How We Create 'Internet 2.0' — Independent, Decentralized, and Truly Sovereign

Hello, community!

On May 18, a meet-up of system operators of the "Medium" network took place in Tsaritsyno Park in Moscow. This article presents a transcript from the event: we discussed the long-term development plans for the "Medium" network, the need for HTTPS for eepsites when using the "Medium" network, the deployment of a social network within the I2P network, and much more..

All the most interesting details are below the cut.

1) This is a long read.

How We Create 'Internet 2.0' — Independent, Decentralized, and Truly Sovereign

2) This is an open discussion: you can join the conversation in the comments of the publication.
3) Participants' names have been shortened for confidentiality and readability.
Podcast

This article on GitHub • What is "Medium"? • M. P.:

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. In order for provocateurs to sneak into some conference and start provoking, we need to be doing something illegal—according to the legal acts that exist, we are deploying Wi-Fi points; firstly, we are not legal entities, and secondly, we do not provide access to the internet—only I2P.

On the agenda, what questions do we have: firstly, it is Yggdrasil, which does not give us peace day or night, right?

Sh.:

The legal aspect... The legal aspect—yes, of course—our comrade will join us, and we will discuss it. Furthermore, we also wanted to discuss the social network—it is half-alive, half-dead...

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Can we set up HumHub in Yggdrasil?

The legal aspect... Generally, yes. But why raise it when we can just provide access?

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Yes, not bad.

The legal aspect... That is, the question of transport is very acute— I2P is slow, and the network concept at the protocol level does not assume it will be very fast. This is normal. From the perspective of the average user, it is, of course, not good.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. M. S.:

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? More than that. By the way, actually, a question about the nodes: let's say, you can place nodes in certain locations that operate continuously — do you do that?

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Well, actually, yes: we essentially have 'Medium' as a decentralized provider, where each operator with their own endpoints serves as their own ISP, i.e., provider.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? Be your own provider.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Yes: be your own provider. That is, independent, decentralized, and sovereign.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? But what about those who won't always be online — logging in and out? One way or another, the nearby nodes will all be connected, and there is such a thing as a public peer.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. No, the thing is that we mark such nodes as semi-available, and there’s nothing wrong with that, really: it just means the indicator will be yellow instead of green.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? No, well, in terms of speed — not everyone will be bothered about constant connectivity.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. In general, yes. But this approach is problematic because you can’t guarantee the authenticity of all endpoints, that they will behave the same way. Someone might act according to their own rules.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? This is the specificity of the equipment…

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. This is the specificity of any decentralized networks, really. It’s not just about the hardware, but about the operators — if something doesn’t suit them, they might block you.

Our users' safety depends on the authenticity of these endpoints, meaning they are all configured the same way. Not all users are genius hackers who understand why they shouldn’t enter passwords without HTTPS on the I2P network when connecting through 'Medium'; by default, it seems secure, but if you go through 'Medium', then…

The legal aspect... We will see your passwords!

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Yes. We have to take such precautions.

The legal aspect... Therefore, for the sake of security, please create long, incomprehensible passwords!

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Ah, no, the problem is that this won’t save you from the major’s oversight — I mean, we assume that every 'Medium' endpoint is compromised by default and that the major is watching.

You can’t access the I2P network without HTTPS because all data between the connection node, i.e., the router, and the subscriber is transmitted in decrypted form, which is unsafe. So, from that perspective, any such use must be curtailed.

M. S. Further regarding points that can be set up not directly at home or at the dacha; points that could be connected to a specific power source and installed in some park areas, because, at the moment, we need some coverage anyway...

The legal aspect... By voluntary coercion, setting up with acquaintances and relatives.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? Have you drawn up a rough plan on paper of how things will look? Or is everything still only being discussed like this?

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. In theory, we didn’t even have a question about taking paper and drawing. What to draw? Everything is already straightforward and clear.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Well, actually, comparing 'Medium' to a benign tumor is accurate; that is, while it's small, it's not visible and doesn't concern anyone. When there's a lot of it — what can be done then?

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? Regarding concerns about communication control, we all understand that there are people who want to control absolutely everything.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. There's a kind of dissonance: a centralized state — decentralized networks.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? And to the point that the internet was initially pushed by private individuals, that's why we don't have the same issues as in China.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Well, we shouldn't compare with China for one reason: the percentage of people who know English there is very small. Why would they need a different internet? They don't really relate to it at all.

I spoke with a Chinese person, everything is going smoothly.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? No, we need to understand in which areas people are ready to go into the gray zone...

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Somehow determining the boundary of these vague moments...

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? Setting a point next to the FSB is a direct provocation; no need to do that.

If, roughly speaking, you set up a router somewhere in a field that will be distributing something — well, that's fine.

No need to provoke. That's all.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. I completely agree regarding provocation.

The legal aspect... A lot of similar things have proliferated now.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. That is, our position is about maintaining neutrality and calmness... And not crossing boundaries, so to speak. That's it.

We are not going to organize any NGO — everything is based on voluntary grounds. Essentially, 'Medium' is just the name of the point. SSID. Nothing is being monetized.

If the government starts terrorizing users — that's a question for the authorities, not for the users.

The legal aspect... We have an excessive paranoia about the authorities being interested.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? We still download from torrents, we watch pirated movies and series—no big deal. We don't worry. But as soon as someone thinks about creating a decentralized social network, suddenly there's talk about an unexpected danger.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. The risks are greatly exaggerated.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? Therefore, I don't know how reasonable it is to worry at all… No one will risk everything just to reach some enthusiast who is doing something for fun.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. If we don't write the apartment number—then of course!

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? No, but why? The question is—why?

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. We won't.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? At this moment, there are a huge number of quite radical groups on 'VKontakte'. The question is: how many of them get closed each day?

The legal aspect... All these current events—fuel for paranoia—prosecutions for reposting—are done based on tips.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. And they are not done selectively—just randomly: bam! And that's it: to meet the quota.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? Who should sit in a decentralized small project to attract people who are very conservative in their thinking? This might interest some specialists, but how many similar projects actually exist?

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Of course, take Yggdrasil, Hyperboria...

The legal aspect... We don't really install Linux.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? And again: the reward for capturing such people, who are quite useless for their work—is nothing. So, what do they gain from this?

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Well, for example, take the story with Bogatov, the mathematician?

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? The story with Bogatov is a story where a guy, let's say, yes: he set up a node, and through it someone threatened someone...

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Well, it’s all clear here—he took on all these risks...

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? Yes. First of all, he took on risks, and secondly, excuse me, there was indeed such a resonant thing. Once again: who here and now will do something through this network?

Now those who will come to it will be solely interested in this project as a project: not to implement something or to negotiate drug deliveries, or to kill someone...

The essence is that if this ever becomes important to someone, it will happen when a critical mass is accumulated. And it’s not even certain that it will be accumulated.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Even if this were of interest to politicians, who, let's be honest, don't really understand the principles of the global network's functioning...

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? Oh, and this is already a completely separate topic... What are encryption keys? Encryption keys are, first and foremost, about trust. They are a level of people who speak on the topic of encryption keys. They approach someone who read something from the podium about the need for encryption keys—like a specialist—and ask them: what are encryption keys? They answer that you should ask specialists, although they are supposedly a specialist themselves.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. So, their main concern is that the goal justifies the means. But many examples can be given here: some cannot even answer what IP stands for—Internet Protocol.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. I now propose to discuss transport. So, we had I2P and we have Yggdrasil. There is an option to replace I2P with Yggdrasil.

The legal aspect... It's a good option.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Comments are needed. Why? There should be a strong argument.

The legal aspect... Yggdrasil will be faster.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. And only for that reason? But it's much easier to identify participants. There is encryption there, of course—right out of the box—that's good, but not like in I2P.

The downside of I2P is that it's slow. But! In any book on cryptography, no matter which one you open, you'll be told from the very first pages—choose: either fast or secure. From this standpoint, I2P excels, despite what people say: 'No, we won't use this; there’s nothing there at all.' Well, how can you say there's nothing? Here, we set up HumHub.

So, here again we have to choose: what do we prefer—Yggdrasil is good when there are many points and traffic isn't going through the internet—but between the points themselves.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. The sticking point for us is either speed or security. What do we want? There’s an issue, you see: the connection channel between the 'Medium' subscriber and the I2P point is insecure. So, we need the resources we provide to already be with HTTPS—that is, a transport layer of security. Because the traffic is decrypted at the I2P router of the provider and transmitted over an unsecured channel to us.

The question is how to secure potential users: the simplest radical solution is to set up a resource park—a forum, an image board, a social network—and link them all with HTTPS.

The legal aspect... Can we connect any messenger at all?

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Of course, we can perhaps think of a messenger that would work in overlay mode over I2P.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? In any case, if we are talking about messengers, it’s mostly text... The speed is fine.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Actually, I have a question to raise for discussion — can we set up not only a transparent web proxy for web services at one 'Medium' point but also some kind of file-sharing service, something along those lines?

I’m exaggerating to make the point clear. So that it triggers some ports for file sharing, some for web proxy, and a chat or some messenger. Trigger some ports for the messenger, and everything will be fine.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. We need to discuss the rules of behavior online. Digital hygiene. Bring ordinary people up to speed — for example, why you shouldn't send your passwords through 'Medium' if you are visiting a site without HTTPS.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? The essence is that people who don’t understand that you shouldn’t send passwords through, say, VK — shouldn’t transmit them through chats and all that...

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. No, actually, I was talking about something else: I mean that it’s not about transmitting passwords to anyone, not at all; I’m talking about a different issue. In 'Medium', the situation is indicated a little differently: it's the same reason why you shouldn’t enter your password on unprotected sites while using Tor.

Usually, users don’t realize that if you’re connected through your I2P router without connecting to 'Medium', there is no problem — your traffic is encrypted, and you don’t need to worry about your data. But when you use 'Medium', you must first assume that this point has already been compromised by a certain major. A certain major is listening to everything you say.

When you enter your password, what happens is: your password is transmitted over an unprotected channel from you to the major's router, and only then does it enter the I2P network. The major can listen in. All other nodes — transit nodes — can’t. That's the problem.

I can briefly and simply explain with a very accessible example how asymmetric cryptography works and why 'Medium' is more than suitable as a transport.

Imagine we have a friend from Moscow and a friend from Australia. One of them needs to send a package with a million dollars to Australia. He doesn't want to do it through Sberbank due to high fees.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? So he sends it via a courier.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Yes: so he sends the suitcase filled with cash directly via a courier. I take a lock and attach it to the suitcase. Let's agree that we cannot break the lock.

We hand the suitcase to the courier. The courier carries the suitcase to our friend in Australia. The Australian friend is puzzled: “How will I open the suitcase? I don't have the key!”

I ask him to attach his lock to the suitcase and send it back to me. The courier is confused but returns the suitcase. I remove my lock. The friend's lock remains on the suitcase. I send the suitcase to Australia. The friend removes his lock.

Sleight of hand and no fraud.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? Well, in general, the setting of how much we lock ourselves away from others needs to be balanced. It shouldn't be overly complicated.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. Having certain boundaries.

More than that. By the way, a question regarding points: let’s put it this way, can nodes be placed in certain locations that are operational constantly—do you do that? The biggest hole in security will always sit in front of the monitor, behind the keyboard… Until the level of the people sitting at computers is raised, we won’t be able to fully secure the use of this network.

Today we want to raise important questions regarding the organization of the network—long-term plans and so on. Well, we have already started a bit, jumping ahead in the discussion, and stopped at the problem of dissenters. Some were concerned about negative criticism in the comments, saying that bad actors would come and take everyone away. We essentially just need to gradually increase the number of sites in I2P that support HTTPS. I advocate for HTTPS in I2P specifically to ensure security at the transport level.

Discussion on GitHub • List of all network nodes • Instructions for setting up your AP • Adding your node to the list

Channel on Telegram: @medium_isp

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster