4 ms·
Author here - thanks for the post! A little more background info for my fellow HN people: I've spent that last 8 years building privacy technology at Safing a
by dhaavi 1y ago
Author here - thanks for the post!
A little more background info for my fellow HN people:
I've spent that last 8 years building privacy technology at Safing as Co-Founder/CTO. The biggest technological achievement there was undoubtedly the SPN (previously called Port17/Gate17): A privacy network (ie. a layer-5 proxy), fitting in the niche between VPNs and Tor. Impossible to misconfigure, good speeds and way superior privacy to VPNs using onion encryption and decoupled authentication/authorization. Funnily enough, this (decoupled auth) is what was later implemented by Apple Private Relay and Google One VPN.
SPN worked great for the most part, but scaling was hard. With the decision to make it a layer-5 proxy for decreased metadata and improved privacy, this meant that also traffic and congestion control had to be re-implemented - no easy feat, and still causing issues.
Meanwhile, I have followed and read a lot about cjdns and Yggdrasil over the past few years and was intrigued by their ideas how to do networking.
After some interesting talks in November 2023, I was at the point where I just wanted to know how far I would get - with all the experience and knowledge I had up to that point - implementing a scalable layer-3 mesh network, that still allowed for some privacy and full security. I spent most evenings of a couple months building it and was surprised how well it went.
Sadly, after a decent MVP and a first friend using it in small scale production, I did not have the time to work on it further.
But I am currently starting a new project, where I will make good use of it, so it will see quite some more development in the coming years!
So, Mycoria works, at least on small scale for now, but is more or less MVP.
Thanks for reading, I hope you have fun poking around and trying it out!
I am also happy to answer any questions you have here!
- tornadofart 1y agoGreat technical achievement. What is, for you, the sweet spot between VPN and TOR? What's the tradeoff there?
- dhaavi 1y agoIf you want Tor for your _whole_ existing system, not just the browser, good luck. If you want actually good privacy with a VPN, also good luck with that. (There are very few good companies doing the best they can here, but they are still limited technologically.) SPN can be seen as my attempt to solve both of these issues.
- nlitened 1y agoSo, what are the tradeoffs? In some ways it’s better than both VPNs and Tor — but in what ways it’s worse?
- dhaavi 1y agoWell, it is in the middle: Not as fast as a VPN, not as private as Tor.
- synctext 1y agoImpressive design! Are you assuming bandwidth is free and abundant? Mycoria routers, proxies, Tor exit nodes, and VPNs are difficult to run. There needs to be an global incentive, economy, or private community usually. Our Delft University students wrote "The fifteen year struggle of decentralizing privacy-enhancing technology" a decade ago. Scaling to many millions or billions is unsolved. Have you talked to any lawyer or law professor about your MVP? "Being welcome" has known drawbacks when you operate a central DNS service.
- dhaavi 1y agoThanks! Well, every participant has to cover their own server/bandwidth cost. So, from my perspective, yes, bandwidth is free and abundant. Although I hope that Mycoria can/will perform well in lower bandwidth areas. Interesting. Can you link that paper/article? The DNS is not central. Everyone maintains their own local mapping. When accessing a website on mycoria, you open a URL like this that first creates the mapping and then forwards you to it: http://router.myco/open/speedtest.de.myco/fd13:6239:a07a:eb46:2d51:52f:d4e1:6d0c/ http://router.myco/open/speedtest.de.myco/fd13:6239:a07a:eb4...
- aspenmayer 1y ago> Can you link that paper/article? I'm not who you asked, but this appears to be the article: https://arxiv.org/abs/1404.4818 https://arxiv.org/abs/1404.4818
- lifty 1y agoLove the inspiration from Yggdrasil with the hashed key -> IP concept. How do you enforce the geographical part? And what do you use from transport? WireGuard?
- dhaavi 1y agoGeographical: No enforcement, but if you choose the wrong country, packets will have issues reaching you, because routing is "bucketed" into layers of regions. Routers only hold the bext x routes to each bucket. Transport is custom in order to support source routing, but I use the WireGuard library for setting up the interface and such. (I have experience with cryptography in network protocols from Safing/SPN - the cryptography of which was audited without fault. Also, I am _very_ cautious and keep to standards as close as possible.)
- evbogue 1y agoMaybe there's a way to offset this risk by testing the speed of connections? How does peer discovery work? Where do the region buckets live?
- dhaavi 1y agoLatency is considered in routing. Every router announces itself on the network. Routers can optionally publish their IANA IP addresses. Buckets live on the routers themselves.
- irq-1 1y agoCities with significant internet POPs would be better than countries. 1. You control the list of locations (so Singapore not Brunei.) 2. People can easily choose from a list of cities. 3. Latency tests could make it a non-issue. 4. Local connections in semi-isolated areas (think antarctic or islands in the south pacific) can be identified by people with a config.
- dhaavi 1y agoInteresting idea - thanks! Will think about this more.
- teleforce 1y agoHi Dhaavi, Mycoria looks very promising and it reminded me of the early days of peer-to-peer system with Napster and Gnutella [1]. Any specific reason why you didn't use the standard based segment routing for source routing support, that can be adopted at layer 3 instead of custom layer 4 transport [2]? For security analysis did you use BAN logic and ProVerif tool for verification [3], [4]? [1] Gnutella: https://en.wikipedia.org/wiki/Gnutella https://en.wikipedia.org/wiki/Gnutella [2] Segment routing: https://en.wikipedia.org/wiki/Segment_routing https://en.wikipedia.org/wiki/Segment_routing [3] Burrows–Abadi–Needham (BAN) logic: https://en.wikipedia.org/wiki/Burrows%E2%80%93Abadi%E2%80%93Needham_logic https://en.wikipedia.org/wiki/Burrows%E2%80%93Abadi%E2%80%93... [4] ProVerif: https://en.wikipedia.org/wiki/ProVerif https://en.wikipedia.org/wiki/ProVerif
- dhaavi 1y agoThanks! I wasn't really aware segment routing, tbh. However, I do think with where Mycoria is going, the additional control to change things as needed will be required. I have used VerifPal https://verifpal.com/ https://verifpal.com/ for security analysis before, but not yet with Mycoria.
- Spackonewz 1y ago[flagged]
- kahicks 1y ago>WP has so many issues with both its data, and their governance. Indeed. See "Canceling Disputes": https://www.cambridge.org/core/services/aop-cambridge-core/content/view/91BEE9C7E89DE234777B6FF04E82C1B9/S0897654623000151a.pdf https://www.cambridge.org/core/services/aop-cambridge-core/c.... Here are some non-Wiki links: Gnutella: https://computer.howstuffworks.com/file-sharing.htm https://computer.howstuffworks.com/file-sharing.htm Segment routing: https://www.segment-routing.net/ https://www.segment-routing.net/ BAN Logic: https://www.cdk5.net/security/Ed2/BANLogic.pdf https://www.cdk5.net/security/Ed2/BANLogic.pdf and ProVerif: https://bblanche.gitlabpages.inria.fr/proverif/ https://bblanche.gitlabpages.inria.fr/proverif/
- 1y ago
- mhitza 1y agoI've only read your landing page, so I don't fully understand the technical part yet. Can you do a comparison with I2P?
- leobuskin 1y agoI apologize, wasn't clear from the documentation: router's IPv6-like address is a fingerprint of the public key, but does it also encode geo-prefix and distance (I mean, it's hypothetically doable, I'm curious what's the approach if it is)? or the router's address has no metadata encoded, and only end-user addresses are encoded this way?
- dhaavi 1y agoMycoria brute forces a public key/IP pair until it matches the desired geo-prefix.
- dfc 1y agoI am a little confused how the geo encoded addresses and private addresses work. It seems like the network will be overwhelmed with keeping track of switch labels?
- dhaavi 1y agoSwitch labels are effectively interface IDs on the servers, there is no data to be stored. Geo encoding simply improves routing to unknown routers, kind of as a baseline structure to the whole network.
- notepad0x90 1y agoHi Dhaavi, this looks like a great project and your vision for it is excellent. But the consistent theme I see with similar solutions is that they ignore the commercial aspect of such solutions. I don't know if you have mass adaption in mind, but the more people use it, I would presume the privacy and anonymity properties would improve? If so, then have you considered introducing participation incentives (financial or not)? That seems to be the critical problem in this space that needs solving, standardized anonymous payment for infrastructure service providers in the network.
- dhaavi 1y agoCurrently, this is just a fun project for me. I have technical ideas, but I don't have growths plans or the like - and it is nice that it does not have to. Yes, I would expect the privacy would increase by some degree with more users, but I don't know by how much. Although I will be using the technology in future projects, so Mycoria will benefit from that.
- atemerev 1y agoSo basically Mycoria IP addresses/keys leak information about your geographical location?
- dhaavi 1y agoJust like the Internet we currently have, albeit less accurate, but more stable. See https://github.com/mycoria/mycoria/blob/master/m/geo_marker.go https://github.com/mycoria/mycoria/blob/master/m/geo_marker.... In the future, non-routable private addresses will solve that for users that require it.
- yubblegum 1y ago"services: - name: my-service # This is your service url: 'http://my-service.myco/ http://my-service.myco/' # For service listening on 0.0.0.0:80 friends: true friends: - name: alice # This is your laptop ip: fd1f:2cd5:6feb:7aa7:d674:1b3c:c82c:dfc" May I suggest r/friend/peer. This is not motivated by pedantry. Relational semantics that are not closed over by the domain of user-agent (in the broadest sense) should not be used in the infrastructure layer. My laptop's server is a user-agent of mine as is the instance running on my phone; they are peers. Applications built on top of this substrate will be (generally) concerned with social relationships of users and 'friend' et al. will be of use in those layers.
- dhaavi 1y agoThanks for the feedback. I will re-evaluate.
- LoganDark 1y agoPortmaster and the SPN were great, back when we used Windows! We just wish there were that sort of stuff for macOS - sure Private Relay exists, but it only works in a few first-party apps like Safari, and you never know if it's working or not, and can't force traffic to only be through it.