Account Options

  1. Sign in
The old Google Groups will be going away soon, but your browser is incompatible with the new version.
Google Groups Home
« Groups Home
Message from discussion Potential DoS on Bittorrent
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
D. J. Bernstein  
View profile  
 More options Apr 12 2005, 10:44 pm
Newsgroups: alt.internet.p2p, sci.crypt
From: "D. J. Bernstein" <d...@cr.yp.to>
Date: Wed, 13 Apr 2005 02:44:21 +0000 (UTC)
Local: Tues, Apr 12 2005 10:44 pm
Subject: Re: Potential DoS on Bittorrent

Michael Amling wrote:
> the OP's threat model included a malicious peer

The great thing about attackers is that there are so many to choose from!
You should be using

   * a small non-cryptographic error-correcting code between the peers
     as the most efficient way to reduce the random error rate to, say,
     one in a thousand packets;

   * a strong cryptographic authenticator as the most efficient way to
     eliminate forgeries by anyone on the network between the peers (and
     to clean up the remaining random errors); and

   * a signature from the original source of the data as the only way to
     catch forgeries by the middlemen.

I was commenting solely on the balance between the first two stages; I
didn't mean to suggest that they were the only stages.

---D. J. Bernstein, Associate Professor, Department of Mathematics,
Statistics, and Computer Science, University of Illinois at Chicago


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.