5 ms·
Tribler has a very long history of making high profile claims and never being able to follow through with actually usable software, so I'm not really surprised
by santacluster 12y ago
Tribler has a very long history of making high profile claims and never being able to follow through with actually usable software, so I'm not really surprised by this.
The entire project is a combination of TU Delft publicity stunt and EU subsidies sinkhole. In 10 years of screwing around with bittorrent it hasn't produced anything that could compete with the side projects of individual hackers.
It's a disgraceful waste of community money.
The code may be fixable (though I doubt they even care), the project however isn't.
- researcher88 12y agoAny idea how something like this happens? They got at least 22 million euros in funding and seemed to be managed by academics but somehow completely missed the mark?
- wmf 12y agoIt's regrettably common for academic work to be compared only against other academic work so something can be considered novel or state-of-the-art even if it's worse than shipping products or open source. It seems possible that Tribler is the leading academic P2P system and thus deserving of more grants, which keep it in the lead. (It's also common for open source to ignore competition from commercial software, and for enterprisey products to ignore the consumer market, etc.)
- RayNbow 12y agoKeep in mind that the majority of the 22M EUR has been spent in the past on various P2P aspects (e.g., semantic overlay for search, modifying BitTorrent for live streams, modifying BitTorrent for Video on Demand). The anonymity/privacy aspect is quite new for Tribler (< 1 year).
- praseodym 12y ago"Work on Tribler has been supported by multiple Internet research European grants. In total we received 3,538,609 Euro in funding for our open source security research. Roughly 10 to 15 scientists and engineers work on it full-time." http://www.tribler.org/about.html http://www.tribler.org/about.html
- synctext 12y agowe are not an anti-spook project and never claimed to be. Our aim is to give an option where there is none. We will make our warning more elaborate and will work differently with bloggers/journalists in the future.
- letstryagain 12y agoAn "option" for what? Tribler seems completely useless in the light of this article. People are even getting automated infringement notices from the MPAA! What's the use case for Tribler?
- deleted 12y ago[deleted]
- userbinator 12y agoRoughly 10 to 15 scientists and engineers work on it full-time. They have carefully evaded the point of what exactly those "scientists and engineers" are qualified in. Apparently not cryptography.
- radarsat1 12y agoThese do look like serious problems, but it seems to me that all or at least most of them can be fixed. (Are there any "deal breakers"?) What they need is cryptography experts to do more than comment publicly (which is commendable, I am not criticizing), but also contribute some fixes. It is open source after all. To say that the whole thing is a waste of effort and money is a little strong-worded I think.
- MichaelGG 12y agoThe fact that such serious mistakes were committed in the first place makes it highly unlikely that they'll properly fix the system.
- throwawaykf05 12y ago1. As somebody interested in P2P, I've been following Tribler for a while. Note that this is, first and foremost, a research project. It's basically a playground / lab for research and thesis work, and that's how it should be viewed. While the people who work on it (I even talked to a couple many years ago) do wish for it to be generally usable, they are academics, and so publishable material is their primary goal. That it is decently usable by the general populace at all is in itself unusual as far as most research projects go. 2. The researchers (at least as of a few years ago) were more interested in distributed systems and P2P, so the flawed crypto is not surprising to me. 3. The only reason it is getting so much scrutiny is because of recent claims that it makes "stopping bittorrent impossible". My guess is, this originated from typical university PR. What happened instead is that these claims seemed to address a long-standing need of people the world over who wish to download copyright material without being held accountable for it. This generated vastly more publicity and enthusiasm amongst circles that probably didn't know how many grains of salt university PR is supposed to be taken with. Which, naturally, resulted in a proportional amount of scrutiny, and hence, TFA. 4. As noted elsewhere, the adversary here isn't "spooks" but rather the MPAA, RIAA and the like. As such, they are probably more vulnerable to hacking-related laws and probably less motivated to exploit these flaws. 5. I haven't seen any "side projects of individual hackers" that are anywhere as close to functional as Tribler is, but then again, I haven't been looking. I'd certainly be interested in seeing some.
- pipes_included 12y agowithr regards to point 5, you should look at bittorrent inside i2p[1] 1: https://geti2p.net/en/docs/applications/bittorrent https://geti2p.net/en/docs/applications/bittorrent
- luoin 12y agoFWIW, funding for Tribler has significantly dried up, probably also due to this. When I read about this sequence of severe fundamental security screw-ups in Tribler, it really scares me that Pouwelse has recently started to position himself as a cyber security expert. I don't think that TU Delft considers Tribler a publicity stunt, but that they see it as a serious initiative, even though it probably does more harm than good to both its users and the university. Outside the academic papers and review comment process, there often isn't much of a feedback channel back into academia and giving the mass of academic conferences, it is only a matter of persistence to get something (bad) accepted.