Anon address attack...

Eli Brandt ebrandt at jarthur.Claremont.EDU
Mon Feb 22 23:00:28 PST 1993


> One possibility (which might not be that easy technically) would be to
> assign a new anonymous ID for each such message through the Penet server.

I was thinking of installing a trivial hack in my remailer, such that
upon demand it adds some random (essentially unrepeatable) cruft to
the From: line, placing it as a name field so as to have no
addressing significance.  I believe penet assigns IDs based on this
line, so chaining this to a penet-style remailer would provide
"hit-and-run" anonymity -- even if the remailer wants nothing of the
sort.  The social desirability of this could be questioned, but it
certainly seems more secure to built pseudonyms on top of something
like this (using PGP sigs to provide a solid identity) than through
the presently-popular approach.  Comments?  (Julf?)

> Hal Finney

	 PGP 2 key by finger or e-mail
   Eli   ebrandt at jarthur.claremont.edu






More information about the cypherpunks-legacy mailing list