> Well my attack on test.jpg and test.html is well underway. I've got my > code checking inform.php every 5 minutes and sending new copies using > libfreenet's testclient (it's fast and clean! good stuff! one small > bug though...) to any new nodes found. My code has tried to send to > 164 nodes now and it's not finding many more. (1 every 10 minutes > maybe?) About %80 of the nodes I think didn't have those two in there > datastores and accepted the new versions without trouble.
The important thing to remember here is that such an attack depends on inform.php to get a list of nodes. The inform.php script is a temporary solution to node discovery. Once a better mechanism is in place obtaining a large list of nodes running Freenet becomes much harder. In the meantime inform.php could be modified to better guard against attacks based on IP address accumulation. The problem isn't just with data tampering, but with things like automatic cease and desist notices from the RIAA to the ISPs of people running Freenet nodes. _______________________________________________ Devl mailing list Devl at freenetproject.org http://lists.freenetproject.org/mailman/listinfo/devl >From devl-admin at freenetproject.org Wed Apr 11 20:47:13 2001 Return-Path: <devl-admin at freenetproject.org> Received: from hawk.freenetproject.org (postfix@[4.18.42.11]) by funky.danky.com (8.9.3/8.8.7) with ESMTP id UAA05739 for <danello at danky.com>; Wed, 11 Apr 2001 20:47:11 -0400 Received: from hawk.freenetproject.org (localhost [127.0.0.1]) by hawk.freenetproject.org (Postfix) with ESMTP id 4F12258026; Wed, 11 Apr 2001 17:29:07 -0700 (PDT) Delivered-To: devl at freenetproject.org Received: from femail3.rdc1.on.home.com (femail3.rdc1.on.home.com [24.2.9.90]) by hawk.freenetproject.org (Postfix) with ESMTP id ADC4558000 for <devl at freenetproject.org>; Wed, 11 Apr 2001 17:28:44 -0700 (PDT) Received: from gw.localdomain ([24.68.44.193]) by femail3.rdc1.on.home.com (InterMail vM.4.01.03.20 201-229-121-120-20010223) with ESMTP id <20010412002220.DAEI15969.femail3.rdc1.on.home.com at gw.localdomain> for <devl at freenetproject.org>; Wed, 11 Apr 2001 17:22:20 -0700 Received: from pete by gw.localdomain with local (Exim 3.22 #1 (Debian)) id 14nUsx-00025c-00 for <devl at freenetproject.org>; Wed, 11 Apr 2001 20:22:55 -0400 From: Peter Todd <[email protected]> To: devl at freenetproject.org Subject: Re: [freenet-devl] Flaw Exposed Message-ID: <20010411202255.A7742 at gw.localdomain> References: <20010411043644.F1929 at niss> <Pine.OSF.4.21.0104110341350.13684-100000 at curly.cc.utexas.edu> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="PNTmBPCT7hxwcZjr" Content-Disposition: inline User-Agent: Mutt/1.3.15i In-Reply-To: <Pine.OSF.4.21.0104110341350.13684-100000 at curly.cc.utexas.edu>; from blanu at uts.cc.utexas.edu on Wed, Apr 11, 2001 at 03:45:58AM -0500 Sender: devl-admin at freenetproject.org Errors-To: devl-admin at freenetproject.org
