1996-04-27 - Re: An idea for refining penet-style anonymous servers

From: Olmur <olmur@dwarf.bb.bawue.de>
To: cypherpunks@toad.com
From: Olmur <olmur@dwarf.bb.bawue.de>
Date: Sat, 27 Apr 1996 14:07:45 +0800
To: cypherpunks@toad.com
Subject: Re: An idea for refining penet-style anonymous servers
>>>>> "Alan" == Alan Bostick <abostick@netcom.com> writes:


Alan> There is a way that attackers who have seized or copied the
Alan> database can search it - by trying it out on anonymous IDs, or
Alan> user addresses, until they hit paydirt.

I think that's exactly where the problem lies.  The advantage of your
proposal is, that for an honest SysOp your system makes it easier not
to look on the database, but I assume that Julf isn't interested in
the contents of the database anyways..

But for a real attacker it's just a small inconvinience, nothing more.

Alan> So what do people think of this scheme of mine?  Are there
Alan> drawbacks or weaknesses that I'm not seeing?

I think it's similar to a postmaster running a script to automatically
removing the actual message from a bounced mail, before she looks at
it.  But I don't think it's really making penet-style servers more

Have a nice day, and hope your flu cured now!

