[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Blocking addresses by default



>> With remailer abuse becoming more popular and remailers going down
>> because of complaints, there seems to be some interest in remailer
>> software that will block all email by default and will only pass
>> along email that is explicitly unblocked.

Rich wrote:
>I think this threatens serious security problems for the remailer 
>network in two ways:
>1. You'd create a list of people interested in anonymous information,
>   which could potentially be obtained by police or other armed thugs.
>2. The traffic would go down so substantially that traffic analysis     
>   would be trivial.

Yeah.  If you keep a centralized list, it's too risky.
I've been thinking about how to implement a related approach -
when the mailer receives anonymous mail for you, it sends a message saying
        Subject: Anonymous message #<cookie> 
        Hi!  You've got an anonymous message!  
        Here's how to retrieve it / block future messages / accept all
future....
        <disclaimers, explanations, etc.>
and you can send back the cookie to retrieve the message.
Blocking or accepting also using the cookie, to reduce denial-of-service
and spam attacks.  

This approach is primarily useful for terminal remailers, but if you set up 
the syntax carefully, you can get the things to relay to each other.
It's not particularly useful for posting news, though.
Since it is good for terminal remailers, that may make it less hassle
to run them.



#			Thanks;  Bill
# Bill Stewart, +1-415-442-2215 [email protected]
# You can get PGP outside the US at ftp.ox.ac.uk