View Full Version : Worried about ANts
Nikidajen
February 19th, 2005, 05:37 AM
1. I'm hoping that Jason from MUTE isn't working on ANts. He got bought last I heard.
2. MIM isn't a worry so much as an idiot in the middle who can't configure a firewall and allows their machine to be occupied by snoops. Rinse, repeat.
3. ANts looks rich for node flooding, not a crack, but a crash.
4. I've heard the time issues, but question whether a link between content and dropping can be associated. To try and clarify, User has file X with no multi-source (the file is unique on the network), the Use logs off, file X drops on the search, you now know User is sharing file X.
Somebody shoot these ideas down, please do it nicely (if possible), I'm looking for concise answers, not conflict. Thanks in advance for your help at typing up some literate prozac for the paranoid.
fnordprefect
February 19th, 2005, 06:12 AM
1. Jason doesn't work on Ants, but I believe Gwren communicates with MUTE developers (Nate particularly).
2. That's a concern for any and all P2P programs.
3. I don't think an evil node would be able to flood the network. You'd need LOTS of them, I think Ants would naturally route around any such areas of flooding.
4. Ants uses a distributed hash table, other nodes will learn your shared files and they will still appear in searches after you disconnect.
Nikidajen
February 19th, 2005, 06:24 AM
Thanks.
For the MIM or idiot in this case, it's completely preventable, Ants shouldn't be able to run if your firewall is "open". I see that ANts does try to accomplish this. What ANts doesn't do is see if a snoop is in your machine. It can be argued that the only thing the snoop could get is what you have locally.
I would be certain that an evil node could flood. This is really trival when you look at the purpose of ANts and how well it accomplishes it's goals, but it is still a crash. Before anybody else gets to it, yes, most networks can be brought down by a flood. I'd just hate to see it done to a program with so much development and potential.
Thanks for the response fnordprefect!
tsafa1
February 20th, 2005, 01:38 PM
1. Jason doesn't work on Ants, but I believe Gwren communicates with MUTE developers (Nate particularly).
Oh yes, definetly communicating in a very affectionate mannor. Cursing and Screaming and saying that the other guys sucks. Its very funny to follow. I have been able to pull out some very usefull information out of the crossfire which i have posted. See latest post on "wrong IP address".
usualy development occurs when people work together but these guys are at thier best when they are at each others throats. Its hilarious :ass
tsafa1
February 20th, 2005, 09:31 PM
hmmm... let me add to my prior comment... while i think development would benefit from more cooperation between developers of Ants an Mute, I think that security is benefiting from the fighting. At this point Nate and Gwren hate each other and are very criticle of each others work. If there are any security flaws in Ants or Mute, I think these guys have been for some time trying to find them just to look the other guy look bad. I have heard some commets about speed and enefficiency. but nothing substancial about weeknesses in security. It may be better for us that these two guys do stay at odds, so they can look for flaws in the others work.
In the meantime, I'll use both programs.
Nikidajen
February 22nd, 2005, 12:58 AM
I agree with staying at "odds", I just don't want to see anybody else directly working on the code, regardless of it being open source. If there ever is a collaborative release, I'd like to know who worked on it.
The heated, "You're pretty...for a fat girl" type discussions are entertaining as well as productive. Gwren live in a country where he can see jail time, I've watched other apps "sell out" giving up names, IP's content that was shared and so on. You couldn't do this with Ants now and I don't want to see this change.
My other concern is that on of the alphabet corps is simply just going to crash the nodes.
Also after more thinking, it's not conclusive, but it is a good place to start, even if the file still appears because it is on a table, you may be able to make an association with that file to the person sharing it. (User has file X, it's downloadable, User disconnects, file is listed, but not available) There is still plausible deniability, however, I'd like to see ants bootstrap as it does now and then disconnect from IRC until ANts needs to search for a node. While in IRC, nothing should be being ul/dl/routed while in a room. Asssociations can be made. I can here it now, that no one can see if you are ul/dl'ing, but it would add a little more security for the super paranoid. I know many don' see the point, but many don't see the point to E2E encryption.
fnordprefect
February 22nd, 2005, 01:07 AM
Tsafa, where are these "discussions" between Gwren and the Mute devs taking place?
Got a link?
tsafa1
February 22nd, 2005, 09:06 AM
https://lists.sourceforge.net/lists/listinfo/mute-net-discuss
you have to sign up. Its an email forem. The website keeps old posts so you can read what you missed on the website.
The fact that italian users face real jail time for filesharing is the best reason to to have confidence in Gwren.