Re: hostmangling in new ircd

Mrten <[email protected]> Fri, 26 Aug 2005 01:51:29 +0200
Newsgroups gmane.network.irc.blitzed.general
Message-ID <[email protected]>
Om 15:53 op donderdag 25 augustus 2005, Andy Smith:

>> > >  if i, as a channel-op, want to report logs as evidence to a third
>> > >  party, i have to ask the admins for help to translate the mangled
>> > >  hostnames to real ones. do the admins really want to meddle in
>> > >  that?
>> 
>> > How many times does that realistically happen?  
>> 
>> we wouldnt know, because admins are not involved atm.

> You have ignored all that I said about me being in the largest
> english-speaking channels on Blitzed for 4+ years and not really
> seeing users legitimately need to do this.

no, i haven't, it's just that the mail is long as it is already so i
snipped a bit. i know you Rule blitzed, and i know that there wouldn't
be a blitzed without you. personally i think that the problems i'm
thinking of would arise in the smaller channels, btw.

i'm not trying to put your opinions down or something, if that seems
to be the case i apologize. i really do appreciate the time that you
take answering some of my admittedly silly questions, and hopefully my
thoughts and questions make you look at this a new way. i'm offering
up venues that you might have not thought of before, at least, i won't
know until i've asked would i :)

> Like I said it's possible there is a lot of this going on without
> our knowledge but it seems unlikely to me - on Blitzed when they
> have a problem they seem to come running to us pretty quickly.

the scenario that i have in my head: let's say that some minor is
privately or in a private channel abused/harassed by someone and the
parents want to give the evidence to the police. without hostmasking,
we aren't involved. with hostmasking, we are. do we want to be?

>>> How do you currently deal with such issues on IM networks that don't
>>> show hostnames?  IRC is virtually the only IM technology that shows
>>> users' hosts.
>> 
>> ICQ shows (read: 'has knowledge of') users' hosts. all IM's that have
>> CTCP-like behaviour have, at one time or another. MSN-text travels over
>> Microsoft servers afaik (another reason not to use it), but audio/video and
>> filetransfers don't.

> I argue that people do and say things that may be illegal or abusive
> on other IM networks and the users of the network don't know how to
> obtain the offender's real host.  All they can do is complain to the
> network itself.

which would be useless, because the network is probably based in
another country and most probably wouldn't log anything useful anyway.

but this is arguing the wrong way around! "hey, its a problem with all
other IM's. let's make it a problem here as well".

> Would you like a channel mode which would prevent users with masked
> hosts from entering the channel, or that would show their real hosts
> to ops of the channel?

i don't think blocking masked users in a channel would be a much used
channel option. :)

>> how about having chanops see the real hosts of users in their channels?
>> that will still stop the ddos-kiddies and alleviates much of the other
>> objections.

> Yeah this is what I was trying to ask you before.

> This can be done, has been done on irctoo I believe.  The only
> tricky bit would be that there would have to be some way for the
> user to be warned that their real host will be visible to chanops in
> a given channel before they join it.  Otherwise someone malicious
> can create such a channel and invite their victims to it.

there are of course problems caused with such a way of implementing
hostmasking. it's not standard nor expected, so the difference has to
be explained somewhere. MOTD? wiki? join-msgs? noone RTFMs lately.

> Can you think of a good way?  It could be done by adding yet another
> user mode, but that's maybe getting rather ridiculous...

do you mean implementing hostmasking as a usermode (say) "+Z" for
"masked host but not for chanops/opers"? or does "+Z" mean "hostmask
me for chanops as well"? is there a 'standard' usermode for
hostmasking?

if irctoo does it like this, how do they explain it to their users?
(couldnt find anything on the website, and their ftp-server with
bahamut-patches seems down atm)

>> > >  what does *the network* have to gain from hostmasking users?
>> > >  aren't we making it ourselves more difficult?
>> 
>> > What we're gaining is that we're getting ever more demands for masked
>> > hosts and when we say we don't have the feature, they go to a
>> > network that does, and it's getting harder and harder to justify why
>> > we don't provide the feature.
>> 
>> if its such a demanded feature, why isn't it in bahamut 1.8 already?

> Because bahamut is written for dalnet and dalnet is opposed to the
> feature.  There are other IRC networks bigger than dalnet that are
> not opposed to the feature, but we don't like their ircds.

fair enough.

> I'm not going to waste my time trying to justify that we really do
> get heaps of requests for this.  I sit in #help and answer the
> people who ask for this stuff so I know how many requests we get and
> I do have an idea how many people have left to other networks that
> do have the feature.

so the gain is 'make new users happy'. fair enough.

>> > Also in channels like the maroc ones their users are being
>> > terrorised by kiddies who DDoS if they don't get chanops and we can
>> > do nothing to help.
>> 
>> (ah, the "terrorised"-meme)

> Are you suggesting I'm making it up?  I don't know what you do on
> IRC but if you're going to comment on how something will affect the
> network it has to be based on the real uses of the real users in a
> lot of different channels that amounts to more than just a couple of
> semi-private friendly hangouts.

> As I say I regularly visit all larger channels and spend a lot of
> time dealing with users in #help and elsewhere, and have done on
> Blitzed for the length of its existence, and on other networks
> before it. It's pretty offensive of you to intimate that my
> experiences are somehow invalid or made up or just folk lore
> repeated from irc admins of old.

geez griff, chill out. remember where #maroc.nl came from?

you were using the 'terror'-word. i notice that the word 'terror' is
used a lot lately, in less and less the original meaning of the word.
everything seems to be "terror", lately. so, terror-meme. it's
tangential, nothing more. hence the parentheses.

> Do you PERSONALLY AT THE MOMENT WITH YOUR OWN EYES see users on IRC
> needing to legitimately report real host names to ISPs with such
> regularity that the burden on the network would outweigh the
> benefits, or was it a hypothetical issue?

you asked for thoughts, these are my thoughts. of course these are
hypothetical examples.

but hypothetical != impossible.

> Bear in mind that the user can still contact an oper and then make
> the report to the ISP giving the email address of the network and
> then if the ISP ever gets around to giving a damn (unlikely) then
> they can get the real host from us.

> It's already a miracle if an ISP takes any action based on problems
> on IRC and after the ability to DDoS users is removed what is left
> for ISPs to care about?  Hate speech?  Spamming?  They already leave
> it to the IRC network to deal with.

you think ISP, i think 'polees'.

>> well, have them register to get a masked host. 

> We have no way of authenticating who someone is until they identify
> to services, which leaves a large window where their real hosts can
> be seen.

so? this is the responsibility of the user. if he/she decides to join
a channel before authing, that would be his/her choice.

yes, that would be hard to explain to turkeymenistan.
yes, there is probably a problem when services are down.

but, as an engineer, i'm trying to define 'good enough'.

>> if you have someone that blackmails you you're fucked anyway.
>> possible side-effect: hostmasking will shift the load of the
>> DDosses to the network instead of the private user.

> As admins we react differently to attacks than users do, and there
> is no evidence that miscreants who would DDoS a user for chanops
> will DDoS a server instead. They do it to the users because the
> users cave in, but I think most irc admins would just shut the
> server(s) down until the attackers gave up or the network didn't
> exist anymore.

they wouldnt DDos the server per se, they would DDos the channel
(instead of the user directly). seems likely in the scenario you
described.

> It is possible that having this feature will attract the wrong kind
> of users, just like it is possible that allowing warez channels on
> the net attracts the wrong kind of user.  It's not like we can't
> turn the feature off at a later date if this is seen to be the case.

of course.

Mrten.
-- 
Reverse-engineering design assures 'bug-for-bug' compatibility