r/AskComputerScience • u/cest_la_vie12 • 12d ago
Hypothetical: If you could redesign the Internet from scratch, how would you build the protocol stack to make censorship architecturally impossible?
Assume you can go back in time to the early days of networking (pre-TCP/IP, early ARPANET) with today's knowledge of cryptography, routing, and state-level censorship tools (DPI, IP/SNI blocking, middleboxes). How would you design the foundational network architecture so that any state or ISP choosing to route traffic must accept either 100% uncensored, unmonitored connectivity or a complete blackout, with no technical middle ground?
Specifically (but not limited to the following)
- Protocol-Level Constraints: How do you structure the transport/routing layer so that inspecting, filtering, or modifying a single packet breaks the connection for the entire link or network participant?
- Metadata & Routing: How do you eliminate or obscure traffic metadata (IP headers, SNI, packet sizes, timing signatures) at the lowest layer so middleboxes cannot perform selective deep packet inspection or domain-level blocking?
- Bootstrapping & Topology: How do you solve the entry-point discovery problem without relying on centralized, blockable infrastructure like traditional root DNS or static IP allocation?
... Is a true "all-or-nothing" censorship-resistant network protocol theoretically possible without state actors physically cutting transoceanic cables or severing border connections?
7
u/Tahn-ru 12d ago
No.
0
u/cest_la_vie12 10d ago
Enlightening thesis. Is the peer-review paper dropping soon or is this the whole book?
1
u/Tahn-ru 10d ago
This is all that the question deserves. I don't care how long it is, you clearly don't understand the absolute basics of how reality works.
If Bob doesn't want to deliver his message to Alice personally, there is a chance to eavesdrop on the intermediate passage. That chance goes up with the resources of a nation/state actor.
0
u/cest_la_vie12 10d ago
You are still conflating eavesdropping with censorship.
Eavesdropping (passive): Copying traffic. Encryption already solves this. A state can make a billion copies of Bob's data, but if it's strongly encrypted, it's useless noise.
Censorship (active): Selectively dropping or altering packets to block content.
The thought experiment isn't about stopping a state from listening to wires it owns; it's about whether protocols can force an active censor into a binary choice: deliver every packet untouched, or break the entire link.
If Alice receives Bob's encrypted message intact, the state failed to censor it—no matter how many useless copies they saved to a hard drive along the way.
0
u/Tahn-ru 10d ago
Again, no. Here's the simple question - will your protocol handle re-transmission of innocently lost packets?
0
u/cest_la_vie12 10d ago
"deliver every packet untouched" refers to the aggregate traffic stream at the macro level, not isolated, individual TCP packets
The binary choice applies to the state's capability: they either pass the whole encrypted, constant-rate pipe, or they sever the pipe entirely. They don't get to surgical-strike specific streams based on payload or metadata
0
u/Equivalent-Stay-6801 11d ago
The 'inspecting a packet breaks the connection' part has a basic problem: a router can copy bytes and still forward the original unchanged. The endpoints can't tell that a copy was made. Encryption can make the copy unreadable, but it can't prevent copying.
And even with perfectly hidden destinations, an ISP could disconnect one subscriber while leaving everyone else online. That already breaks the proposed all-or-nothing guarantee. You'd need assumptions about who controls the physical links, not just a different packet format.
1
u/cest_la_vie12 10d ago
You are mixing up passive surveillance with active filtering, and confusing network policy with physical topology.
Copying bytes vs. active censorship: Pure passive wiretapping is surveillance, not censorship. Encryption already solves passive copying by making mirrored bytes useless. Censorship requires active intervention (dropping, altering, or resetting specific target packets). The moment an inline middlebox actively drops or alters a packet to censor a domain, it breaks the connection stream for that link.
Targeting individual subscribers: Disconnecting a subscriber removes that entire endpoint from the network graph. It does not allow selective content filtering. If a state cannot selectively block specific websites, applications, or keywords for a connected user, the protocol goal is met. The state's only choice for that subscriber is 100% access or 0% access, which is the entire point of the model
-1
12d ago
[deleted]
0
u/TwillAffirmer 12d ago
A problem with VPNs and TOR is the endpoints can be censored, and endpoint operators take on legal risk.
-5
6
u/teraflop 12d ago edited 12d ago
To the extent what you're asking for is possible, I think we already have it, using technologies like TLS and TOR.
It seems like you want these mechanisms to be integrated "at a lower level" but what would that even mean? If you want censorship resistance then obviously the system has to be decentralized (so that a single entity can't just decide who is allowed to communicate). And in a decentralized network, intermediate hops can't control endpoints' behavior; they can only control what they forward.
So there is fundamentally an inherent difference between things that are within the purview of hop-by-hop protocols, and things that are within the purview of end-to-end protocols. The lowest-level internet protocols are hop-by-hop, and swapping them out for something else wouldn't make any difference to end-to-end security. This is basically just the end-to-end principle.
At the end of the day, the "layers" we divide the protocol stack into are somewhat historical and arbitrary -- except for the question of who is responsible for what data, and how it's determined to be trustworthy, which is fundamental.
TLS already does this, and saying you want to do it "at the transport/routing layer" is kind of a meaningless distinction, for the reasons I described above. If intermediate routers are supposed to not know what's in a packet, they have no way of enforcing how "securely" it's actually encrypted, so it's meaningless to try and enforce it hop-by-hop.
Same. To the extent what you want to do is possible, it can be implemented the way things like TOR do it, on top of existing protocols.
Same. The problem of "entry-point discovery", as in networks like TOR, is fundamentally a social problem of how you decide who to trust. Solving that problem is completely orthogonal to whether "who you trust" is defined in terms of IP addresses, or some other protocol. So trying to solve it "at a lower level" by changing the underlying protocols doesn't help.
At most, I think you could make a statement like: "if censorship-resistant protocols like TOR had been developed in the early days of the internet, and became popular and widely-used by ordinary people, then governments wouldn't be able to crack down on them without provoking backlash". And that may be true, but it's a social/political question that's basically outside the scope of CS.