1994-07-28 - Re: (fwd) Possible compromise of anon.penet.fi

Header Data

From: roy@sendai.cybrspc.mn.org (Roy M. Silvernail)
To: cypherpunks@toad.com
UTC Datetime: 1994-07-28 23:56:46 UTC
Raw message

From: roy@sendai.cybrspc.mn.org (Roy M. Silvernail)
Date: Thu, 28 Jul 94 16:56:46 PDT
To: cypherpunks@toad.com
Subject: Re: (fwd) Possible compromise of anon.penet.fi
In list.cypherpunks, nzook@math.utexas.edu forwards:

Subject: Possible compromise of anon.penet.fi
> Someone has been collecting email addresses, apparently from postings
> to Usenet, and forging them to anonymous postings through
> anon.penet.fi to alt.test.
> The text of the posting states the REAL email address of the poster,
> under a posting attributed to the anonymous ID assigned to that
> poster.

I actually saw this article in alt.privacy, and sort of mentally filed
it.  Then, this morning, I received a note from anon.penet.fi informing
me of my anonymous ID.  I don't use penet, and never sent anything
through there anonymously.

I first thought it might have been a mail-bombing run, but then I
re-read this:

> However, there are some lower numbered anonymous IDs, presumably in
> previous use by the addressee named in the text of the message.  These
> anonymous addresses are now compromised.

I think this might be a forked attack... trying to flood penet with
traffic, and also outing people who have used penet for anonymous
traffic previously.  This is a good argument against maintaining a
double-blind database (and in favor of systems like soda.berkeley.edu's
remailer with its 'response block' strategy).

Does anyone else smell Detweiler?
