4 ms·
Neat service! But, why does something saying it is p2p always seem to have some centralized dependency? In this case, it's GitHub auth. It seems that the init
by lighthawk 11y ago
Neat service!
But, why does something saying it is p2p always seem to have some centralized dependency? In this case, it's GitHub auth.
It seems that the initial authentication of you are who you say you are could be done via transferring a key to someone- by email, flash drive, whatever- and then after that, as long as you could connect to them, you could talk to them- with no other dependency except the network itself, which may involves a lot of significant dependencies, or may not, e.g. a cross-wired cable.
- tormeh 11y agoBecause key distribution is a pain. That said, it would be neat if you could choose centralized keystore. That would mean that you would get one account per online service, but the communications could be multiplexed.
- api 11y agoKey distribution and NAT traversal. The latter is literally impossible without some kind of external third party to facilitate.
- lawl 11y ago> Simply put, this is a proxy server that works behind a NAT, even when the client is behind a different NAT, without any 3rd party or network changes. > There is no middle man, no proxy, no 3rd party, no UPnP/STUN/ICE required, no spoofing, and no DNS tricks. http://samy.pl/pwnat/ http://samy.pl/pwnat/ The FAQ is great too :) Ok, so does this really work? Yes. Try it! I'm confused. This can't work. You should be, and it does work. But it can't. My NAT blocks incoming packets and so will the other. I know.
- Tcepsa 11y agoThat is both brilliant and hilarious!
- abcd_f 11y agoIt's clever, but not exactly relevant to the GP's comment. pwnat requires the initiator to know the IP of the target host, so some form of external seeding is still required.
- lawl 11y agoKnowing who you want to contact is usually a requirement to be able to contact them.
- grrowl 11y agoSomething like PGP without automatic trust of new connections may work, as if cross with Facebook's friend system. "This user claims to be Jimmy Jimson (image of fingerprint). Trusted by 19 people you directly trust, and by 250 people they trust. [add] [ignore]". Is this feasible? I'd rather attackers social engineer people rather than subvert the technical, non-human aspects. And like Facebook, if you see two of the same person on your Trusted list, you know one of the accounts is probably not under their control.