Explorations in Networking and Computing

9 readers
1 users here now

A place for discussing the new developments in IT networking technologies that strive to enhance and assure privacy, security, and autonomy online, ensuring equitable and strong universal access to information.

You can share info about Confidential Computing software and hardware like Intel SGX enclaves, HSI, attestation, HEADS BIOS, and vendors like Nitrokey, Purism, Fairphone, Open Source Hardware, etc.

The Tor Project, Nym, mixmaster, Yggdrasil, Veilid, and other networking technologies can be discussed here. Questions could be answered by people versed in any of these networking projects.

Also, social media in such networking paradigms could be discussed and be of interest to the wider Mastodon community. You might think about how Amethyst with LND and LNC works, for example. Or have thoughts about developing a social media Veilid application. Facebook has an onion address. What about new networking technologies incorporated into the Fediverse?

founded 5 months ago
MODERATORS
1
 
 

RAM is perfectly sufficient for full simultaneous functionality of all qubes on this X230 Thinkpad which also satisfies all the green check marks for HSI (hardware security). Latest Libreboot BIOS and no Intel ME.

  • encrypted messaging apps (Pidgin, signal-cli, Hexchat)
  • dvm veilid-server.service qube (network support)
  • sys qubes for networking like VPN, Yggdrasil, and DNS (TLS resolv and odoh.cloudflare)

  • lock LUKS with a Nitro USB A security key

  • dvm of Brave and Librewolf (in firejail) when tor is not an option
  • fully ephemeral Whonix WS dvm qube

  • Debian template upgrade to Kicksecure and enable apparmor service on all Debian

  • Vault (no networking) has LibreOffice and Keepass with a keyfile inside a FIPS security key

Pretty sweet.

2
3
3
submitted 5 months ago* (last edited 5 months ago) by lightscription to c/explorations_in_networking
 
 

Veilid is a recently developed networking paradigm that holds considerable promise for the future of autonomous and free activity on the internet. As someone just starting to think about it and try to implement the technology, what I think is most intriguing about the project is that applications are peer to peer, so that, instead of volunteers of nodes on the tor network, each person on the Veilid network with an app is hosting the computation locally on their device. Then people aren't having to rent from AWS and the like if they don't have their own servers. In other words, there is more primary local control over your contribution to the network. Of course there is more to it, but that seems to be the most innovative aspect of the project. Really cool design!

My question is: do they have a plan for EW? It is described as a "mobile first" network and most cellular phones appear to be more resistant to EMI attacks than others, which is perfect.

Anybody want to talk about Veilid?

4
1
GrapheneOS kernel (self.explorations_in_networking)
submitted 3 weeks ago* (last edited 4 days ago) by lightscription to c/explorations_in_networking
 
 

Kernel killers

5
4
Indigenous Futurism (lemmy.world)
submitted 2 months ago* (last edited 2 months ago) by lightscription to c/explorations_in_networking
 
 

Drone swarm of native symbols that appear similar to a fireworks show - Olympia,WA https://squaxinisland.org/

https://lemmy.world/pictrs/image/59db9192-9e53-4709-9f35-19c89293ac15.jpeg

6
 
 
7
5
TAILS development (lemmy.world)
submitted 4 months ago* (last edited 2 months ago) by lightscription to c/explorations_in_networking
 
 

Arti (Rust memory hardened code) https://lemmy.world/post/17930434 Keystroke Deanonymization https://lemmy.world/post/17672429

8
4
Augmented Reality and VR (www.dvidshub.net)
submitted 4 months ago* (last edited 4 months ago) by lightscription to c/explorations_in_networking
 
 

A few decades and exciting new worlds to explore, sensorially indistinguishable from IRL? https://lemmy.world/pictrs/image/e5e3626b-d8bf-4d71-9867-90d3b23e33ee.jpeg

9
10
11
 
 

Certain computing platforms like smart phones are more resilient when it comes to EMI/EMC (harmful electromagnetic interference) than others. Defense computers, for example, are designed to meet specifications like TEMPEST and MIL-STD-461. Although "Qubes Air" or cloud Qubes which could run on a cellular platform has been proposed, more development is required. Defense computers like Roda or GRiD can be found on eBay and from government surplus but the models do not have sufficient CPU power (core2duo in the instances I have seen which is close to Pentium and not nearly the i5 / i7 Intels required). There are also EMI shielding sprays with silver particles that might be applied to consumer laptops as another alternative to explore. Other than that, does anyone have ideas about creating an EMI fortified platform prototype that would be compatible with Qubes?

https://www.roda-computer.com/technology/mil-std-standards/

https://www.griduk.com/

https://forum.qubes-os.org/t/qubes-air-qubes-in-the-cloud/921

https://mgchemicals.com/products/conductive-paint/conductive-spray-paint/emi-shielding/

12
 
 

note the Polish names https://invisiblethingslab.com/ "Low level" i.e. BIOS, EC, firmware

Qubes Certified with latest 12th gen Intel i5/i7 CPUs https://novacustom.com/product/nv41-series/ (laptop) https://shop.3mdeb.com/shop/open-source-hardware/dasharo-fidelisguard-z690-qubes-os-certified/ (desktop) [RAM greater than or equal to 16GB required. VM sys qubes can be configured for lighter memory use. 32 GB of RAM is what these systems ship with and you wouldn't need to tailor qube utilization. But, really, the i5/i7 CPU is the most important part for Qubes compatibility.]

Polish Firmware Companies https://3mdeb.com/ https://www.dasharo.com/

13
3
submitted 4 months ago* (last edited 2 months ago) by lightscription to c/explorations_in_networking
 
 

Hardened Grub in Libreboot https://libreboot.org/docs/linux/grub_hardening.html

See Mate Kukri at upcoming Open Source Firmware Conference about TPM compromise.

https://libreboot.org/docs/install/spi.html Ready to get out your pi and external programmer? https://en.m.wikipedia.org/wiki/CryptoParty

14
 
 

mount issue

password defaults unchangeable

15
 
 

experiments with filtered DNS, ODOH, TLS, opportunistic/strict, etc

16
 
 

tried TAILS with Snapdragon or RISC-V (Framework) or other non-Intel processors?

17
 
 
18
 
 
19
2
submitted 5 months ago* (last edited 5 months ago) by lightscription to c/explorations_in_networking
 
 

fixed 6.4