Ukukhishwa kwesiphequluli sewebhu se-CENO 2.0, esisebenzisa inethiwekhi ye-P2P ukudlula ukuvinjwa

Inkampani ye-eQualite ishicilele ukukhululwa kwesiphequluli sewebhu esiphathwayo i-CENO 2.0.0 (CEnsorship.NO), esiklanyelwe ukuhlela ukufinyelela olwazini ngaphansi kwezimo zokuhlolwa, ukuhlunga kwethrafikhi noma ukunqamula izingxenye ze-inthanethi kunethiwekhi yomhlaba wonke. Isiphequluli sakhelwe enjinini ye-GeckoView (esetshenziswa kuFirefox ye-Android), ithuthukiswe ikhono lokushintshana ngedatha ngenethiwekhi ye-P2P ehlukaniselwe izwe, lapho abasebenzisi babamba iqhaza ekuqondiseni kabusha ithrafikhi kumasango angaphandle anikeza ukufinyelela olwazini oludlula izihlungi. Intuthuko yephrojekthi isatshalaliswa ngaphansi kwelayisensi ye-MIT. Imihlangano eseyilungile iyatholakala ku-Google Play.

Ukusebenza kwe-P2P kuthuthelwe kulabhulali ye-Ouinet ehlukile, engasetshenziswa ukwengeza amathuluzi okudlula ukucwaninga ezinhlelweni zokusebenza ezingafanele. Isiphequluli se-CENO kanye nomtapo wezincwadi we-Ouinet zikuvumela ukuthi ufinyelele ulwazi ngaphansi kwezimo zokuvinjwa okusebenzayo kwamaseva abamba iqhaza, ama-VPN, amasango nezinye izindlela ezimaphakathi zokudlula ukuhlunga kwethrafikhi, kuze kufike lapho kuvalwe khona i-inthanethi ngokuphelele ezindaweni ezihloliwe (ngokuvinjwa okuphelele, okuqukethwe. ingasatshalaliswa kunqolobane noma kumishini yokugcina yendawo) .

Le phrojekthi isebenzisa ukugcinwa kwesikhashana kokuqukethwe komsebenzisi ngamunye, igcina inqolobane yokuqukethwe okudumile. Uma umsebenzisi evula isayithi, okuqukethwe okulandiwe kugcinwa kunqolobane endaweni futhi kwenziwe kutholakale kubahlanganyeli benethiwekhi ye-P2P abangakwazi ukufinyelela ngokuqondile kusisetshenziswa noma badlule amasango. Idivayisi ngayinye igcina kuphela idatha ecelwe ngokuqondile kuleyo divayisi. Ukuhlonzwa kwamakhasi kunqolobane kwenziwa kusetshenziswa i-hash evela ku-URL. Yonke idatha eyengeziwe ehlotshaniswa nekhasi, njengezithombe, imibhalo nezitayela, iqoqwa futhi ihanjiswe ndawonye ngaphansi kwesihlonzi esisodwa.

Ukuze uthole ukufinyelela kokuqukethwe okusha, ukufinyelela okuqondile okuvinjiwe, kusetshenziswa amasango ommeleli akhethekile (ama-injection), atholakala ezingxenyeni zangaphandle zenethiwekhi ezingekho ngaphansi kokuhlolwa. Ulwazi phakathi kweklayenti kanye nesango lubethelwa kusetshenziswa ukubethela kokhiye womphakathi. Amasiginesha edijithali asetshenziselwa ukukhomba amasango nokuvimbela ukwethulwa kwamasango anonya, futhi okhiye bamasango asekelwa iphrojekthi bafakiwe ekulethweni kwesiphequluli.

Ukuze ufinyelele isango lapho livinjiwe, ukuxhumana kweketango kusekelwa abanye abasebenzisi abenza njengabameleli bokudlulisela ithrafikhi esangweni (idatha ibethelwe ngokhiye wesango, ongavumeli abasebenzisi bezokuthutha okuthunyelwa isicelo ngezinhlelo zabo. ukungenela ithrafikhi noma ukunquma okuqukethwe ). Amasistimu eklayenti awathumeli izicelo zangaphandle egameni labanye abasebenzisi, kodwa abuyisela idatha esuka kunqolobane noma asetshenziswe njengesixhumanisi sokusungula umhubhe oya kusango lommeleli.

Ukukhishwa kwesiphequluli sewebhu se-CENO 2.0, esisebenzisa inethiwekhi ye-P2P ukudlula ukuvinjwa

Isiphequluli siqala ngokuzama ukuletha izicelo ezivamile ngokuqondile, futhi uma isicelo esiqondile sihluleka, sisesha inqolobane esabalalisiwe. Uma i-URL ingekho kunqolobane, ulwazi lucelwa ngokuxhuma kusango lommeleli noma ngokufinyelela isango ngomunye umsebenzisi. Idatha ebucayi njengamakhukhi ayigcinwa kunqolobane.

Ukukhishwa kwesiphequluli sewebhu se-CENO 2.0, esisebenzisa inethiwekhi ye-P2P ukudlula ukuvinjwa

Isistimu ngayinye kunethiwekhi ye-P2P ihlinzekwa ngesihlonzi sangaphakathi esisetshenziselwa umzila kunethiwekhi ye-P2P, kodwa ayiboshelwe endaweni yangempela yomsebenzisi. Ukuthembeka kolwazi oludluliselwe futhi olugcinwe kunqolobane kuqinisekiswa ngokusebenzisa amasignesha edijithali (Ed25519). Ithrafikhi edluliswayo ibethelwe kusetshenziswa i-TLS. Ithebula le-hash elisabalalisiwe (i-DHT) lisetshenziselwa ukufinyelela ulwazi mayelana nesakhiwo senethiwekhi, ababambiqhaza, nokuqukethwe okugcinwe kunqolobane. Uma kunesidingo, i-µTP noma i-Tor ingasetshenziswa njengesithuthi ngaphezu kwe-HTTP.

Ngesikhathi esifanayo, i-CENO ayinikezi ukungaziwa futhi ulwazi mayelana nezicelo ezithunyelwe luyatholakala ukuze luhlaziywe kumadivayisi ababambiqhaza (isibonelo, i-hashi ingasetshenziswa ukunquma ukuthi umsebenzisi ufinyelele isayithi elithile). Ngezicelo eziyimfihlo, isibonelo, lezo ezidinga ukuxhunywa ku-akhawunti yakho ngemeyili nezingosi zokuxhumana nabantu, kuhlongozwa ukuthi kusetshenziswe ithebhu eyimfihlo ehlukile, lapho idatha icelwa kuphela ngokuqondile noma ngesango lommeleli, kodwa ngaphandle kokufinyelela inqolobane nangaphandle ukuzinza kunqolobane.

Phakathi kwezinguquko ekukhishweni okusha:

  • Idizayini yephaneli ishintshiwe futhi isixhumi esibonakalayo se-configurator siklanywe kabusha.
  • Kungenzeka ukuchaza ukuziphatha okuzenzakalelayo kwenkinobho ethi Sula futhi ususe le nkinobho kuphaneli nakumenyu.
  • Isihleli manje sinamandla okusula idatha yesiphequluli, okuhlanganisa nokususa okukhethiwe ngohlu.
  • Izinketho zemenyu zihlelwe kabusha.
  • Izinketho zokwenza ngokwezifiso isixhumi esibonakalayo zifakiwe kumenyu encane ehlukile.
  • Inguqulo yelabhulali ye-Ouinet (0.21.5) kanye ne-Ceno Extension (1.6.1) zibuyekeziwe, injini ye-GeckoView kanye nemitapo yolwazi ye-Mozilla kuvumelaniswe ne-Firefox ku-Android 108.
  • Kwengezwe ukwenziwa kwasendaweni kolimi lwesi-Russian.
  • Izilungiselelo ezingeziwe zokuphatha amapharamitha etimu nezinjini zokusesha.

Source: opennet.ru

Engeza amazwana