5 ms·
What's wrong with bitmessage?
by tocomment 13y ago
What's wrong with bitmessage?
- dochtman 13y agoOnly solves a subset of the email problem, IIUC.
- wyager 13y agoWhat's missing? I was very skeptical about Bitmessage, but it totally surpassed my expectations when I tried it.
- boyter 13y agoThe biggest issue is missing messages. You essentially have to have it running all the time to get your "mail", otherwise you miss out on all of the resend windows. I love the idea of bitmessage, but this issue is a major problem.
- nwh 13y agoBitmessage doesn't scale, it's POW doesn't solve any spam problems, and it's largely insecure. There's been quite a lot of public discussion about just how hilariously insecure it is.
- tocomment 13y agoI didn't know that. Is anyone working on an improved version? It seems like a great idea in principle.
- nwh 13y agoThere's room for improvement, but there's a lot of core issues that just can't be flushed out. The concept of the POW is to stop spam, as all addresses are inevitably public, it doesn't really work though, as spammers typically have access to botnets which can spam all day long. Normal users just have to wait minutes to send a message. The scale issue is a weird one, they plan to split the network into different "streams" with different address types, which just sort of muddles the entire setup. Ultimately the limit is how much CPU and bandwidth the network can survive with while mirroring the entire content of the entire network. There's lots of problems with timing attacks that have been "resolved" with random sleeps, though nobody is really convinced of that too much.
- sirsar 13y ago>The concept of the POW is to stop spam Your other points are good, but this one is wrong. Bitmessage is currently bundled with a client because that makes adoption easier, but ultimately, Bitmessage is first and foremost a protocol. POW increases the cost of flooding attacks on the network. Clients like Thunderbird (it was easier for me to integrate Bitmessage with Thunderbird than my regular email provider) stop spam. The scaling is a rather hard problem, since, for anonymity, "everyone gets everything." If you have any ideas about how to scale a network like that, OR have any comparable methods for hindering traffic analysis, you should publicize them. The timing attack mitigation via sleeps /is/ a rather ineffective substitute for constant-time decryption. In summary: 1. POW is a non-issue, and part of the design at least the way you've put it. 2. Scaling is inevitable given the tradeoffs being made, unless you have a better idea, for which I will pay money 3. Timing attacks are a temporary problem, but they can certainly be "flushed out."
- banachtarski 13y agoIt's not a great idea in principle at all. It should have been obvious that it wouldn't scale from the beginning by design.
- hnha 13y agolinks please
- tocomment 13y agoHere's the wiki page: http://en.wikipedia.org/wiki/Bitmessage http://en.wikipedia.org/wiki/Bitmessage