holepunchto / holepunchto/hyperdht
Secure and privacy preserving DHT
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 408
- Forks
- 78
- Avg merge
- 3d 20h
- Merged PRs (30d)
- 4
Description
Good job with Hyperswarm! 👏 👏
I reckon there are no mechanisms in place in the DHT for protecting peers against passive and active attacks that could a) easily reveal the intentions of lookup initiators by leaking DHT requests and routing requests and b) allow active attackers to perform many different routing attacks, effectively serving poisonous content to lookup initiators.
Is the Hyperswam DHT somehow taking these potential vulnerabilities into consideration? If not, are there any plans to address these issues at any point? I'd be glad to discuss and help, if the topic is relevant for Hyperswarm.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue does not name files, tests, or an entry point. Begin by reviewing the DHT's current lookup and routing behavior, then clarify the passive and active attack scenarios, expected protections, and acceptance criteria with maintainers. Done cannot be defined until the threat model and scope are agreed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- distributed-systems, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100