1996-04-06 - [OFF-TOPIC] Re: Fwd: Anonymous code name allocated.

Header Data

From: “Peter Trei” <trei@process.com>
To: coderpunks@toad.com
Message Hash: e12660da0f2ce22d7129c2949cd09336e4c48f61f081d31792215bdbbc913428
Message ID: <199604051712.JAA06181@toad.com>
Reply To: N/A
UTC Datetime: 1996-04-06 07:30:23 UTC
Raw Date: Sat, 6 Apr 1996 15:30:23 +0800

Raw message

From: "Peter Trei" <trei@process.com>
Date: Sat, 6 Apr 1996 15:30:23 +0800
To: coderpunks@toad.com
Subject: [OFF-TOPIC] Re: Fwd: Anonymous code name allocated.
Message-ID: <199604051712.JAA06181@toad.com>
MIME-Version: 1.0
Content-Type: text/plain


> From: JonWienke@aol.com

[I know this is off-topic for coderpunks, but some of the discussion is
happening here]

> [The following has been censored to protect the guilty.]
> 
> >Subj:	Anonymous code name allocated.
> >Date:	96-04-02 23:37:10 EST
> >From:	daemon@anon.penet.fi (System Daemon)
> >To:	jonwienke@aol.com
> >
> >You have sent a message using the anon.penet.fi anonymous forwarding
> service.
> >You have been allocated the code name anXXXXXX.
> >You can be reached anonymously using the address
> >anXXXXXX@anon.penet.fi.
> >
> >If you want to use a nickname, please send a message to
> >nick@anon.penet.fi, with a Subject: field containing your nickname.
> >
> >For instructions, send a message to help@anon.penet.fi.
> 
> I tried sending a test message to the address indicated, and received it back
> a day later, so sending email to this address does reach me.  The funny part
> is that I have never (to my knowledge) had any communication with
> anon.penet.fi prior to receiving this email.  
> 
> Questions:
> 1. How do I use this to SEND messages anonymously?  Having an email address
> with no obvious link to my identity is cool, but I would like to be able to
> send as well as receive.  I sent email to help@anon.penet.fi, but have
> received no response yet.
> 
> 2. Why was I chosen for this?  How did anon.penet.fi find out my email
> address?  Is the NSA trying to lull me into a false sense of security in the
> hope that I will use this account to violate ITAR?
> 
> 3. Has anyone else on this list received unsolicited remailer accounts?
> 
> Jonathan Wienke
> ---------------------
> Forwarded message:
> From:	daemon@anon.penet.fi (System Daemon)
> To:	jonwienke@aol.com
> Date: 96-04-02 23:37:10 EST
> 
> You have sent a message using the anon.penet.fi anonymous forwarding service.
> You have been allocated the code name an573530.
> You can be reached anonymously using the address
> an573530@anon.penet.fi.
> 
> If you want to use a nickname, please send a message to
> nick@anon.penet.fi, with a Subject: field containing your nickname.
> 
> For instructions, send a message to help@anon.penet.fi.

While I'm not up on all of the wrinkles, I've seen this reported as an
attack on the penet anonymous mail forwarder and news poster.

An attacker forges email in your name, requesting an anon-id.
 
The server creates one, and sends the report both to you, and to
the attacker's address.

If you try posting thru the penet server, the post gets anonymized
using the anon-id the attacker created.

The attacker can now link the anonymized post to your True Name.


If you ever intend to use the penet anon server, you should write
to the server administrator, requesting to have the id the attacker
created deleted, and the create a new one, with password protection.
(I don't use penet, so I don't know the details).

Peter Trei
ptrei@acm.org





Thread