4 ms·
There are two useful things (IMHO) in magic-wormhole. The first is the PAKE-based security model, with the invitation codes. The second is the "try to find each
by lotharrr 11y ago
There are two useful things (IMHO) in magic-wormhole. The first is the PAKE-based security model, with the invitation codes. The second is the "try to find each other" STUN-fallback transit stuff. Transit is way less interesting than PAKE, but by combining the two, you get a tool that's about as simple as it could possibly get while still being secure.
magic-wormhole always uses a baked-in rendezvous server (which I run) for exchanging PAKE messages, and frequently uses a baked-in transit server (which I also run) for the bulk data of file transfer. If one of the two sides has a public IP address or they're both on the same subnet, the file transfer runs directly, without my transit server. My transit server is effectively a STUN server.
I have a list of alternative approaches to explore (use the BitTorrent DHT, use Tor hidden services, use IP multicast groups, local MDNS, IPFS), which may do one or more of the following:
* reduce the single-point-of-failure -ness
* reduce the exposure of IP addresses
* increase the exposure of IP addresses
* reduce the load on my server
* speed things up
* slow things down
Compared to scp: to get proper (i.e. non-password) security out of ssh/scp (and rsync on top of them), you must have previously copied a public key to the target machine, which requires e.g. reading the string to someone sitting next to you and having them type it in, or publishing the key somewhere that can be reached by something you read to them and then visually comparing what they got with what you meant to publish. (at least for the initial contact; once you've set up the keys, then future transfers are trivially easy). Plus the target must be reachable by TCP.
For magic-wormhole, you still have to read something to them, but it's really short and designed specifically to be transcribed aloud. And the two sides don't need TCP reachability.
I figured that almost every form of file transfer involves either the sender telling some reference string to the recipient (like a URL of some sort), or the recipient telling some destination reference string to the sender (an email address), followed by a bunch of other work that's annoying and reduces security. Magic-wormhole requires the same "read something to the recipient" part, but removes the setup phase, and removes all the security-losing middlemen.