‹ BackHN Continuity

Thread

Radicle: Disclosure of Vulnerability in the Network Protocol

154 points · 58 comments · lostmsu

  1. iamnothere · · focus · HN ↗
    Glad to hear they are moving to iroh instead of a custom protocol. This is the problem with rolling your own stuff.

    As a bonus, this should help camouflage the traffic. (Iroh is becoming more common.)

    1. innocent_name · · focus · HN ↗
      >this should help camouflage the traffic

      How? QUIC is easy to fingerprint and flow classificate:

      <a href="https:&#x2F;&#x2F;datatracker.ietf.org&#x2F;doc&#x2F;html&#x2F;rfc9000#section-12.1" rel="nofollow">https:&#x2F;&#x2F;datatracker.ietf.org&#x2F;doc&#x2F;html&#x2F;rfc9000#section-12.1

      Speaking of bold claims, Iroh, just like Radicle, are overselling themselves:

      &gt;iroh&#x27;s QUIC multipath implementation automatically switches between Wi-Fi, cellular, ethernet, LAN, LoRa, HaLow, Tor, Bluetooth—or bring your own transport.

      The thing is, QUIC multipath isn&#x27;t standardized.

      1. iamnothere · · focus · HN ↗
        It should appear as encrypted iroh traffic. Depending on how radicle handles things, this could make it difficult to identify versus other applications using iroh. If needed, they could add noise or dummy traffic in the future for further obfuscation.

        They may be overselling, but I’ve had good experiences using apps built on it.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.