1996-11-10 - Re: Another possible remailer attack?

Header Data

From: ichudov@algebra.com (Igor Chudov @ home)
To: steve@edmweb.com (Steve Reid)
Message Hash: c768b78227a27a9c01fb2a383c8c334c8885953b1d24e16fee93f3289ba1f8d6
Message ID: <199611100309.VAA02940@manifold.algebra.com>
Reply To: <Pine.BSF.3.91.961109134348.182B-100000@bitbucket.edmweb.com>
UTC Datetime: 1996-11-10 04:10:33 UTC
Raw Date: Sat, 9 Nov 1996 20:10:33 -0800 (PST)

Raw message

From: ichudov@algebra.com (Igor Chudov @ home)
Date: Sat, 9 Nov 1996 20:10:33 -0800 (PST)
To: steve@edmweb.com (Steve Reid)
Subject: Re: Another possible remailer attack?
In-Reply-To: <Pine.BSF.3.91.961109134348.182B-100000@bitbucket.edmweb.com>
Message-ID: <199611100309.VAA02940@manifold.algebra.com>
MIME-Version: 1.0
Content-Type: text


Steve Reid wrote:
> 
> >Date: Fri, 8 Nov 1996 12:58:42 -0800
> >From: nobody@cypherpunks.ca (John Anonymous MacDonald)
> >Subject: Vulis on the remailers
> > Please, remailers, source block Vulis for a week.
> > Remailer Fan
> 
> Suppose you operate an ISP and you suspect that one of your users (let's
> call him Dimitri) is using anonymous remailers to submit politically
> incorrect messages (under a pseudonym, or all with the same writing style)
> to Usenet, mailing lists, and a well-known phreak/hack publication. Also
> suppose that these public messages are appearing on a regular basis. 
> 
> You want to know if Dimitri is the person regularly posting these
> messages. So, you use your powers as ISP to block his access to all
> remailers. If the public messages suddenly stop then you can be reasonably
> certain that Dimitri was sending them. 
> 
> I expect this would work even against DC nets.
> 
> The only solution I can think of is to have an account with multiple ISPs
> and always send mail from more than one account. This probably wouldn't
> offer much protection against TLAs (NSA, CIA, FBI, MCI, AT&T ;) who may be
> able to block traffic no matter where it comes from. 
> 
> Comments?
> 

"Dimitri" can always telnet to smtp ports of various sites and use them
to forward his mail to remailers. If his ISP blocks him (via a router
filter, for example), then he would notice. A schizophrenic mind can
imagine a situation where USENET Cabal would try to fool him and try to
stand in the middle between him and all smtp servers, emulating their
responses, but that is not terribly feasible.

Also, some people regularly (via crontab) send anonymous email to
themselves, just in case. They would notice when they stop receiving
them.

	- Igor.





Thread