"warning about IIP" freesite

<auto97841-revL73yDgGBWk0Htik3J/[email protected]> Mon, 28 Jul 2003 05:51:00 -0700
Newsgroups gmane.comp.security.invisiblenet.iip.devel
Message-ID <[email protected]>
SSK@wHOf1LwI6PUVcgDwqEu0CuZ6bRAPAgM,W6k8nbDP~T9StSHXQg5D9g/1.html

I saw that this morning and wanted to bounce it at y'all (no, I didn't
write it, as you can hopefully guess since it has some factual inaccuracies
;)

if anyone wants to write up a 'rebuttle' and post it to freenet, that'd
be cool.  i could toss it into the next edition of my flog or it could
go as a standalone response page (or even on the iip freesite ;)

Anyway, just thought i'd mention it.  If no one wants to write up a response
to their 7 points, I'll post one up on wednesday or so.

(attached is the html of the page)
-jrandom
iip_attacks.html (text/html, 7.2 KB)
<HTML><HEAD><TITLE>Warning about IIP</TITLE></HEAD><BODY>
I have been looking into the anonymity provided by IIP, and it appears to me
that it really doesn't provide much anonymity, at least not more than regular
IRC via an anonymizing IRC proxy with SSL (if such a beast existed)<SUP><A href="#1">1</A></SUP>.
This isn't a problem in itself, however I get the impression many people are
trusting IIP to be anonymous to a greater extent than it actually is, it's often
seen as a companion for freenet, which though it has plenty of anonymity problems
too is a lot more secure.  In my opinion the IIP server should have really big
banners warning those who would use it in ways in which loss of anonymity could
cause actual real life problems<SUP><A href="2">2</A></SUP>.
<P><P>
Issues I've found after looking at the source for 15 minutes (ie. there's probably more, and ie. I might be wrong):
<UL>
<LI><B>The path through relays is determined randomly and ad hoc.</B><BR>
Unlike mixmaster, each IIP relay picks the next hop to send a connection to itself,
so the client cannot choose which relays it trusts and which it doesn't, apart from
hoping all relays he contacts directly will have trimmed their noderefs to something he agrees with.
<LI><B>There is no chain length regulation</B><BR>
Your connection will happily bounce about until it happens to reach the server.
Not only does this mean you often get very unstable connections, but when you
eventually have a stable connection this will probably be one going through very
few servers, and quite possibly be directly to the main IRC server, not using any relays!
<LI><B>It's trivial to find the IIP server</B><BR>
Which means the local law enforcement agency (the US law enforcement in this case, the server 
(iip.invisiblenet.net) appears to be located in the US) can come knocking on NOP's door and 
install a wiretap (and quite probably demand he not tell anyone about it), and
read all your conversations.  Or just wait until you connect directly to the IIP
server and grab your IP.  (with the current number of relays, this happens once in
every 24 <U>attempted connections</U> (on average) to invisible IRC you make.  Assuming they also
get their hands on inform.invisiblenet.net (which isn't entirely unlikely) this number
comes down to 1 in 12.  <U>1 in every 12 times you connect the IIP server operators
know exactly who you are (unless you're running an in use public relay)</U>
<LI><B>All communication is plaintext once it reaches the server</B><BR>
Even for private /msges, the text arrives as plaintext on the server.  This means
that anyone with control of the server can read all messages.  (you could ofcourse
use gpg to encrypt every message you type and have all readers use gpg to decrypt,
but it would make a lot more sense to have isproxy do this.)
<LI><B>Anyone can become a relay</B><BR>
For freenet and many other systems this is a strength, but IIP relays have so
many methods of attack that this is probably a bad thing.  For instance just
by keeping track of local connects from non-relay hosts and cross reference
with /join's to popular channels and anyone with a relay can construct nick&lt;-&gt;ip mapping in
no time.
<LI><B>IIP is connection oriented, and connects/disconnects are publicly visible.</B><BR>
Another problem caused by trying to adapt a protocol not designed for anonymity,
IIP works with connections that get broken as soon as any link in the chain breaks
the connection.  An even quicker attack than the one mentioned above is as follows:
One by one start killing connections and watch who drops off IIP.  This is an active
attack and will probably get noticed if you do it too often, however if you only
want the mapping once it'll work.
<LI>Finally, it's not really a flaw in IIP but still not exactly encouraging, the
<A href="/__CHECKED_HTTP__http://wiki.invisiblenet.net/iip-wiki?HowItWorks">IIP wiki description</A> claims
portscanners cannot detect the listening port for isproxy.  This is not possible unless one
does <I>interesting</I> things with TCP/IP, and even then it would require root.  Isproxy shows
up on port scans just fine.  (<SMALL>In all fairness, this was probably just someone
being let loose on the wiki who should have been kept off</SMALL>)
</UL>
I don't think IIP is a bad initiative and I understand that progress comes in
small steps, however claiming it provides any significant amount of anonymity
at the current state of the project is a bad idea.
<P><P><P>
<SMALL><A name="1"><SUP>1</SUP>Actually, IIP provides less security than using anonymizing proxies,
as anybody can set up a public relay and as far as I can tell get it onto the
public nodes.ref, while using a single anonymizing proxy would only have one proxy
admin that could be corrupted or could snoop.<BR>
<A name="2"><SUP>2</SUP>To name a few: the people running illegal (in most countries) banks or gambling operations,
child pornographers, and those who post deep personal secrets to their flogs.</SMALL>
<HR>
There might be a <IMG height="0" width="0" alt="" src="2.html"><A href="2.html">next edition</A> if I have any corrections or additions.
<HR>
        <form action="/servlet/Insert" enctype="multipart/form-data" method="POST">
          <p><b>NIM</b> - Nearly Instant Messaging. <font size="-1">Original design 
            by <i><b>wire</b></i></font></p>
          <p><b>Used Submission Slot Checker : </b><b><a href="/KSK@iipharmful-1" target="_blank">1</a></b><b> 
            - <a href="/KSK@iipharmful-2" target="_blank">2</a></b><b> 
            - <a href="/KSK@iipharmful-3" target="_blank">3</a></b><b> 
            - <a href="/KSK@iipharmful-4" target="_blank">4</a></b><b> 
            - <a href="/KSK@iipharmful-5" target="_blank">5</a></b><b> 
            - <a href="/KSK@iipharmful-6" target="_blank">6</a></b><b> 
            - <a href="/KSK@iipharmful-7" target="_blank">7</a></b><b> 
            - <a href="/KSK@iipharmful-8" target="_blank">8</a></b><b> 
            - <a href="/KSK@iipharmful-9" target="_blank">9</a></b><b> 
            - <a href="/KSK@iipharmful-10" target="_blank">10</a></b><br>
          </p>
          <table cellspacing="0" cellpadding="2" align="center">
            <tr> 
              <td> <div align="right"><b>Target</b></div></td>
              <td> <input name="key" size="30" type="text" value="KSK@iipharmful-1"> 
                <font size="-1"><i>Adjust as required.</i></font></td>
            </tr>
            <tr> 
              <td> <div align="right"><b>HTL</b></div></td>
              <td> <input name="htl" size="6" type="text" value="15"> <font size="-1"><i>Higher 
                values for deeper insertions (they take longer).</i></font> </td>
            </tr>
            <tr> 
              <td> <div align="right"><b>Text</b></div></td>
              <td> <textarea name="filename" rows="10" cols="80"></textarea> </td>
            </tr>
            <tr> 
              <td></td>
            </tr>
            <input name="content-type" type="hidden" value="text/plain">
            <tr> 
              <td></td>
              <td> <input name="submit" type="submit" value="Submit feedback"> 
                <i>&nbsp;<font size="-1">Note : Sending a submission may take 
                a long time.</font></i> </td>
            </tr>
          </table>
        </form>
</body>
</html>