3 ms·
We have options already, although we abandoned them once the Internet became ubiquitous. UUCP would allow encrypted envelopes that would only allow trusted nod
by reeses 13y ago
We have options already, although we abandoned them once the Internet became ubiquitous. UUCP would allow encrypted envelopes that would only allow trusted nodes to decrypt enough to forward to the next destination or to the local user.
It would be ungainly, especially at first, and just as easy to scoop associations between users (although, not subject lines or other metadata) by tracing the limited paths. As a critical mass were achieved (yay network effects), along with peer-to-peer sharing, you could source route your messages to anyone.
Given this message:
From: reeses
To: hagbard
Subject: fnord
Please immanentize the eschaton at your earliest convenience.
I could route it through the equivalent of a bang path (foo!bar!baz!bob), each step of which is a trusted node whose private key(s) I have in my routing table. Instead of bang paths, however, the envelope could be something as simple as:
Next: baz
Data:
Ardhrcbeebdhvfdhnzrfgdhvqbyber
zvcfhz,pbafrpgrghe,nqvcvfpviryvg
baz would receive the "Ardhrcbeebdhvfdhnzrfgdhvqbyberzvcfhzdhvnqbybefvgnzrg,pbafrpgrghe,nqvcvfpviryvg" blob and unwrap it, forwarding it to bob, who would have exchanged keys with reeses.
Multipath routing and multiple recipient support would be possible by having additional Next: headers and the encrypted blob would serve as a sufficient identifier, or input into an identifier generator, to deduplicate messages if a transmission fork were coalesced.
This is off the top of my head, so it's wrong in a bunch of ways, but it's a simple model that could easily be deployed among circles of people who need a degree of anonymity. As in the later days of UUCP, with comp.mail.maps and the like mapping a combination of FQDNs to named hosts, initial, intermediate, or terminal nodes could involve forwarding over (E)SMTP. (foo!{bar|baz}|quux|reeses@example.com) would route through a number of machines, and the message in my inbox would look like the following:
From: POSTMASTER@quux.com
To: reeses@example.com
Subject: (none)
-----BEGIN PGP MESSAGE-----
Version: 2.6.2
PnyyzrVfuznry.Fbzrlrnefntb-arirezvaqubjybat
...
Again, at the beginning, it would just be necessary to know about quux (or just the message fingerprint) and monitor its traffic to identify reeses@example.com as someone up to no good and watch for sidechannel communications to create a correlation between conversants. "Hmm, reeses received a message at 3:14pm from an unknown source. Ah, he received a phone call from 415-555-1212 at 2:58pm and called that number at 3:18pm." Multiple transmission sources, split messages (torrent file pointing to message, etc.), unconventional channels, and the like could wrap enough layers of encryption (and yes, STO) that the feasibility of a timely interception of content would be significantly reduced.
Plus, rubber hose.
- astrodust 13y agoUUCP is an interesting example because it was completely understood that your messages would be routed through semi-trusted intermediaries. SMTP is presumed to go directly between trusted parties, but this is clearly not the case any longer.
- ZoFreX 13y agoYou might enjoy reading up on how Tor works[1], it's along similar lines. [1]: https://www.torproject.org/about/overview.html.en https://www.torproject.org/about/overview.html.en
- reeses 13y agoYeah, it's onion routing applied to services. I never know how much detail to go into on HN these days. I should have just said "TOR back ported to UUCP" and saved time. :)
- anigbrowl 13y agoAmusingly, it seems like we've come full circle to the early days of Linux when getting your own domain was the definition of hardcore (and Linux itself typically involved booting from floppy). timely interception of content would be significantly reduced The thing is, most people are not interested in such security because they don't see themselves as engaged in a race against government surveillance. You want privacy on general principles, that makes perfect sense. But if you're proposing obfuscation of message paths as a temporizing tactic, it becomes attractive of attention because the naturally question to ask is 'what's the rush, exactly?'. If anything, this gives ammunition to the proponents of 'ticking time bomb' scenarios, notwithstanding the inherent flaws in their arguments. I don't really think that the smart response to their claims is to propose that everyone carry loud mechanical alarm clocks, for the same reason that the 4th amendment is not best upheld by advising everyone to carry miniature safes.
- reeses 13y agoOh my, the miniature safe analogy was one of the methods I used to try to explain to my wife why messaging privacy was an issue. :-) "OK, I don't know the combination, I just have a bunch of safes with your name on them, and only you know the combination..." I'm not so concerned about the "timeliness" issue on a sub-yearly scale. It was a throwaway possible benefit of using multiple keys, cryptosystems, and decentralized transmission. As one of the elements is compromised by advancements in the art, they can be deprecated in favor of a stronger one. By timely, I meant that it would be less economical to slurp up everything with the goal of SNA on a cohort of college friends or whatever. I'd like an increase in the reasonable expectation of privacy with email. I would of course comply with a legal demand, authorized by a judge in my country, to surrender cleartext emails that are on my systems or in my accounts. I would expect my partners in conversation to do the same. What I do not like, and I think we agree, is the convenient slurping of all the traffic, storing that, and then mining it for correlations with "un-American" conduct. What I've found to be a more useful explanation trying to explain "security" as we usually mean it is to get to the reason why I think people should have privacy from their government or the agencies to whom they willingly transmit information about individuals. We've come a long way in securing rights for people who are not white, christian (of accepted denominations), straight, men. We have a lot longer to go. I am really quite uncomfortable with a HUAC-style group having access to all electronic communications. It was communism fifty years ago, it's obviously terrorism now, but it will always be some threat to "national security" that is used as an excuse to be proactive about looking for suspicious characters because of what crimes they may be inclined to commit. (And I kept using my own boot-root installation on my first Linux box (which could now legally buy alcohol in the USA) until 2000 or 2001, when I tried this "Redhat" thing. :-))