Beware of the message about the security bug in the anon.penet.fi software! If you do as requested, and send your true email address to an5877@anon.penet.fi then he will see both your true email address and your anonymous address (if you have one - if you don't, you will be assigned one and he will see that). Any future use you make of this anonymous server (say, to post anonymously) will appear under that same anonymous address - and this person will know your true email address that goes with it. an5877's message appears to be a trick, designed to collect anonymous/real address pairs. Johan Helsingius should take action against this trickster. Since he is learning other people's real addresses, perhaps it would be appropriate for his own real address to be revealed. But, this does point out that these systems which automatically assign anonymous addrsses have several security flaws. Johan has already had to introduce a "password" feature to make it more difficult to send fakemail that appears to be from a particular email address through the server, thus revealing the corresponding anonymous address when it is delivered. an5877's trick is a variant on one discussed in news.admin.policy where it is pointed out that you can mail to someone via anon.penet.fi and ask for information; when the return mail comes back it will be from that person's anonymous address. So again you can pair up real and anonymous addresses. These are serious problems. We need some discussion of how to avoid these simple tricks for defeating the anonymity while still having an easy-to-use system. ::Xavier::
Excerpts from list.cypherpunks: 22-Feb-93 Beware of anon.penet.fi mes.. by nobody@rosebud.ee.uh.edu
These are serious problems. We need some discussion of how to avoid these simple tricks for defeating the anonymity while still having an easy-to-use system.
Perhaps a new header such as X-Anon-Doubleblind: yes|no defaulting to yes...? As was said, the doubleblind system is a great idea, but incomplete if you want to correspond to someone without revealing your anon id. -- David Sward sward+@cmu.edu
participants (3)
-
David Reeve Sward
-
Johan Helsingius
-
nobody@rosebud.ee.uh.edu