Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>> I have always wondered if it gets the same level of scrutiny or interest from researchers or nation states

My guess is the I2P gets more scrutiny from the US government, because it's much harder to break versus TOR(for which there we're always probably some attacks). It might even be that TOR is a government response for the demand for anonymizing networks - funded specifically in order for the anonymity community to do something else than I2P and anonymous remailers, and seems that the community mostly went with it.



>> My guess is the I2P gets more scrutiny from the US government, because it's much harder to break versus TOR

How so? Is this what is alluded to by "onion vs garlic" routing design?

http://resources.infosecinstitute.com/anonymizing-networks-t...

(I can't get the I2P explanation/comparison on their official site right now; not sure it's me or them, haha.)

Again, I read a while back. I am pleased to know it is more secure.

Personally, I liked they had easily accessible Android builds directly from them at the time. But the Tor devs do so much good development, tech writing on the blog, and research publication it is hard to love or hate either group as they save the Internet from itself.


>> My guess is the I2P gets more scrutiny from the US government, because it's much harder to break versus TOR

> How so? Is this what is alluded to by "onion vs garlic" routing design?

For one, it is a closed overlay network. There are no "exit nodes" (well, not unless someone explicitly setup a proxy to provide "exit" functionality). So everything that happens anywhere within I2P remains inside I2P.

So any attacks on TOR that require control of one or more exit nodes in the TOR network to function will not directly function against I2P (no exit nodes).

Now, that has no bearing upon whether there are other, different, exploits in I2P that would break its hidden aspects, but you can at least know you are immune when using I2P to any TOR exploit that requires exit nodes.


I was under the impression out proxies are a thing, and thereby not so different from exit nodes; they are the big weakness.

https://www.reddit.com/r/i2p/comments/46yan0/are_i2p_outprox...

(Again, I am having trouble with the geti2p.net site, which I believe is an public Internet<->I2P HTTP service bridge, which was originally the only outside view in.)

Are they similar? Not sure. To agree with you, I believe the culture and philsophy of Tor is looking out, with exit nodes. I2P was designed to only look in, and the out proxies and bridges are run by select volunteers as a convenience and not the priority.

My favorite part of I2P was there POP3 mailer service, but testing it with friends never seemed to work great.

https://zwadderneel.wordpress.com/2011/05/04/thunderbird-as-...


>My favorite part of I2P was there POP3 mailer service, but testing it with friends never seemed to work great.

You should try it out with I2P-Bote instead, it also has inbuilt hooks so you can use it through your favourite mail client.


>> How so?

It's been a long time since i read about those subjects, but from what i remember - TOR is a low-latency network, which is required for regular web sites to work. This means the network can do little to randomize/mess with packet timing, and thus leaks packet timing which theoretically(and practically) can expose them to timing attacks.

The onion network, on the other hand, does support high-latency connections.


Did you mean to refer to I2P in that last sentence?


True, thanks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: