[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

No subject



In-reply-to: Johan Helsingius' message of Tue, 23 Feb 1993 10:14:27 +0200.
	     <[email protected]>

-----BEGIN PGP SIGNED MESSAGE-----

> Well, then, how *should* anon.penet.fi operate? I really am open to
> suggestions...

I'll restrict my comments to anonymous email, but the application to
anonymous USENET posting is analogous.

I'll ignore messages of the sort

	From: Alice
	To: [email protected]
	X-Anon-To: Bob
	X-Anon-Password: zzz

since it's clear that Alice's identity should be concealed in this
case.  The problem we're dealing with is the message of the sort

	From: Alice
	To: Bob <[email protected]>

Should the remailer expose Alice's identity in the message that it
forwards to Bob?  If it does so blindly, Alice's anonymous identity is
subject to accidental exposure.  If it does not conceal Alice's
identity, then certain expectations of anonymity might not be realized
(according to Johan).

Here's a way out that will satisfy me and Johan: assign Alice a new
pseudonym here and now, one that will be good for replies only.  If
Alice has registered with the remailer in the past, i.e., if she has a
password, then she knows how to X-Anon-To:, but has opted not to.  If
she has not registered, then it is also appropriate to assign her a new
ID.  However, should she later register, I suggest she be given a new,
permanent, password-protected ID, just in case her earlier reply
inadvertently exposed her real ID (in the way we have been discussing).

In essence, I'm suggesting that the Finnish remailer have two classes
of anonymous IDs, one that is password protected, and one that is not.
The former should never be used without the X-Anon-Password header.

DEADBEAT

P.S.: Another suggestion I would make is that the remailer _not_ strip
In-Reply-To: headers.

-----BEGIN PGP SIGNATURE-----
Version: 2.1

iQBFAgUBK4pRavFZTpBW/B35AQGC2AF/Q+LZt6T+SupvLftQom7xlon7+8LOGLpX
bSy1lT0XEyzPQ1nwCDGOr0+MF9KdwPEO
=AoKd
-----END PGP SIGNATURE-----
-------------------------------------------------------------------------
To find out more about the anon service, send mail to [email protected].
Due to the double-blind system, any replies to this message will be anonymized,
and an anonymous id will be allocated automatically. You have been warned.
Please report any problems, inappropriate use etc. to [email protected].
*IMPORTANT server security update*, mail to [email protected] for details.