1993-02-08 - Re:

Header Data

From: Johan Helsingius <julf@penet.FI>
To: Anonymous <root@extropia.wimsey.com>
Message Hash: 8b0c42a9d9e38ca37ebb530079c9ce10b4a08f0d4470631b4d6ce3cc707fc69f
Message ID: <9302081609.aa24308@penet.penet.FI>
Reply To: <199302080630.AA01555@xtropia>
UTC Datetime: 1993-02-08 15:36:58 UTC
Raw Date: Mon, 8 Feb 93 07:36:58 PST

Raw message

From: Johan Helsingius <julf@penet.FI>
Date: Mon, 8 Feb 93 07:36:58 PST
To: Anonymous <root@extropia.wimsey.com>
Subject: Re:
In-Reply-To: <199302080630.AA01555@xtropia>
Message-ID: <9302081609.aa24308@penet.penet.FI>
MIME-Version: 1.0
Content-Type: text/plain



> Hi - I tried to use the anon.penet.fi remailer and got a warning that
> some people had hacked it to find out for which anonymous ID any user
> had.  It sounded like they would forge mail from the person they wanted
> to find out about, have it go through penet, and then go to themselves.
> Then they could look and see what anonymous ID it seemed to come from.

Precisely!

> This has been fixed by making people register a password with the remailer
> and then use it whenever they want to forward mail.

Yeah. A bit cumbersome, but at least it is an attempt to find a workable
compromise between security and ease of use. The password is only
required if you intend to mail to "unregistered" addresses.

	Julf






Thread