What's the difference between using the Tor and Ceno browsers?
> Unlike Tor Browser, Ceno Browser is not a tool for anonymity, which is Tor's primary purpose. In the Tor network, network traffic is encrypted and routed through a network of relays run by volunteers, and appears to originate from the IP address of an exit node. Tor is an excellent option for privacy from Internet surveillance and website operators. If it works in your network environment, we recommend it, provided that you've also read their support documentation.
> Ceno's primary distinction from a VPN is that it does attempt to route all of your website requests through the decentralized network. When a website is available without restriction, Ceno will simply connect to it like a normal web browser. Also, Ceno users cache and share content with each other. This reduces the strain on censorship circumvention nodes and improves deliverability.
You dont need the Web to browse web pages. You need 1) a BitTorrent bootstrap server in your network 2) web pages cache inside your network 3) Ceno browser
This is why Ceno scrapes, caches then announces hundreds of media websites on BT https://schedule.ceno.app/
If the cache is inside your network (e.g. Iran) then that website is available through Ceno browser
In Public mode, Ceno will look into the BitTorrent network to see if another Ceno user has recently shared the requested page. If the service can identify the requested page, it will retrieve that page from another user's device. If the content is not available, Ceno will contact several Injectors to request that website and have it delivered to you.
In Personal mode, you will only contact the Injectors to have that website fetched and delivered to you. The search will not connect to the BitTorrent network and will not attempt to locate the content on other users' devices.
To ensure that your Ceno client can always contact an Injector, we have also created Bridges. If the Injectors are blocked on your network, the Ceno app will look for available Bridges, who will forward your request to the Injectors. The Ceno network currently features around 6,000 Bridges. Their number is always growing.
So on the one side it's some kind of shared cache of website resources, and on the other some kind of distributed tor-like edge network?
Quite clever! I wonder if it works well though, and if there is a risk of content injection by adversaries.
How is Ceno making sure someone is not poisoning the cache?
edit: I try to read the paper and it's just referencing some RFC, which is not making me smart at all.
Again, how am I sure that when I am reading something from the cache, it's really serving what the site was serving somewhere else, and the person saving it there didn't modify it? Is it signed by the original page SSL cert?
edit2: ahh the "injector server", which is run by Ceno, retrieves the page and signs it. So you are moving the trust to Ceno and the central Ceno server actually does the browsing...? So the injectors can just see all the traffic? But that's inevitable I guess, someone needs to see the traffic
Am I reading this right? You do still need internet access, to actually retrieve the page from someone else. Also I'm not sure how this will reduce data costs. Do providers charge different amounts for getting data from different servers? The same amount of data is still going into your device, it's just coming from somewhere else than usual
Yes, I was confused as well. The current Hacker News title is “Ceno, browse the web without internet access”, but on the official site the headline/ reads “Ceno Browser | Share the Web!”.
That mismatch is likely what is causing the confusion. The HN title probably should be updated to reflect the current title used on the site.
Another possibility is that the original title actually was “browse the web without internet access” and the developers later changed the site headline after the post was submitted to HN.
The hope/promise is that the handful of people with internet access in a blackedout country can spread content around in a way that is seemless to the end user.
> route all of your website requests through the decentralized network
I thought this sounded like Freenet. Searching for "ceno" and "freenet" together led to this repository, which said "CENO uses the Freenet censorship resistant platform for communications and storage":
I think the relevant use case for this are places like Russia (one is even quoted in the testimonials) where I've seen concern about the country isolating itself from the outside internet, due to the various regional tests actually trialling this.
I've seen such users ask about ways to prepare storing outside data in the event it becomes permanent. Some have suggested mesh networks, others downloading Wikipedia and torrenting things.
So it seems that this is useful where internet is still available but is restricted at say the ISP level. It seems to be a browser that when a page is unavailable it checks for Ceno torrents of the page from other users and serves that instead.
This looks like a great project, but there's one big problem that I can see...
If it's based on BitTorrent, then surely that means that anybody who has the content that you want to see (or who advertises that they have the content you want to see...) will be able to see your IP address? Like how the movie industry can catch people who are sharing movies on BitTorrent?
Obviously, an attacker wwould probably need to use a separate BitTorrent client to do this, because I'm sure the IP addresses won't be displayed in the app itself, but that seems like it could potentially be possible.
I really hope I'm wrong on this, because other than that seemingly-big privacy flaw, this seems pretty great otherwise.
Wouldn't this be better as a proxy? I don't want to install yet another browser. I already av Vivaldi in addition to Firefox so that I can access web sites that haven't been tested with Firefox.
thinking out loud: it'd be great if web servers could sign their responses+timestamp, so you could guarantee getting the right content even through such intermediaries
40 comments
>
What's the difference between using the Tor and Ceno browsers?> Unlike Tor Browser, Ceno Browser is not a tool for anonymity, which is Tor's primary purpose. In the Tor network, network traffic is encrypted and routed through a network of relays run by volunteers, and appears to originate from the IP address of an exit node. Tor is an excellent option for privacy from Internet surveillance and website operators. If it works in your network environment, we recommend it, provided that you've also read their support documentation.
> Ceno's primary distinction from a VPN is that it does attempt to route all of your website requests through the decentralized network. When a website is available without restriction, Ceno will simply connect to it like a normal web browser. Also, Ceno users cache and share content with each other. This reduces the strain on censorship circumvention nodes and improves deliverability.
source: https://ceno.app/en/faq.html
>Ceno users cache
Good way to get in trouble for cp
EU: Digital Services Act Article 5: Caching https://www.eu-digital-services-act.com/Digital_Services_Act...
This is why Ceno scrapes, caches then announces hundreds of media websites on BT https://schedule.ceno.app/
If the cache is inside your network (e.g. Iran) then that website is available through Ceno browser
Quite clever! I wonder if it works well though, and if there is a risk of content injection by adversaries.
edit: I try to read the paper and it's just referencing some RFC, which is not making me smart at all.
Again, how am I sure that when I am reading something from the cache, it's really serving what the site was serving somewhere else, and the person saving it there didn't modify it? Is it signed by the original page SSL cert?
edit2: ahh the "injector server", which is run by Ceno, retrieves the page and signs it. So you are moving the trust to Ceno and the central Ceno server actually does the browsing...? So the injectors can just see all the traffic? But that's inevitable I guess, someone needs to see the traffic
That mismatch is likely what is causing the confusion. The HN title probably should be updated to reflect the current title used on the site.
Another possibility is that the original title actually was “browse the web without internet access” and the developers later changed the site headline after the post was submitted to HN.
The hope/promise is that the handful of people with internet access in a blackedout country can spread content around in a way that is seemless to the end user.
I'd prefer mesh networks running spam resistant, private&anonymous protocols.
> route all of your website requests through the decentralized network
I thought this sounded like Freenet. Searching for "ceno" and "freenet" together led to this repository, which said "CENO uses the Freenet censorship resistant platform for communications and storage":
https://github.com/censorship-no-archive/ceno1
Looks like they have since archived everything on github and moved to gitlab.
I've seen such users ask about ways to prepare storing outside data in the event it becomes permanent. Some have suggested mesh networks, others downloading Wikipedia and torrenting things.
So it seems that this is useful where internet is still available but is restricted at say the ISP level. It seems to be a browser that when a page is unavailable it checks for Ceno torrents of the page from other users and serves that instead.
If it's based on BitTorrent, then surely that means that anybody who has the content that you want to see (or who advertises that they have the content you want to see...) will be able to see your IP address? Like how the movie industry can catch people who are sharing movies on BitTorrent?
Obviously, an attacker wwould probably need to use a separate BitTorrent client to do this, because I'm sure the IP addresses won't be displayed in the app itself, but that seems like it could potentially be possible.
I really hope I'm wrong on this, because other than that seemingly-big privacy flaw, this seems pretty great otherwise.
Better executive summary: "A browser that lets you bypass censorship via BitTorrent-based residential proxies and Ceno-owned proxies"
If I understand correctly the Internet Archive provides torrents for everything they archive.
> Ceno, browse the web without internet access
Another Crypto AG.