Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ianopolous
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
61.
▲
by
ianopolous
3y ago
The block auth is very generic, just an extra top level key in cbor maps or a small prefix in raw blocks. The protocol is S3 V4 signatures. There is a Java implementation of the modified bitswap for this in Nabu [0] and a Go one in ipfs-nuc
62.
▲
by
ianopolous
3y ago
We've been pioneering privacy and access control on top of IPFS since 2015 in Peergos [0]. We have block level access control for example: https://peergos.org/posts/bats As well as E2EE, sharing, trustless servers
63.
▲
by
ianopolous
3y ago
For those interested, here is the implementation of enter for JPC emulator: https://github.com/ianopolous/JPC/blob/master/src/org/jpc/em... https://github.com/ianopolous&#x
64.
▲
by
ianopolous
3y ago
You might be interested in Peergos[0], where the server is treated as an adversary, and can't see file sizes, number of files etc. Everything is in merkle trees whose roots are signed. So not possible for a mirror to selectively remove
65.
▲
by
ianopolous
3y ago
The author is one of the creators of blake3, Zooko.
66.
▲
by
ianopolous
3y ago
Would be interesting to hear Zooko's response to this. (Peergos lead here)
67.
▲
by
ianopolous
3y ago
You can make blocks private in ipfs so only authorised people can download them. Here's how we do this in peergos https://peergos.org/posts/bats
68.
▲
by
ianopolous
3y ago
What you really want is something e2e encrypted so you don't need to trust the server.
69.
▲
by
ianopolous
3y ago
I wrote/ported a single file Java implementation of another of the post quantum signature schemes - sphincs+ here: https://github.com/Peergos/sphincsplus
70.
▲
by
ianopolous
3y ago
You can do that and also require auth to retrieve the cipher text blocks: https://peergos.org/posts/bats
71.
▲
by
ianopolous
3y ago
You can do that with peergos [1]- mount a peergos folder locally using FUSE. Or login to the web interface and share easily and privately. [1] https://github.com/peergos/peergos
72.
▲
by
ianopolous
3y ago
I once wrote a Linux process emulator in java for static x86 binaries. It could run 80% native speed on x86 and 240% native speed on arm compared to gcc -o3. (I think gcc wasn't very good on arm at the time) Sadly it was proprietary.
73.
▲
by
ianopolous
3y ago
Not necessarily. You can add auth at the encrypted block level: https://peergos.org/posts/bats
74.
▲
by
ianopolous
3y ago
You might be interested in the p2p design of Peergos. You sign up to Peergos[0]. Your initial server is just responsible for storing your data (although you can run as many live mirrors as you like), and clients verify all updates. You can
75.
▲
by
ianopolous
3y ago
Peergos is the most advanced encrypted dropbox clone on ipfs. Disclaimer, founder here. We even extend the block retrieval protocol so encrypted blocks are not public - like most data in ipfs - you need auth to retrieve them: https:/&
76.
▲
by
ianopolous
3y ago
I'm interested in the "removing your websites from the public web". Are you taking them down, putting them behind auth, or something else?
77.
▲
by
ianopolous
3y ago
G'day Why! This is operating through the gateway. So you have to trust the gateway currently. Yes, you can move the gateway to your machine and then the trust requirement doesn't extend over the network. However with local ipfs, b
78.
▲
by
ianopolous
3y ago
IPFS doesn't currently. But there are some in the community working on exactly this using Blake3 and BAO.
79.
▲
by
ianopolous
3y ago
How about they support the algorithm parameter in the TOTP spec, rather than silently ignoring it and hard-coding hmacSha1?
80.
▲
by
ianopolous
3y ago
You could do that running this as a custom app in Peergos [0], and the drive image would just be another file: https://book.peergos.org/features/apps.html We've done that for doom using another js emulator (jsdosb
81.
▲
by
ianopolous
4y ago
I thought the selling point of wasm was close to native speed. :-) If something is important browsers can always add it to webcrypto anyway.
82.
▲
by
ianopolous
4y ago
Don't get me wrong, FR-CGKA looks cool. I hadn't seen it yet, and am still reading it. Not sure why wasm/js is relevant to the discussion.
83.
▲
by
ianopolous
4y ago
At 1000 members a DCGKA key update (when the group membership changes) is ~300kb. So, equivalent to someone sending a small image, which they probably do very frequently.
84.
▲
by
ianopolous
4y ago
That's true, but not really relevant until you hit 1000s of chat members. MLS targets up to 50,000. But there isn't a plausible threat model for a secure chat that large (someone will leak or it will be infiltrated).
85.
▲
by
ianopolous
4y ago
And it's still true today. I was considering implementing MLS myself, but decided against it because of this. https://github.com/mlswg/mls-architecture/blob/main/draft-ie...
86.
▲
by
ianopolous
4y ago
As your link discusses, MLS still requires centralization because of the requirements of total ordering of some messages by the delivery service. If you want a truly p2p encrypted group chat protocol then look at DCGKA by Matthew Weidner, M
87.
▲
by
ianopolous
4y ago
100% agree. I want a web where using web apps is private by default. Been working on an attempt to move towards this: https://peergos.org/posts/a-better-web
88.
▲
by
ianopolous
4y ago
Totally agree! Shameless self promotion: have a look at Peergos - https://github.com/peergos/peergos Our tech book might be a better starting point for this group: https://book.peergos.org
89.
▲
by
ianopolous
4y ago
Thanks! The security is partially a defense against future owners/operators of your server. But I'm totally sold on the idea of only seeing things shared by people you follow.
90.
▲
by
ianopolous
4y ago
This is a great idea. I totally agree. It's the same design we've chosen for the social network in Peergos. Two main differences are we enforce no server-side algorithmic curation by being e2e encrypted, and posts can be anything,
More ›