1996-05-22 - Re: The Crisis with Remailers

Header Data

From: Lance Cottrell <loki@obscura.com>
To: “Timothy C. May” <tcmay@got.net>
Message Hash: 88293cdab318834e1b6820eeb175b7b5a56e5d57eb378b543ac4de44416d4433
Message ID: <Pine.SOL.3.91.960521115520.8484A-100000@sirius.infonex.com>
Reply To: <adc757e122021004025a@[205.199.118.202]>
UTC Datetime: 1996-05-22 00:29:47 UTC
Raw Date: Wed, 22 May 1996 08:29:47 +0800

Raw message

From: Lance Cottrell <loki@obscura.com>
Date: Wed, 22 May 1996 08:29:47 +0800
To: "Timothy C. May" <tcmay@got.net>
Subject: Re: The Crisis with Remailers
In-Reply-To: <adc757e122021004025a@[205.199.118.202]>
Message-ID: <Pine.SOL.3.91.960521115520.8484A-100000@sirius.infonex.com>
MIME-Version: 1.0
Content-Type: text/plain


On Tue, 21 May 1996, Timothy C. May wrote:

> At 6:16 PM 5/21/96, Lance Cottrell wrote:
> 
> >I had thought of that. Unfortunately, if the coin is of a special form
> >which identifies the message as being a cover message, then they are of no
> >use against the attacker who is running a remailer. The cover messages
> >really have to be indistinguishable from real messages, even to the
> >remailers. One could do some kind of accounting, where every remailer would
> >refund to the traffic generators their share of the postage, but there is a
> >lot of trust required for that system since it is impossible (very
> >difficult) to verify.
> 
> First, it's not clear to me that "The cover messages really have to be
> indistinguishable from real messages, even to the remailers."
> 
> The "slug messages" will be indistinguishable to all outside observers.

I think the "enemy controled remailer" is an important part of the threat 
model. In many ways it is easier to do than to monitor all the traffic.

> Only by colluding with other remailers will Alice be able to tell Bob,
> Charles, etc. which were slugs and which were not.

True, but it is folly to think that only one remailer would be compromised.

> Second, I was thinking of the model in which all remailer usage is by
> tokens or slugs, anyway, in which case Alice would not know if an incoming
> message was by a "paying customer" or by one of the other remailers.

There has been a lot of discussion of this. It is difficult to make slugs 
which can be purchased in bulk (since you want to buy them using 
anonymous mail), can not be used to connect messages from a one person, 
and do not infringe on Chaum's patents. It is not acceptable for a 
remailer to see a message and know which other messages came from that 
same person. If it is ever the first remailer, it knows who you are. If 
it is the last, it knows who you mailed to. There has been discussion of 
secondary markets for the slugs, but I don't think it is going to happen.
 
> This discussion belongs on the list, not in private e-mail.

Oops, I must have hit the wrong key. I ment to have a copy go to the list.
 
> --Tim

	-Lance

-------------------------------------
Lance Cottrell   loki@infonex.com
President Infonex Internet Services
http://www.Infonex.com
-------------------------------------






Thread