12 ms·
OkTurtles + DNSNMC: Surveillance-free communication on your favorite websites
- mknits 13y agoSo, it seems it's a PGP-based technique? Good.
- orenbarzilai 13y agoimho bitcoins technology is amazing and and the near future we will see a lot of new products, such as this one, that are built on bitcoin technology but aren't related to bitcoins.
- chippy 13y agoYou know, at the moment for me it feels as if this is exciting as if its on the cusp of something great but I'm not sure what it is or how to put it into words. Could you explain why it's amazing?
- SectioAurea 13y agoI too have this feeling, and made a post about possibilities for traditional state functions in the blockchain: http://www.wallstreetcrypto.com/2013/12/distributed-anonymous-government-fourth.html http://www.wallstreetcrypto.com/2013/12/distributed-anonymou... It's a very fuzzy concept for now, but I'm sure someone will come along and articulate it better.
- 97-109-107 13y agoI'm really happy to see this here; I've tried to build a tool based on the very similar concept - initially just as a chrome plugin (I do see the irony), but ran out of time, enthusiasm. http://kaniowski.info/umshade/ http://kaniowski.info/umshade/ Good luck, really want to see this getting popular
- Nux 13y agoI'd LOVE for something like this to take off.
- zobzu 13y ago-----BEGIN PGP MESSAGE----- Version: GnuPG v2.0.22 (GNU/Linux) hQEMA/H221DfyGXJAQf+IDMe33H8hz1MgYfqxGta/FauUinOWtXqT+xskkGtt+es wRE1stgcJeKlzFDMHMS99Cvfw1qUis+CMVUnrBJw3yn1tdNo3FV+V0BgMIJwTPGS nkHxeXsxHXcsgcyRhB1PEO2arPaiek9xqxwUehnsDHI8T6oAJaUhteNHo72ybM4S Q1vSY8/Ni6t7Uk5zjpsHPq+Jhi7+QA9L1xaJuNBcm1lQxE2hWyrdXRB7N+HMnvJR LMgZndBjoKeui032cbIV8z/N7n2YT8Vtx0syVkDT0KppcW4EcQyAp6hbRPrgnUMu jDLLwT1xSgPwtH8NPo0iuusGmONa+stGGmjwHnhiLNJxAZWGQM36uE+FA9bXUVDl ikp29kE8qmCijPIHSDUny6SiNUjrEJeQEBq4TJpU7GDEsOQKx2tjchOZyWQFpKWK mBPnU6H9uAAByM+t+ejG5lxxlp/R9eKBs+YSf7QT7H2sLR/KIwyuXNJg+oHBtzKY weo= =bZbG -----END PGP MESSAGE-----
- AlexanderDhoore 13y agoSo how do we read it? Edit: I know public key crypto... I meant: where's the key?
- coherentpony 13y agoYou need his public key to decrypt it.
- bushido 13y agoI think you mean private key. If it were public key it would not be secure at all :)
- coherentpony 13y agoNo. You need his public key. His private key should be known only by him. That said, he also needed the recipients public key to encrypt it. Private keys are private. Public keys are public. Edit: I realise this is unclear. He needs his private key and the public key of the recipient to encrypt the message. Then only the recipient can decrypt the message. To do this, the recipient needs his private key and the encryptor's public key. Hope that helps.
- jnbiche 13y ago
- swombat 13y agoWebsite lacks a summary of what this does exactly and how, other than "add turtle buttons that do magic encryption voodoo" - or did I miss it somehow?
- deleted 13y ago[deleted]
- MacsHeadroom 13y agoDid you miss the prominently linked to white (ie technical) paper?
- swombat 13y agoI'm not a cryptographer, I'm a potential user. If I was up for reading white papers on this, I wouldn't be interested in having buttons shaped like turtles. What I'm asking for is a summary of what this thing actually does from a semi-literate layman's perspective...
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- jere 13y agoOh, don't worry. I don't believe the white paper is at that level. It has typos, smilies, movie references, it's clearly a work in progress, it's very short, and it's written at a high level. Clever logo by the way. http://okturtles.com/other/dnsnmc_okturtles_overview.pdf http://okturtles.com/other/dnsnmc_okturtles_overview.pdf
- alan_cx 13y agoJust clicked the link. I just see the usual lazy kit web site, and no prominently linked white paper. No, I didn't scroll or click. I just looked at where I landed. Nothing. Just standard bland marketing stuff, pushing something that comes across as snake oil. It makes fantastic claims that given what we know about the NSA and its tentacles, are very hard to take seriously. If their claim were true, I'd expect to know that straight away from the landing page, and be blown over by the storm such protection would mean. If any one really made it 100% impossible for the likes of GCHQ and the NSA to spy, all hell would break loose.
- infocollector 13y agoIf its something that will work inside gmail/facebook frontends (web ui), isn't it inherently at the mercy of google and facebook?
- deleted 13y ago[deleted]
- itistoday2 13y agoSee section "6.3 Note on JavaScript Cryptography" in the paper: http://okturtles.com/other/dnsnmc_okturtles_overview.pdf http://okturtles.com/other/dnsnmc_okturtles_overview.pdf
- salient 13y agoI'd be interested to see another comparison with DNSCurve on your page (http://okturtles.com/#DNSNMC http://okturtles.com/#DNSNMC): http://dnscurve.org/ http://dnscurve.org/ http://www.youtube.com/watch?v=K8EGA834Nok http://www.youtube.com/watch?v=K8EGA834Nok It seems Aaron Swartz has inspired so many great projects. It makes me sad that he's no longer with us from such a young age. It seems he had a lot of potential to change things for the better.
- lukifer 13y agoIt's tragic that Aaron won't be around to see (and aid) the coming wave of distributed direct democracy.
- rakoo 13y agoI'd have loved if instead of reinventing the wheel, they added support for GPG keys in web-based inputs, and distributed GPG keys in DNSNMC. GPG is already widely deployed (among the crypto-sensible people, of course), it would be sad if we had to restart from scratch. But this is still a step in the right direction.
- itistoday2 13y ago(author here): GPG support for the web can be easily done with @okTurtles, and was part of the plan from the start. It's very easy to do that compared to the rest of the goals of @okTurtles. One thing about that though, is that GPG-based communication suffers from all the problems described in the OTR docs (and the overview paper on the site, see sections on plausible deniability and PFS). But if you want it, again, it's very simple to transparently support GPG on the web (once the rest of the foundation is implemented), and I can definitely see how people would find that useful for forums, reddit, HN, etc.
- itistoday2 13y agoPlease note that the site and PDF describe two different, but related projects. DNSNMC, IMO, is actually the more significant of the two, while okTurtles is just one example of the type of app it makes possible. First draft of a complete DNSNMC specification and implementation is being worked on right now and will be pushed to https://github.com/okTurtles https://github.com/okTurtles soon. A rudimentary DNSNMC is very simple to implement in something like Nodejs. The version that will be pushed to github will be written in CoffeeScript and NodeJS. At some point my hope is to provide a version that installs easily on Linux via package managers and integrates nicely with PowerDNS.
- sillysaurus2 13y agoFrom the whitepaper http://okturtles.com/other/dnsnmc_okturtles_overview.pdf http://okturtles.com/other/dnsnmc_okturtles_overview.pdf "The magic doesn’t stop there. DNSNMC isn’t just DNS + NMC, it’s also an HTTP server. DNSNMC provides its clients with secure access to the Namecoin blockchain itself through a RESTful API." They're planning on shipping this browser extension with a hardcoded list of DNSNMC server IP addresses. Isn't that a central point of failure? (E.g. If an adversary mounts a DDoS against all servers in that list.) Adversaries wouldn't need to render the service unreachable, just slow it down to painfully-slow speeds for average users. Regular DNS is resilient to this because of its hierarchical design, but the paper seems to be proposing a flat list of DNSNMC servers that will be shipped with the extension by default. Since almost all users will stick with the defaults, subverting those servers would disrupt DNSNMC for most users. Also, it's unclear to me how users or website owners use DNSNMC's REST API to update their blockchain identity entry. Is it password-based? Like, when a user first creates a blockchain entry, do they set a password they must remember? If so, then what happens when they inevitably forget their password or someone steals it via a key logger? It needs to be changeable in case the old password is compromised, but that causes a whole bunch of problem scenarios, like an attacker steals a password then changes it, then modifies the user's blockchain entry. How does a user recover his stolen blockchain identity? Overall the whitepaper is a comprehensive survey of the current public key infrastructure landscape and embodies some interesting ideas for the future. While there are some very dubious ideas (like tackling all problems with JavaScript crypto) I'm cautiously optimistic about the overall direction this whitepaper is proposing, because something similar to this is a necessity: a distributed DNS system that doesn't rely on certificate authorities, and lets users distribute their public keys in a public way that can't be easily MITM'd. There are unsolved problems, like how users can recover a stolen identity, but this whitepaper takes care to be extremely clear that it's a work in progress, and that it's being made available to get early feedback on the design / to solicit ideas from the community. They don't pretend that they've thought of everything, which is nice. They're working on an important problem (a future in which CAs are unnecessary + giving everyone a way to distribute encryption keys tied to your public identity) so this kind of research is sorely needed, and I look forward to seeing what their next step is.
- itistoday2 13y ago
- nexttimer 13y agoI like seeing people offering solutions against mass surveillance. What I want to suggest is that you drop the requests you send to 3rd party services like Google. If somebody makes money off of collecting as much data about us as they can, it's Google, Facebook, etc. So, letting them track your users is a contradiction.
- itistoday2 13y agoWhat I want to suggest is that you drop the requests you send to 3rd party services like Google. If somebody makes money off of collecting as much data about us as they can, it's Google, Facebook, etc. So, letting them track your users is a contradiction. What are you referring to? There's no Google tracking code on the site. The only analytics is Mint (which is local to the server).
- colmmacc 13y agoDisclaimer: I've been involved in several DNS implementations, for a long time, and so probably have a bias. Namecoin and namecoin-derived systems are cool, but they tend to overlook a lot of real-world functionality provided by DNS. As used today DNS is 1) A distributed key-value storage system 2) Incredibly scalable and fault-tolerant and 3) a de-facto internet routing layer for CDNs and GSLB endpoints. Namecoin systems typically provide (1) but overlook (2) and (3), which makes it hard to consider them as viable replacements. I think it's interesting to look at what existing entities do when faced with DNS MITM and takedowns. The various torrent searchers and anti-censorship entities just diversified the TLDs they depend upon. So when their ".com" or ".net" domain gets taken down or man-in-the-middled, they tell their users to shift to .is , .ch, .se or some other TLD with a different regulatory framework, thus avoiding a single point of failure. If a new mechanism depends on the inconvenience of a browser extension anyway, why not automate the process people already use? For example "colmmacc.multi" could be intercepted by an extension and translated into 5 DNS requests against say SHA-2("colmmacc").[com|ch|ly|se|is] and the extension could use a simple majority quorum of the answers to defend against a tampered response. Of course it means you have to register and host your domain 5 times, but that's pretty cheap these days. Other nice properties: works with all existing DNS security mechanisms (including DNSSEC or DNScurve), provides security against registrar or registry level tampering or compromises. Hash of the domain makes it hard for registries to block domains (they have no idea what the name is until it is popular) and also resets the clock on squatters.