The release of the P2P platform GNUnet 0.25

The release of the GNUnet framework version 0.25 has been announced, aimed at building secure decentralized P2P networks. The networks created using GNUnet have no single point of failure and can guarantee the privacy of user information, including eliminating potential abuses by administrators who have access to the network nodes.

GNUnet supports the creation of P2P networks over TCP, UDP, HTTP/HTTPS, Bluetooth, and WLAN, and can operate in F2F (Friend-to-friend) mode. NAT traversal is supported, including with the use of UPnP and ICMP. A distributed hash table (DHT) can be used for data location addressing. Tools for deploying mesh networks are provided. For selective granting and revocation of access rights, the decentralized attribute exchange service reclaimID is used, which employs GNS (GNU Name System) and attribute-based encryption.

The system is characterized by low resource consumption and the use of a multi-process architecture to ensure isolation between components. Logging and statistics collection tools are provided. To develop end applications, GNUnet offers a basic API for the C programming language and wrappers for other programming languages. To simplify development, it recommends using event loops instead of threads and processes. It includes a test library for automatically deploying experimental networks covering tens of thousands of peers.

Several ready-made applications are being developed based on GNUnet technologies:

  • The GNS (GNU Name System) is a completely decentralized and censorship-resistant alternative to DNS. GNS can be used alongside DNS and in traditional applications such as web browsers. Unlike DNS, GNS employs a directed graph instead of a tree-like hierarchy of servers. Name resolution is similar to DNS, but requests and responses are handled with privacy in mind—the node processing the request doesn't know to whom the response is given, and transit nodes and third-party observers cannot decipher the requests and responses. The integrity and immutability of records are ensured through cryptographic mechanisms. A DNS zone in GNS is defined using a pair of ECDSA public and private keys based on the Curve25519 elliptic curves.
  • A service for anonymous file sharing that prevents data analysis by transmitting all information in encrypted form and does not allow tracking of who uploaded, searched, or downloaded files through the use of the GAP protocol.
  • System VPN for creating hidden services in the '.gnu' domain and tunneling IPv4 and IPv6 over a P2P network. Additionally, it supports IPv4-to-IPv6 and IPv6-to-IPv4 translation schemes, as well as tunneling IPv4 over IPv6 and IPv6 over IPv4.
  • The GNUnet Conversation service for making voice calls over GNUnet. GNS is used for user identification, and the content of voice traffic is transmitted in encrypted form. Anonymity is not yet provided—other peers can track the connection between two users and identify them. an IP address.
  • A platform for building decentralized social networks, Secushare, that uses the PSYC protocol and supports the multicast distribution of notifications with end-to-end encryption so that only authorized users can access messages, files, chats, and discussions (those to whom messages are not addressed, including node administrators, will not be able to read them);
  • The GNU Taler payment system provides anonymity for buyers while tracking seller transactions to ensure transparency and provide tax reporting. It supports operations with various existing currencies and electronic money, including dollars, euros, and bitcoins.
  • The GNUnet Messenger service for creating secure chat applications employs the CADET (Confidential Ad-hoc Decentralized End-to-End Transport) protocol to ensure privacy and protect against message interception, allowing for fully decentralized interaction among a group of users with end-to-end encryption of transmitted data.

In the new version:

  • The CORE subsystem responsible for routing and information exchange between nodes in a decentralized network has been overhauled. A new implementation of secure communication channels has been proposed, utilizing a variant of the KEMTLS protocol for encrypted connection negotiation, employing the X25519, XChaCha20, and Poly1305 algorithms, as well as many concepts from the DTLS 1.3 protocol.
  • The PILS (Peer Identity Lifecycle) service has been added for the identification of network participants, allowing peer identifiers to be generated based on the current connection context. For instance, when accessing from home, one identifier will be generated, while traveling abroad will generate another, preventing the tracking of the participant's movements.
  • The service performance for transferring (AXFR/IXFR) DNS zones in GNS has been significantly improved. New utilities for mirroring and importing DNS zones from files have been added.
  • Support for AutoTools has been discontinued in the build system.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster