The release of the P2P platform GNUnet 0.16.0.

The release of GNUnet framework 0.16 has been announced, designed for building secure decentralized P2P networks. Networks created using GNUnet do not have a single point of failure and can guarantee the privacy of users' information, including preventing potential abuses by authorities and administrators who have access to network nodes.

GNUnet supports the creation of P2P networks over TCP, UDP, HTTP/HTTPS, Bluetooth, and WLAN, and can operate in F2F (Friend-to-friend) mode. NAT traversal is supported, including with the use of UPnP and ICMP. A distributed hash table (DHT) can be used for data location addressing. Tools for deploying mesh networks are provided. For selective granting and revocation of access rights, the decentralized attribute exchange service reclaimID is used, which employs GNS (GNU Name System) and attribute-based encryption.

The system features low resource consumption and a multi-processing architecture to ensure isolation between components. Flexible tools for logging and accumulating statistics are provided. For developing end applications, GNUnet offers an API for the C language and bindings for other programming languages. To simplify development, it is recommended to use event loops and processes instead of threads. It includes a testing library for the automatic deployment of experimental networks covering tens of thousands of peers.

Several ready-made applications are being developed based on GNUnet technologies:

  • The GNS (GNU Name System) is a completely decentralized and censorship-resistant alternative to DNS. GNS can be used alongside DNS and in traditional applications such as web browsers. Unlike DNS, GNS employs a directed graph instead of a tree-like hierarchy of servers. Name resolution is similar to DNS, but requests and responses are handled with privacy in mind—the node processing the request doesn't know to whom the response is given, and transit nodes and third-party observers cannot decipher the requests and responses. The integrity and immutability of records are ensured through cryptographic mechanisms. A DNS zone in GNS is defined using a pair of ECDSA public and private keys based on the Curve25519 elliptic curves.
  • A service for anonymous file sharing that prevents information analysis by transmitting data solely in encrypted form and does not allow tracking of who uploaded, searched for, and downloaded files thanks to the use of the GAP protocol.
  • System VPN for creating hidden services in the '.gnu' domain and tunneling IPv4 and IPv6 over a P2P network. Additionally, it supports IPv4-to-IPv6 and IPv6-to-IPv4 translation schemes, as well as tunneling IPv4 over IPv6 and IPv6 over IPv4.
  • The GNUnet Conversation service for making voice calls over GNUnet. GNS is used for user identification, and the content of voice traffic is transmitted in encrypted form. Anonymity is not yet provided—other peers can track the connection between two users and identify them. an IP address.
  • A platform for building decentralized social networks, Secushare, that uses the PSYC protocol and supports the multicast distribution of notifications with end-to-end encryption so that only authorized users can access messages, files, chats, and discussions (those to whom messages are not addressed, including node administrators, will not be able to read them);
  • A system for organizing encrypted email, pretty Easy privacy, which uses GNUnet to protect metadata and supports various cryptographic protocols for key verification.
  • The GNU Taler payment system provides anonymity for buyers while tracking seller transactions to ensure transparency and provide tax reporting. It supports operations with various existing currencies and electronic money, including dollars, euros, and bitcoins.

Key innovations in GNUnet 0.16:

  • The specification of the decentralized domain name system GNS (GNU Name System) has been updated. A new type of record, REDIRECT, has replaced CNAME records. A new flag, CRITICAL, has been added to records, which can mark particularly important entries, the inability to process which should result in a name resolution error. VPN tunnel setup operations have been moved from the resolver to applications such as the DNS2GNS service.
  • Route endorsement with a digital signature has been implemented in the distributed hash table (DHT). The metrics for route length have transitioned to the use of the traditional XOR operation. The specifications of data structures, cryptographic functions, and resource records of the DHT have been updated.
  • The decentralized attribute exchange service (RECLAIM) has added support for decentralized identifiers (DID) and verifiable credentials (VC).
  • For the GNU Taler payment system, support for Klaus Schnorr's blind digital signatures has been implemented (the signer cannot access the content).
  • The build system now ensures the generation of current header files from GANA (GNUnet Assigned Numbers Authority). Building from git now requires recutils.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster