4 ms·
While the project is interesting from a technical perspective, there are some serious issues. The main implementation has a vague, non-standard licence, but thi
by Klaus23 2mo ago
While the project is interesting from a technical perspective, there are some serious issues. The main implementation has a vague, non-standard licence, but this is not overly problematic as alternative implementations can simply be used instead. A bigger problem with Reticulum is that it does not appear to offer robust protection against abuse. Messages are protected by cryptography, but there are many other ways to render a network unusable, which will inevitably happen on a larger scale.
- jijijijij 2mo agoWhat's exactly the criticism you got? What do you miss?
- RiverCrochet 2mo agoAny publicly accessible protocol, such as Ethernet (wired and wireless) can only do so much to prevent DoS/DDoS on a given open multiple access medium. You can certainly bake in fairness, congestion control, etc. in the protocol level, but protocols require 2 participants to follow rules/spec to work, and if one side doesn't follow the rules/spec, at the very least some bandwidth will be consumed. The only way to absolutely prevent DoS/DDoS is to have more bandwidth than all possible simultaneous attackers, or limit physical access to the medium. Cellular networks, for example, keep direct physical access to its medium under tight lock and key through proprietary, non-open-source baseband firmware.
- Klaus23 2mo agoOf course, you can't protect against all types of abuse perfectly, and an attacker will always be able to degrade the network to some extent. However, I fear that a larger Reticulum network would become unusable if an attacker put in even a modicum of effort. You could whitelist everything, but then the project would lose its core goal of being a free network.
- Panda_ 2mo ago> robust protection against abuse I would say it has a fairly reasonable number of protections with things like being able to prioritise certain interfaces and controlling the announce rate from a node and rate limiting the number of announces a destination makes. What in particular is abusable?
- Klaus23 2mo agoI can't see any effective protection against the classic tactic of flooding the network. There are some defences in place, but they seem easily overcome with minimal effort. If everything has to be whitelisted, the project would lose its core goal of being a free network.
- Panda_ 2mo agoThere's a thread by the author of Reticulum [1] on recent flooding attempts of weird clients connecting, spamming path requests and leaving, and attempting to mitigate their impact on the nodes. Yeah it seems like you are in fact right... [1] https://rns.recipes/forum/general/rns-150-testing-traffic-prioritization-stability-improvements https://rns.recipes/forum/general/rns-150-testing-traffic-pr...
- Klaus23 2mo agoSo it has already begun. It's kind of sad/impressive how every single network or group project gets flooded with abuse as soon as it gains any tiny bit of attention.