6 ms·
Pirate Bay Moves to The Cloud, Becomes Raid-Proof
- mariusmg 14y agoIsn't it enough to take down the DNS servers to make TPB unusable for sharing (at least to add new torrents) ? Achieving fault tolerance using a few cloud providers is nice (and expensive) but they're still far from raid proof (all it takes is some coordination from police in multiple countries).
- kennu 14y agoAccording to the article the main vulnerability would be the load-balancer, which is hosted separately. Traffic between it and the cloud instances is encrypted, so that the cloud providers don't actually know they're hosting The Pirate Bay.
- moe 14y agoso that the cloud providers don't actually know they're hosting The Pirate Bay. When the IP addresses of the 'loadbalancers' are known then it takes any cloud-provider the better part of 5 minutes to determine which of their instances are exchanging how much traffic with those IP addresses. However, if a country really wants to go ballistic on TPB then it'd be much easier to just knock their public-facing IPs out at the IX-level[1]. A fairly low-cost operation (if your legislation enables it) and the only circumvention is then to proxy through a different country - a significant barrier for most users. [1] http://en.wikipedia.org/wiki/List_of_Internet_exchange_points_by_size http://en.wikipedia.org/wiki/List_of_Internet_exchange_point...
- solnyshok 14y agowhile I hope this never happens, it might finally give impetus to p2p wireless darknet/shadownet/rebelnet... Whatever they will call it then
- fragmede 14y agoIt's an increasingly technical digital game of whack-a-mole, and the mole has completed another burrow. There are still technical measures that could be taken with-in one country. Eg. automated null-routing of A records for thepiratebase.se (and then do it N-times a second).
- jacquesm 14y agoAll it takes is for some political body to lean heavily enough on the TLD registry. .se and .org are no more invulnerable to this than .com
- rmc 14y agoPerhaps. And that's why you have many TLDs. So .se and .org are gone, so it moves somewhere else, then it moves again.
- chii 14y agoI think somehow the MAAFIA is going to manage to get laws passed which will null out any set of words they like in the registry without prior notice. This would mean the end of DNS as we know it i guess. Or stipulate that DNS services reveal those who registered and then can prosecute along those lines.
- Toshio 14y agoIn the case of a DNS takedown, all it would take would be for The Pirate Bay to publish a browser extension that stores a few IP addresses and "drops in" whenever the user attempts to acces thepiratebay.se.
- chimeracoder 14y agoSavvy users in parts of Europe (Denmark, I believe) are already just adding an /etc/hosts entry to do exactly this. That doesn't solve the problem of the IP address itself changing, but then you need some system of distributing the updated IP addresses whenever they change. Which would require inventing a distributed lookup system....hmm... this is starting to sound familiar....!
- sgt 14y agoUnless they raid the cloud...?
- rmc 14y ago(a) You have to find out what cloud provider (b) You have to raid 2 cloud providers (c) what if they have 4 backup cloud installs ready to go live? You take out the 2 there, and then 2 more in a different, unknown hosting company go live.
- Achshar 14y agoAlso they don't get any useful data as all data on cloud providers is encrypted. So providers won't even know they are hosting piratebay.
- peterwwillis 14y agoWho told you that? Any cloud provider can at any time inspect what's running inside a guest, so they'll definitely know it's piratebay (not to mention the metric fuckton of obscure network traffic that make torrents easy to spot). As far as data, cloud providers usually have functions to administrate guest VMs, which would allow a law enforcement agency to peer into the box as well, nullifying any benefit of data encryption while the box was online.
- mayneack 14y agoI may be misinterpreting your comment, but the massive amounts of data associated with torrents don't actually go through the trackers. The trackers just manage peers while the data goes directly from one user to another. (or at least that's how I understood it)
- jlgreco 14y agoTPB doesn't even run trackers anymore. My impression is that these servers only serve up magnet links (not even torrent files) and textual descriptions of them. Provided they spread it out even a little, nothing about that traffic should appear out of the ordinary.
- maeon3 14y agoIt's like robin hood taking from the rich and giving to the poor, his motives are pure, depending on how you look at it, and robin hood can continue this as long as the governing body who wants him dead is inept at catching him. The pirate bay, like robin hood, cannot live forever. SOME of us will only be stronger than ALL of us for brief moments in history. The only way TPB is to survive is for it to make good on its invisibility promise and make both the users and and distributors invisible to those who want it dead. There needs to be a creative mechanism to render the service invisible to those who disagree with its existence, and to render it visible to those who crave data. It won't matter that TPB is distributed, clouded, encrypted, PTP, or whatever. When the governments are successful in getting SOPA, ACTA or whatever through congress, the ISP's and companies like Google and Apple are going to be made responsible for cooking into their devices preventions for unauthorized copying and unauthorized distribution of 3d schematics for weapons that pass through their ISP's or their hardware. As elite as TPB thinks they are, a few elite hackers can't fight an army of mediocre hackers. An important factor in TPB living forever is preserving its image in the hearts and minds of ALL hackers everywhere, worldwide, collectively we can outsmart those who wish to catch us, a small group of us will eventually be defeated, as all robin hoods must be. We have to have the hackers on the ground floor who wish TPB to live forever inside Google, Comcast, Apple, HP, MPAA, RIAA, and everywhere else. The battle for control what you can think, what you can do inside the comfort of your own mind is under attack. The battle begins here, with the ownership of what can take place in your computer. Soon these computers will be our minds, and the governments will rule over the thoughts that take place inside them. We will wake up as directive following slaves on the land our fathers conquered. We have to have a 10 and a 50 year plan.
- gambiting 14y agoAnd then they will move exclusively to TOR. And then TOR will be outlawed and anybody using it will be sentenced to 20 years in prison.
- S4M 14y agoIt's gonna be hard to identify who is usung TOR, and doing so will require to take measures that will be against freedom, like controlling what people are installing on their computers.
- arocks 14y agoSo we can expect Cloud Computing Regulations to be framed later this year?
- m0skit0 14y agoNice article, I absolutely agree!
- smogzer 14y agoThey have to do it like this: - emule like dht. - keep a cache of 1000 of ips that had trustworthy content in different ip neighbourhoods. - provide a pub-sub of new content + hot/top files. - seed one-to-download one file. Host encrypted content, freenet style to have faster speeds on other files. Never allowing a file to go seedless. - the software could be provided as a chrome+firefox sandboxed addon or something like that. Go hackers go.
- chii 14y agobasically, truly distributed DNS servers, where your domain name->ip maps are shared and voted on iteratively and continuously. Its synonymous with bitcoin in that sense, where the only way to break it is to have control of X% of the computers involved in the entire cluster (and then make X a really high percentage so that it costs prohibitively high to undermine the system).
- jdangu 14y agoCheck out NameCoin http://dot-bit.org/Main_Page http://dot-bit.org/Main_Page
- dhx 14y agoand even in the event they [cloud providers] found out it would be impossible for them to gather data on the users. The encryption key that is providing disk encryption on the VM instances would be accessible to the VM host. The VM host could also directly access the memory of the VM instances to read the disk cache, etc.
- chii 14y agoI think that quote was made because the writer was confused about what happens during live operation, and what happens during the time when communication was cut. The host could potentially sniff the traffic during live operation by sniffing the memory of the vm. But when the vm's communication is cut, the whole disk is encrypted. I expect this encryption to be done using some sort of public/private key encryption scheme, such that without the private key, you can't actually unencrypt the disk. THis is what is meant by gathering data on the user i suspect.
- ianburrell 14y agoWith whole disk encryption, the disk is always encrypted. While running, the decryption key is stored in memory and used to decrypt/encrypt blocks. When communication is cut, they are presumably purging the key from memory. The password would need to be entered to produce the key. This means that while the system is running, the key can be read by the host. It doesn't matter is the key is later purged. Changing the key requires re-encrypting the entire disk which is a slow operation.
- chii 14y agoI guess there isn't enough detail to raelly work out what would happen - its not clear that they meant whole disk encryption in the way you described. I thought they encrypt the disk _only_ after loss of communications. The private key is not on the VM anywhere. Thus, the vm once encrypted, is useless (without the passphrase, which presumably only exist in the head of the operator of tpb).
- zllak 14y agoSomething that could be "funny", if that governments, when they don't understand something, they just call it outlaw/illegal, as they almost did for P2P. That's not because someone make a bad use of something that the whole thing must be considered as dangerous. How long before the "cloud" is declared illegal by governments ? :)
- antidoh 14y agoThey could require licenses, so that corporations can make money while individuals have less freedom.
- cake 14y agoAny more info on the encrypted VMs and how they work ? Do they use TrueCrypt volumes ? What are the alternatives ?
- alz 14y agohow do they manage their databases, this would be interesting if the system is truely distributed
- Fando 14y agoLong Live The Pirate Bay - An icon of revolution and internet freedom!