[Asrg] 3. Requirements - Support for Anonymity (Re: [Asrg] Maintaining Anonymity in an Authenticated System)

Yakov Shafranovich <research@solidmatrix.com> Wed, 02 July 2003 19:49 UTC

Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA09546 for <asrg-archive@odin.ietf.org>; Wed, 2 Jul 2003 15:49:04 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19Xnan-0007V3-U4 for asrg-archive@odin.ietf.org; Wed, 02 Jul 2003 15:48:38 -0400
Received: (from exim@localhost) by www1.ietf.org (8.12.8/8.12.8/Submit) id h62JmbZA028823 for asrg-archive@odin.ietf.org; Wed, 2 Jul 2003 15:48:37 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19Xnan-0007Uo-Pg for asrg-web-archive@optimus.ietf.org; Wed, 02 Jul 2003 15:48:37 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA09467; Wed, 2 Jul 2003 15:48:33 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19Xnak-0006QJ-00; Wed, 02 Jul 2003 15:48:34 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19Xnak-0006QG-00; Wed, 02 Jul 2003 15:48:34 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19XnaD-0007NI-1v; Wed, 02 Jul 2003 15:48:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19XnZR-0007Mb-Mz for asrg@optimus.ietf.org; Wed, 02 Jul 2003 15:47:13 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA09406 for <asrg@ietf.org>; Wed, 2 Jul 2003 15:47:09 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19XnZO-0006PB-00 for asrg@ietf.org; Wed, 02 Jul 2003 15:47:10 -0400
Received: from 000-257-002.area7.spcsdns.net ([68.27.243.209] helo=68.27.243.209) by ietf-mx with smtp (Exim 4.12) id 19XnZL-0006P6-00 for asrg@ietf.org; Wed, 02 Jul 2003 15:47:08 -0400
Message-Id: <5.2.0.9.2.20030702154344.00ba8ab8@std5.imagineis.com>
X-Sender: research@solidmatrix.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
To: Philip Miller <millenix@zemos.net>, ASRG <asrg@ietf.org>
From: Yakov Shafranovich <research@solidmatrix.com>
In-Reply-To: <3F032BD3.8090109@zemos.net>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
X-MimeHeaders-Plugin-Info: v2.03.00
X-GCMulti: 1
Subject: [Asrg] 3. Requirements - Support for Anonymity (Re: [Asrg] Maintaining Anonymity in an Authenticated System)
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Wed, 02 Jul 2003 15:46:44 -0400

At 03:00 PM 7/2/2003 -0400, Philip Miller wrote:

>In all the discussion of authenticating individual senders rather than the 
>servers and MTAs they're using, we've all forgotten that there are 
>circumstances in which anonymity is a requirement.  Think of corporate 
>whistle-blowing situations, in which someone wishes to send an anonymous 
>message to an entity like a media organization or the SEC.  In a world in 
>which all transmissions are undeniably authenticated to a sender, this 
>becomes impossible.
>Anonymous transmission is indeed a feature of our current systems, not a 
>bug.  Any new system or authentication layer on top of what already exists 
>needs to maintain that.

One interesting observation that was made that spammer usually do not use 
CyberPunk anonymous remailers to send spam or any other kind of anonymous 
remailers. There must be a reason for that, perhaps because they see no 
need to do so. However, you are definitely right, anonymity is important.

One distinction that can be made perhaps, that a trusted system could be 
implemented for bulk email only, thus allowing anyone to send a single 
message anonymously once.

The question remains -  can a trust system allow for anonymity? 


_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg