3 ms·
While I'm inclined to agree that Kademlia is the frontrunner for DHTs, I'd like to comment on: > it has the advantage of naturally not depending on other peers
by AnIrishDuck 12y ago
While I'm inclined to agree that Kademlia is the frontrunner for DHTs, I'd like to comment on:
> it has the advantage of naturally not depending on other peers behaving correctly
This is, depending on the variety of pedantic hat you put on, not true. While Kademlia is resistant to some simple malfunctions, it can be attacked by an adversary. Or, to put it formally, Kademlia is not Byzantine Fault Tolerant [2].
It can be strengthened, but at the cost of greater complexity. See [3] for an example. Further, it's arguable that zero-trust systems where anyone is allowed to join can never be BFT because of Sybil attacks [4]. The paper in [3] elaborates on how to mitigate this variety of attack, but it's unlikely that Sybil attacks can ever be "solved".
1. "Attacking the kad network" http://www.p2p.tu-darmstadt.de/fileadmin/user_upload/Group_P2P/lecWS12/a23-wang.pdf http://www.p2p.tu-darmstadt.de/fileadmin/user_upload/Group_P...
2. http://en.wikipedia.org/wiki/Byzantine_fault_tolerance http://en.wikipedia.org/wiki/Byzantine_fault_tolerance
3. "S/Kademlia: A Practicable Approach Towards Secure Key-Based Routing" http://doc.tm.uka.de/SKademlia_2007.pdf http://doc.tm.uka.de/SKademlia_2007.pdf
4. http://en.wikipedia.org/wiki/Sybil_attack http://en.wikipedia.org/wiki/Sybil_attack
- rakoo 12y agoOf course, a global attacker can always muck with the system. I was talking about single independent peers behaving badly on their little scale, such as returning wrong or no information, which I believe is more likely to happen. Also, the guys at Bittorrent are pushing for a limitation on how you can form your own ID based on your external IP [0], which should make it much more costly to perform a large-scale attack. Thank you for being pedantic :) [0] http://blog.libtorrent.org/2012/12/dht-security/ http://blog.libtorrent.org/2012/12/dht-security/