Slashdot Mirror


New Kazaa Lite Protects Identity

Denver_80203 writes "Found this story about the new Kazaa K++ 2.4.0 and it's new sister program which claim to protect your identity while sharing files. Any of you folk know how legit this could be? We all knew it wouldn't be long... is this the war or just another battle?"

22 of 668 comments (clear)

  1. Kazaa K++ is an excellent program by Ice_Balrog · · Score: 5, Informative

    I don't know if Kazaa K++ can hide your identity, but what I do know is this: Kazaa K++ is an excellent program. It is so much better than vanilla Kazaa. No ads, spyware, many cool features make it a great program.

    --
    #include "sig.h"
    1. Re:Kazaa K++ is an excellent program by aldousd666 · · Score: 4, Informative

      I was going to mod you down, but instead I'll be informative. Spyware can be detected by checking the network connections, and/or sniffing packets. I'm sure somewhere out there (people who work for kolla.de or lavasoft) people are already doing this. You can't hide spyware from a hacker. If you don't know anything about what I'm saying, try netstat -a at a command prompt (dos) you can see your incoming/outgoing connections. If you do it with Cydoor enabled kazaa, you'll notice some shifty odd IP addresses, which you can investigate further by jumping on a linux box and 'dig'-ing for the source, or nslookup them on you windows box (far less complete) to see who is connected to you. Some programs may hide spyware in the connection to their servers, which would be the way that it would have to in the new Kazaa in order to appear spyware free, but the guys with the packet sniffers would eventually dig this out as well. If they say it's spyware free, they'd better not be lying, becasue they will eventually be exposed.

      --
      Speak for yourself.
  2. How? by bazik · · Score: 4, Informative

    How can you hide your identify on a Peer2Peer system where other users get your IP when they connect to your machine to download stuff (for backup reason of course)?

    I doubt there is a way... netstat kills your privacy :P

    --


    --
    One by one the penguins steal my sanity...
  3. A Most Important New Feature by Entropy248 · · Score: 3, Informative

    The new versions contain several features designed to foil scanning attempts. PeerGuardian attempts to catalog a range of IP addresses used by or suspected to be used by labels, the Motion Picture Association of America, the Recording Industry Association of America, and other agencies. The database is built by contributions of individual users, although the methodology used to determine and verify the IP addresses is unclear.

    Stop trying to flood my P2P network...
    Now we have blacklisting and whitelisting (through Sig2DAT). Though both of these methods together would seem to defeat P2P "spammers", the easiest way for them to get around this might be to spam the whitelist. The next move in the P2P wars remains uncertain.

  4. Re:Still isn't available for Linux though... by SugoiMonkey · · Score: 5, Informative

    mldonkey is pretty good and has Fast Track (meaning Kazaa) support.

  5. Re:This isn't surprising. . . by Doctor7 · · Score: 3, Informative

    It doesn't use a fixed list of IPs, it links in to a user-created database, so that shouldn't be a problem. Some of the other upgrades sound a bit less convenient. One is the ability to block people from requesting 'show all files from this user' - great for people with a directory full of infringing material, not so great for someone like me who's sharing fan music videos and wants anyone who downloads one to be able to see what else I've got - so if this feature isn't optional, I won't be upgrading.

  6. Re:Still isn't available for Linux though... by drgroove · · Score: 4, Informative

    Limewire

    Runs on anything, has a decent following, so there's a good chance the song/file/app you're looking for is available.

  7. Re:This isn't surprising. . . by Karamchand · · Score: 4, Informative

    It is optional. You can find the option in Options => Kazaa K++ Options => K++ Options => User's [sic!] can't get a list of all your shared files checkbox.
    HTH!

  8. anonymity is available by stinky+wizzleteats · · Score: 4, Informative

    In other P2P networks. Freenet and GNUnet both offer crypto and anonymity. Freenet isn't a P2P app in the pure sense. It's more of an underground www. GNUnet has better anonymity (theoretically - due to it's ability to resist traffic analysis attacks), but it is a younger project.

    When it's time to retreat from gnutella, these represent the next stage in the information war.

  9. Re:Check out UDPP2P by stikves · · Score: 5, Informative

    Please forgive me if I'm wrong, but UDPP2P does not seem to be "promising".

    I've checked the web site. It basically says "we broadcast all the queries and if someone has the file we meet each other by using secret codes hidden in those queries".

    A peer-to-peer network that does queries in terms of network-wide broadcast is always doomed to fail. Gnutalla failed (and was redesigned) the same way. Even Novell NetWare was unable to scale because of SAP (service advertising protocol).

    Nevertheless, the web site says "peers will somehow know each other". This is also a big problem in P2P networks. -- No design only big words.

    Anyways, if I were you, I'd use freenet. It's anonymous, and it works much better than the scheme explained on the web site.

  10. Re:Is it a good thing to not share? by Paddyish · · Score: 3, Informative

    No. Results would still be returned from a general search. All this would do is disable the 'see more from same user' option which allows you to browse a single user's shared file collection.

  11. Re:Still isn't available for Linux though... by Dave2+Wickham · · Score: 5, Informative

    May I point you to giFT-FastTrack?

  12. Re:umm by DoorFrame · · Score: 5, Informative

    Only law enforcement agencies can be accused of entrapment. There's no such thing for a non police corporation. They can entrap all they want. Remember, you're going to be going to civil, not criminal court.

  13. mlDonkey is better anyhow by evilad · · Score: 3, Informative

    My favorite is mldonkey, which hits a whole bunch of different networks, including FastTrack (which Kazaa uses). The gui is separate from the p2p application, so you can turn off your workstation but leave your downloads running on your server in the basement.

    I'm utterly impressed with it. Very easy to use, and I really like being able to hit all the differnt networks at once. It's also pretty cool having native guis available for linux AND windows.

  14. RIAA Should be commended by ShineyNewSlashdotAcc · · Score: 5, Informative

    It aint gonna work. The reason is simple : The rules have changed. Distribution of music is now much easier and cheaper than before and a large chunk of the old distribution network is *no longer necessary*. This is totally irrelavent as to weather or not this new distribution model is legal or not. It is happening. It probably cant be stopped(I mean the software industry tried and failed thru the 80s/early 90s)

    So now the RIAA have several choice.

    1. Try to roll back the technolgy that enables this new distribution channel. This is possible but not very likey.

    2. Use more draconian law enforment techniques. Posibble but I mean whata ya gonna do... start sending colleage kids to prison ? For what stealing a Brittney track ? Is this what we want ?

    3. Try to adapt to the new medium. Be creative and come up with new profit channels that take advantage of the medium.

    Personally I dont think 3 is very likely either... I think RIAA is going to have to be dragged kicking and screaming into the 21st century.

  15. Re:This isn't surprising. . . by Stonehand · · Score: 3, Informative

    Regarding prohibition, Amendment XVIII only prohibited manufacture, sale, transportation, importation and exportation. Technically, consumption was NOT illegal. Unless you can find a similar loophole in copyright law... it's going to be mostly an issue of pragmatism (scaring off the sharers is both easier and more efficient than scaring off the downloaders).

    --
    Only the dead have seen the end of war.
  16. !!!WARNING!!! New Kazaa-Lite turns file sharing on by fmaxwell · · Score: 4, Informative

    I installed the new version of Kazaa-lite and it apparently turned filesharing on even though I had disabled it previously. (Note: I say "apparently" because I did not check the setting immediately prior to the installation and it is theoretically possible that some other process had turned it on.) This was done despite the claim on the website that "You can just install this on top of a current Kazaa Lite installation. That way all your settings will be remembered."

    While people can debate the ethics of not sharing, how it affects the viability of P2P networks, and so forth, it should still be an individual choice.

    Turning on filesharing without the explicit permission of the user could put the user in violation of the policy at their ISP or their work. It could put them in violation of federal, state, and local laws. It could open up a big security hole, causing the user to share files that they never intended to share. This is not something that should be done without the user's knowledge and permission.

  17. Re:K++ edition by ncc74656 · · Score: 3, Informative

    The article said K++ and K-Lite are integrated with the PeerGuardian database. That's a list of IPs from which to refuse traffic. You can get the plaintext list here and run it through a converter here that converts the list into a script full of iptables commands to cut off the ??AA at your firewall, so they won't even get through to whatever filesharing software you're running.

    --
    20 January 2017: the End of an Error.
  18. spare us the theoretics and justifications by *weasel · · Score: 3, Informative

    the RIAA exists because traditionally it has been very expensive to break into the music business.
    now that the wall is being torn down, the RIAA is going out of its way to try to ensure its relevancy. (payola, tighter distribution contracts with artists, destroying the credibility of digital distribution, etc) it sucks - but it's all legal.

    all that aside this is about theft. downloading mp3s for material you haven't paid for -is- theft. whether it -should-be- or not is debatable. but under the law, it is. bummer.

    so this little arms race may be between the good intentioned hackers vs the big bad corporation - but legally it's just pirates against copyright holders.

    the fault -doesnt- lie with the consumer, it lies with the pirate. if you've noticed, not even the RIAA is saying 'p2p is bad' anymore. the specific practice of illegal distribution of music is what they're fighting now.

    they logistically can't (and don't even try to) sue -you- for downloading. it's not obvious from the information available within a p2p app whether or not you are downloading a song you have fair use rights to (if i own nevermind, i can legally download the mp3s for that album) - and it would be financially prohibitive to even try to figure that out.

    -however-, sharing the files is absolutely illegal. the RIAA -owns- the distribution rights for signed artists, and you are infringing on their copyrights by pirating that right.

    sure, maybe some day the artists will wise up - but until then, you -are- breaking the law. get used to it, get an ipod, or uninstall kazaa. check your justifications at the door.

    and whether or not p2p affects CD sales is irrelevant. discussing that is like trying to justify theft from a profitable business because they're still profitable despite the theft. sure - it's a neat little communistic self-delusion - but it's still theft under our laws.

    --
    // "Can't clowns and pirates just -try- to get along?"
  19. You don't have to give them an IP... by wirelessbuzzers · · Score: 4, Informative

    Actually, the folks at UDPP2P had an interesting idea in this regard. The client negotiates through the search network to find a server, but doesn't gets that server's IP. The server sends the data via forged UDP packets, encrypted, with some extra code to correct for out-of-order and dropped packets.

    I think there was a paper on /. a while ago about a similar method of sending data; you take a big, not quite square matrix M and multiplied the data file by it, getting a bunch of rows; you send these rows along with row IDs; once the receiver has enough of these rows, he can construct (using the row IDs) the inverse of the submatrix of M that spawned them, and derive the original message, even if the rest were dropped or corrupted. VanderMonde matrices work for this, although I imagine there's a sparser solution.

    Of course, your ISP/firewall wouldn't necessarily be happy about sending out all those fake UDPs, and many university networks throttle them. Also, the ..AA can still set up a fake server which logs you, since the server knows the client's IP, unless you proxy, which would cost in bandwidth. Or, you could send it to someone on the receiver's subnet and let them sniff, which wouldn't entirely give away their location.

    Perhaps one should point out that this is practically a new internet protocol, requiring root access and stuff... it might be better for them just to use IPSec with address hiding.

    --
    I hereby place the above post in the public domain.
    1. Re:You don't have to give them an IP... by tomtomtom · · Score: 5, Informative

      This is a really good idea. You can extend it to make it even better though.

      Part of the good thing about the erasure-correcting code approach is that if you use a big enough very low-rate code (although its quite tricky to do that with good CPU and memory efficiency) then you can have downloading from several servers concurrently without having to tell each server which parts of the files you want (just send random parts of the encoded data and theres a low chance of overlap from multiple servers).

      Now, here's the clever part: you use IP Multicast with multiple sources spoofing the same sender address. This means that (a) you save quite a lot on bandwidth since many P2P clients will be downloading the same source file (this is important since a big reason many ISPs and Universities have banned P2P is the bandwidth); and (b) it is MUCH harder (not impossible, but hard enough if you are not an ISP or a router at the very end) to find out who either the source or the destination is.

      I don't know if anyone has thought of this idea and tried to implement it. Someone should; maybe I'll give it a go when I have time.

      PS. There is a sparser and more CPU-efficient solution than VanderMonde matrices, look for Low-Density Parity Check codes.

  20. Re:That's what I needed by drinkypoo · · Score: 3, Informative
    If I lock my door on my house, you can still easily get in. That doesn't mean me not locking (or forgetting to lock) the door is inviting you to come in.

    The law does see a difference between locked and unlocked doors. Entering an unlocked door without permission (or reasonable assumption thereof, such as a place of business' front door) is trespassing. Defeating a lock and entering is breaking and entering.

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"