Re: MTS transparency and anonymity
Tony Finch <[email protected]>
| Newsgroups | gmane.ietf.rfc822 |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 28 Feb 2005, Bruce Lilly wrote: > > Trace fields are used with SMTP, not necessarily with other > protocols that use the Internet Message Format. IP address > alone is not sufficient to identify an individual (esp. w/ > DHCP, public access points, etc.) and might identify the sender > (i.e. the person who caused a message to be entered into the > transport stream) who may be different from the message author > (i.e. the person who composed the message). So given that obfuscating the From: field does not provide proper anonymity - if you can trace the message's sender, you can probably identify its author - why can't people just use pseudonymity instead? The following points demonstrate a lack of understanding of the mixmaster anonymizing remailers and of public key cryptography: > > Why not propose a specification for properly strong anonymity based on > > mixmaster or some other multi-stage cryptographic system? > > While the message body content (and originator-specified header > fields if encapsulated in a MIME message/rfc822 wrapper) can be > encrypted by existing S/MIME and PGP/MIME methods (adding more > MIME wrappers), there are still some issues: > 1. If SMTP is used, SMTP trace fields in the (unencryptable) > outer message header will still leave a trail to the sender > (but not necessarily the author, as noted above). > 2. Decrypting requires knowledge of an encryption key, which > implies knowing who sent the message. > 3. While a hypothetical well-known public key unassociated with > an individual would allow decrypting the message, once done > (by anybody), the unencrypted content is available; if it > contains some indication of authorship (viz. a From header > field), there is no anonymity. Mixmaster messages are encrypted with the remailer's public key. The remailer decrypts the message using its private key and sends it on, with a new message header (thus with no trace back to the message's origin). This can be repeated via a number of hops in order to make tracing the message more difficult, since tracing requires a compromise of the anonymity provided by all the remailers. Nothing in the mixmaster system refers to the message's originator, except for the first hop trace headers which are discarded by the first remailer. All of the crypto keys belong to recipients, not senders. Tony. -- f.a.n.finch <[email protected]> http://dotat.at/ FAEROES SOUTHEAST ICELAND: NORTH 6 TO GALE 8 INCREASING SEVERE GALE 9 FOR A TIME. WINTRY SHOWERS. MODERATE OR GOOD.