4 ms·
Iirc, a difference in bitmessage from other protocols is that it has 'receiver anonymity,' in that since a message is received by all parties, the receiver's me
by divbit 10y ago
Iirc, a difference in bitmessage from other protocols is that it has 'receiver anonymity,' in that since a message is received by all parties, the receiver's metadata is not leaked. This is possibly a benefit over some existing protocols, although it has obvious performance / scaling side-effects.
- ycmbntrthrwaway 10y agoBitmessage is just a broadcast protocol implemented with floodfill. Anonymity protocols are mostly divided into 3 classes: broadcast (dining cryptographers, buses, bitmessage), mixes/rerouting (mixmaster, mixminion, tor) and private information retrieval (dissent and followups). After decades of work in the field [1], bitmessage implements broadcast in the most naive way: floodfill. Global passive adversary can simply find out where the message appeared first. If the message is encrypted with a key which is only known to the receiver (i.e., message is not for chan), everything is ok. But in this case bitmessage is not better than alt.anonymous.messages. If messages can be linked together, active non-global adversary can measure time and exploit dynamic topology of the network to reconnect closer to the sender. Bitmessage offers no protection against it. With alt.anonymous.messages the solution is remailers, and bitmessage offers no alternative. [1] http://freehaven.net/anonbib/ http://freehaven.net/anonbib/
- divbit 10y agoThe receiver anonymity tidbit was something I recalled from this summary http://fanti.web.engr.illinois.edu/ciss2016.pdf http://fanti.web.engr.illinois.edu/ciss2016.pdf which for some reason was in my crypto / chat papers folder..
- divbit 10y agobtw thanks for the link - quite extensive citation helper