A short story with three OBIE servers, two attackers and one troublemaker. Step through it at your own pace and watch each server decide for itself.
Illustration: made-up servers and example addresses, not live data from the network.
Here, a server blocks an address when the reports it trusts reach a combined score of 1.2, its threshold, from at least two reporters, its quorum. The federation guide suggests this for three to five servers; out of the box the threshold is 1.8. A Fail2Ban report has a confidence of 0.8. These servers block in their firewalls; a new server only watches (observe mode) until its operator switches blocking on.
- Meet the neighbourhood
Three servers, each run by a different operator: a web shop (A), a university lab (B) and a homelab (C). They connect directly, with no central server. Each lists how much it trusts the others, from 0 to 1.
Planned Peers are added by hand today. Finding them automatically is planned.
- The bot hits server A
A password-guessing bot works through server after server and starts with A. A’s own log watcher (such as Fail2Ban) blocks it at once: A needs nobody’s permission to protect itself. A colleague’s mistyped passwords get an office address blocked too.
- A shares a signed report
A sends B and C a short report: the address, what it did, how often and a fingerprint of the evidence. The logs themselves stay on A. A’s digital signature proves to B and C that the report is A’s.
- One voice is not enough
B and C record A’s reports but do not block. Each scores a report: its trust in the sender times how sure the sender is. One report stays below each server’s bar, and each wants two independent reporters.
Why One mistaken or compromised server must never get an address blocked everywhere. The office address shows why.
- The bot moves on to server B
Next the bot tries B. B’s own detection catches it, and B blocks it at once. Its own report and A’s earlier one agree: two trusted voices.
- C is protected before the attack arrives
B shares its signed report with A and C. Together with A’s, two independent, trusted reports now pass C’s bar, so C blocks the bot. When the bot knocks on C minutes later, it is turned away at the door.
Planned Today the quorum counts servers, not organisations. Checking that reporters come from different networks is planned.
- The scanner only hits server C
A web scanner probes C and nowhere else. C blocks it and reports it. A and B only watch: one reporter is not enough for them, and each weighs C by its own trust. Each server decides for itself.
- Someone tries to abuse the mesh
An unknown participant floods the servers with reports to get the shop’s payment service blocked. Nobody trusts it, so its reports weigh 0, however many it sends. And the service is on A’s safety list: never blocked, whatever anyone reports.
Planned Trust that grows or shrinks with a peer’s track record is planned. Today each operator sets the numbers.
- Mistakes can be undone
A learns the office address is a colleague’s shared connection and withdraws its report with a signed revocation. A unblocks it; B and C drop it automatically. Blocks also end on their own: the scanner’s one-hour block has run out.
Planned A way for the owner of a blocked address to appeal is planned.
- Recap
Shared intelligence, sovereign enforcement: servers warn each other early, and every server still decides for itself what to block.