pull down to refresh

When you say the word Cloudflare, that is exactly what you're describing. Or do we think that TLS termination and re-encryption to a private PKI does not make them see the content of every encrypted HTTP call?

128 sats \ 3 replies \ @ek OP 21 Sep

Maybe PTLCs would help decorrelate payments across hops in this case, too?

reply

It could (maybe) help against traffic being direct hard evidence, but would not prevent heuristics like timing and overall money movement. And for some reason all the heuristics bullshit is way overrated in the cases I've seen it used.

Multi-path may help a bit more depending on total penetration rate, but still it is risky. Bottom line, I think that delegating security to centralized coercible service providers is not how we create robust, private networks. It instead creates single points of failures.

reply
128 sats \ 1 reply \ @ek OP 21 Sep

Yeah, I think it could be enough to have a self-hostable FOSS version of such a protocol-aware firewall. Doesn't need to morph into a dragnet. I should research Cloudflare's history.

reply

So the reason to centralize is (traditionally) DDoS risk.

If something FOSS needs to be built, that is ok, as long as it is extremely lean and configurable.

reply