On 30/07/14 14:37, xor wrote:
> On Wednesday, July 30, 2014 11:25:07 AM Matthew Toseland wrote:
>> but we need our connection level crypto to be
>> written in C, because you can't eliminate side-channels if you're doing
>> encryption in Java.
> I think that's tinfoil hat level of paranoia. If you're that close to a 
> Freenet user that sidechannel attacks work, easier attacks will also work.
If you are connected you can do some fairly cheap attacks, but if you
observe a darknet connection but aren't connected to it? Having an
insecure transport layer is bad.
> I've got another aspect about Tor and us though:
> We should try to get bundled with the "Tails" Tor live CD.
> It is advertised on the front page of the Tor website, and development seems 
> pretty active.
>
> They ship with I2P, so they are open to other projects than Tor. And I2P is 
> Java, so the barrier for bundling Freenet should be very low.
>
> We should get this done for reaching more users.
>
> I've filed a bug for it at:
> https://bugs.freenetproject.org/view.php?id=6268
Thanks!

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Devl mailing list
Devl@freenetproject.org
https://emu.freenetproject.org/cgi-bin/mailman/listinfo/devl

Reply via email to