resilient than you think. There are way too many eggs in one basket in some places.
- walrus01 5y agoSomething not really covered is this concept: "Maybe don't let one telecom company acquire too much control". Look at the history of everything that was acquired by either Qwest/CenturyLink or Level3, and then the merger of Level3. You can't tell me that the existence of Lumen, the combined Centurylink-Level3 entity is good for anyone, except for their shareholders. It's the very definition of too much centralization. Look at all of the things that have now been jammed together into the modern Verizon, as well. Look at the sad state of competition in Canada, with Rogers and Shaw trying to merge.
- FridayoLeary 5y agoIs it? In the UK BT owns all the wires and stuff yet i don't think it majorly affects consumers, nor are their competitiors being crushed.
- cortesoft 5y agoDepends on how heavily regulated it is
- gerdesj 5y agoSee if you can find our ENUM registry and use it. BT doesn't own our wires as such. OpenReach does (yes they were formally BT but spinned off). BT or OpenReach - who cares? The important thing is functionality. I'd like to provide you with a novel telephony setup but the lack of ENUM means I am not able to do that.
- M2Ys4U 5y ago>BT doesn't own our wires as such. OpenReach does (yes they were formally BT but spinned off). Openreach are a wholly-owned subsidiary of BT, they're not really independent.
- ssss11 5y agoThere are a couple of others who own wires but really only in London (colt, forget the other one) BT retail (the arm that sells to clients) has strict rules that forbid it from sharing with BT wholesale (the arm that sells to the other ISPs) so BT retail really can’t crush the competitors.. I don’t know the exact arrangement but they’re treated like any other ISP customer I believe
- betterunix2 5y ago"Internet routing requires addresses to be allocated uniquely, but if the addressing function were captured by a single government or company" Technically it is so captured -- IANA is the root of the hierarchy that distributes both IP address assignments and ASN assignments -- and the RIRs are effectively centralized authorities in their regions. Thus far it has not been a problem. With a larger address space and longer ASNs you could decentralize the entire process. Basically, subnets and ASNs would be hashes of public keys, and you would use a path-vector protocol where the NLRIs contain NIZKs proving knowledge of the secret keys and asserting who the NLRI was sent to at each hop (identified by ASN). It is not current being considered because (1) it would greatly increase the cost of routers and related infrastructure and (2) thus far there is no immediate need.
- user_named 5y agoI think centralization is just a property of reality. Everything is centralized. Crypto is centralized in certain ways (mining capacity, holdings), capital is centralized to the top 0.1% in every country and so on. It is better to design systems to handle centralization than with the assumption that they will remain decentralized, which would sort of break them.
- __MatrixMan__ 5y agoI disagree. As just one counterexample, consider the mycorrhizal fungal networks that mediate access to nutrients among trees--they've been doing their job without centralized intervention for billions of years. If it seems like everything that we build is centralized, it might just be that we're bad at building things that last.
- quinnjh 5y agoOr bad at building things that decompose...
- meheleventyone 5y agoLike the Internet? I actually think we could be good at building these sorts of things if we let go of the profit motive for doing so. History shows that we have been.
- user_named 5y agoThe tree is the center.
- __MatrixMan__ 5y agoThese networks handle the exchange of resources (nitrogen, phosphorous, etc) between trees. So far as I know, there's no reason to believe that there's a "leader tree" or anything like that.
- meheleventyone 5y agoThis is something touched on by The Tyranny of Structurelessness and further confirmed by the way companies with a flat internal hierarchy operate. Where there is decentralisation there is implicit power relationships and in the terms of the root essay here platform and indirect centralisation. It’s the why of democracy in anarchist organisation.
- DarthNebo 5y agoDecentralisation efforts at this point is very akin to the democratic movements from centuries ago. Governments being reluctant to entertain efforts of taking back control, most recent example being StarLink asked to stop selling in India since they aren't registered as an ISP. The whole point of satellite internet is to avoid geo-control by any government body or local ISP.
- tjohns 5y agoThe whole point of satellite Internet is to fill in connectivity gaps where you can’t otherwise run high-speed fiber or wireless towers. It does not avoid government control. Even ignoring local legalities, at the very least it will be under the physical control of whichever country hosts the nearest ground-segment station.
- quinnjh 5y agoAnd arguably exists to maintain said geocontrol
- DarthNebo 5y agoI get the connectivity point but surely you would also need unfettered internet access if you live in countries which actively censor/cripple it like Russia, China, NK etc.
- immibis 5y agoThere can be multiple ground stations.
- bullen 5y agoThey should probably add that merely adding yet another protocol centralizes things. Implementing them takes time and you need many implementations for the protocols themselves to become de-centralized. This is what breaks most new protocols and languages combined with diminishing returns (low hanging fruit has allready been harvested). Personally I'm going back to HTTP, DNS and SMTP. And even if DNS is completely centralized, it's the only thing we have for name lookups after 38 years! Also I never rely on DNS if I can avoid it (I use static IPs and only use the hostname for virtual hosting / load balancing). And de-centralization by hosting is more important than the protocol itself being p2p, since no p2p protocol can operate purely without server because of discovery. I have made my own, from scratch, implementation of all 3: DNS and SMTP soon coming to a rupy (HTTP), enabling DNS and SMTP through HTTP, you'll basically be able to control DNS and SMTP via a "Servlet/Filter". Home hosting on fiber with static IP and ports 80, 53 and 25 open is the real challenge. Making sure your ISP enables those has way higher priority than this document! And the real canary is when you don't get an external IP on your fiber when IPv4 allocations in Africa run out. It's time to wake up if we want an internet that does not become rent seeking. Google charges for static IP addresses on GCP which should not be a thing if they get allocations for free. IPv4 is a scarce asset, so they have an incentive to slow down IPv6!
- yjftsjthsd-h 5y ago> And even if DNS is completely centralized, it's the only thing we have for name lookups after 38 years! Depending on how you mean, it's not the only thing or its not 100% centralized; https://en.wikipedia.org/wiki/Alternative_DNS_root https://en.wikipedia.org/wiki/Alternative_DNS_root lists the major alternatives in that immediate space.
- tecleandor 5y ago> Google charges for static IP addresses on GCP which should not be a thing if they get allocations for free. Same as in AWS (IIRC) in Google Cloud you don't get billed for static IP addresses if they are in use: "If you reserve a static external IP address and do not assign it to a resource such as a VM instance or a forwarding rule, you are charged at a higher rate than for static and ephemeral external IP addresses that are in use. You are not charged for static external IP addresses that are assigned to forwarding rules." https://cloud.google.com/vpc/network-pricing https://cloud.google.com/vpc/network-pricing
- rapnie 5y agoIn "The Promise and Paradox of Decentralization" [0] I found this quote to be very appealing wrt decentralization: > "[A]ny decentralized order requires a centralized substrate, and the more decentralized the approach is the more important it is that you can count on the underlying system." This somewhat counterintuitive notion is often overlooked. In order to facilitate a healthy decentralization effort you need a heck of a collaborative movement to make it a reality and sustain the initiative. [0] https://www.thediff.co/p/the-promise-and-paradox-of-decentralization https://www.thediff.co/p/the-promise-and-paradox-of-decentra...
- fiatjaf 5y agoIf you read this you might be interested in this protocol which started as an idea for truly censorship-resistance Twitter but it's evolving into a generic suite of many subprotocols that involve interaction between users. https://github.com/fiatjaf/nostr https://github.com/fiatjaf/nostr Kinda like the "fediverse", but improved in the sense that it is not federated, but also not P2P (because pure p2p doesn't scale).
- fouc 5y agoAvoiding Internet Centralization means.. avoiding browser centralization.. means avoiding the dominant browser stack (currently chrome-based).. means avoiding browser auto-updates.. means discouraging user agent strings & browser/os version fingerprinting.. means avoiding cloudflare..
- dustymcp 5y agoBut hey those are some of the brogrammers favorite things??
- qnsi 5y agoisnt it ironic it was posted on github?