Re: secure anonymous decentralized systems [was: "Whew, wondered where we'd put those 200,000 BTC!"]

this thread needs more violin and cutting one's self. my comments on this familiar lament inline,... On Sat, Mar 22, 2014 at 6:14 PM, Lodewijk andré de la porte <l@odewijk.nl> wrote:
it's like a pair of glasses you put on, and can't take off! " i see vulns, everywhere! " ;P
see also stealthy dopant level trojans, beam-steering TEMPEST, and you've seen much the same as i on my excursion down what it takes to build "secure anonymous decentralized systems". ( decentralized meaning that every node potentially equal, which means that every threat model a node might experience must be defended, which means you're building to the absolute hardest target, which means you've adopted multiple nation state attackers into scope, which means you're building something entirely unlike what we currently have or know how to build, and absolutely a long way from here...) wanna help? just working on the pieces is useful! [see also, not getting discouraged and giving up. *grin*]
Overall I decided I respect greatly the people that take on this challenge. This was over a year ago.
have you gone through the NSA TAO and SSO catalog? this is a great resource for putting some technical capability around the threat models above, and building test systems able to carry out attacks like those above. (for testing. in a test environment. of course :)
and you wonder why USGov is trying to beat miscreants into submission with CFAA life destruction. everyone is passing the security buck, DA gotta do something... [this is just one of many poor trends.]
MtGox failing because money dissapeared over the years... That was shocking at an unbelievable level.
you must be new to interwebs? see also, every blackhat doxing crew since ever.
... The list goes on.
see also, every blackhat doxing crew since ever.
don't do it. instead, build software secure and usable enough that every average user can be their own exchange and bank without falling prey to haxxors or stupidity. oh, someone told me that i'm depressing the hackers with my realism and please try to make the self hurt less desirable, so here, my real world cover is goat farmer: https://peertech.org/files/totes-coders-goats.jpg </shameless_plagiarism> [ i hope that didn't reduce my anonymity set too much! ]

2014-03-23 2:56 GMT+01:00 coderman <coderman@gmail.com>:
have you gone through the NSA TAO and SSO catalog?
The day it was leaked. Made a writeup on a list too. Massive amount of stuff. I was happy it leaked, I was saying that they *must* be doing that for *years*. At least, to everyone who wouldn't label me a paranoid guy right away. Now they won't label me like that so easily :). don't do it. instead, build software secure and usable enough that
every average user can be their own exchange and bank without falling prey to haxxors or stupidity.
Once I'd have done that I'll be half a year further. If it works out everyone will think it's pretty cool and it'd be totally useless to me otherwise. I can move on to the next thing, but most likely I'll need some money and that'll be the end of the fight for freedom. I much prefer the scenario where the central and quite secure exchange works and half the profit is poured purely into increased security, the other half towards the next projects. If it all bloats up enough there'll be a little horde of people working on those problems I'd have tackled myself years later. In that scenario everyone wins much more. I also still believe I can make it "secure" whatever that means. Pretty much impossible to hack, is the idea. I can't really go into thoughts about how2 distributed secure application right now. It's worth mentioning RetroShare as an existent solution (that's probably not secure at all) and Zero Reserve https://bitcointalk.org/index.php?topic=295930.0. Both attempts at this ideal without any use of those terrible "Interpreted languages" (this sentence is a joke). ttyl
participants (2)
-
coderman
-
Lodewijk andré de la porte