cross-posted from: https://feddit.uk/post/1248314
DEF CON Infosec super-band the Cult of the Dead Cow has released Veilid (pronounced vay-lid), an open source project applications can use to connect up clients and transfer information in a peer-to-peer decentralized manner.
The idea being here that apps ā mobile, desktop, web, and headless ā can find and talk to each other across the internet privately and securely without having to go through centralized and often corporate-owned systems. Veilid provides code for app developers to drop into their software so that their clients can join and communicate in a peer-to-peer community.
In a DEF CON presentation today, Katelyn āmedus4ā Bowden and Christien āDilDogā Rioux ran through the technical details of the project, which has apparently taken three years to develop.
The system, written primarily in Rust with some Dart and Python, takes aspects of the Tor anonymizing service and the peer-to-peer InterPlanetary File System (IPFS). If an app on one device connects to an app on another via Veilid, it shouldnāt be possible for either client to know the otherās IP address or location from that connectivity, which is good for privacy, for instance. The app makers canāt get that info, either.
Veilidās design is documented here, and its source code is here, available under the Mozilla Public License Version 2.0.
āIPFS was not designed with privacy in mind,ā Rioux told the DEF CON crowd. āTor was, but it wasnāt built with performance in mind. And when the NSA runs 100 [Tor] exit nodes, it can fail.ā
Unlike Tor, Veilid doesnāt run exit nodes. Each node in the Veilid network is equal, and if the NSA wanted to snoop on Veilid users like it does on Tor users, the Feds would have to monitor the entire network, which hopefully wonāt be feasible, even for the No Such Agency. Rioux described it as ālike Tor and IPFS had sex and produced this thing.ā
āThe possibilities here are endless,ā added Bowden. āAll apps are equal, weāre only as strong as the weakest node and every node is equal. We hope everyone will build on it.ā
Each copy of an app using the core Veilid library acts as a network node, it can communicate with other nodes, and uses a 256-bit public key as an ID number. There are no special nodes, and thereās no single point of failure. The project supports Linux, macOS, Windows, Android, iOS, and web apps.
Veilid can talk over UDP and TCP, and connections are authenticated, timestamped, strongly end-to-end encrypted, and digitally signed to prevent eavesdropping, tampering, and impersonation. The cryptography involved has been dubbed VLD0, and uses established algorithms since the project didnāt want to risk introducing weaknesses from ārolling its own,ā Rioux said.
This means XChaCha20-Poly1305 for encryption, Elliptic curve25519 for public-private-key authentication and signing, x25519 for DH key exchange, BLAKE3 for cryptographic hashing, and Argon2 for password hash generation. These could be switched out for stronger mechanisms if necessary in future.
Files written to local storage by Veilid are fully encrypted, and encrypted table store APIs are available for developers. Keys for encrypting device data can be password protected.
āThe system means thereās no IP address, no tracking, no data collection, and no tracking ā thatās the biggest way that people are monetizing your internet use,ā Bowden said.
āBillionaires are trying to monetize those connections, and a lot of people are falling for that. We have to make sure this is available,ā Bowden continued. The hope is that applications will include Veilid and use it to communicate, so that users can benefit from the network without knowing all the above technical stuff: it should just work for them.
To demonstrate the capabilities of the system, the team built a Veilid-based secure instant-messaging app along the lines of Signal called VeilidChat, using the Flutter framework. Many more apps are needed.
If it takes off in a big way, Veilid could put a big hole in the surveillance capitalism economy. Itās been tried before with mixed or poor results, though the Cult has a reputation for getting stuff done right. Ā®
This sounds awesome, will try to use it