// COMPLETE THREAD

Alternative to remailer shutdowns...

2 expanded posts ยท every known parent and child

NODE 674f670aAlternative to remailer shutdowns...
There are hundreds of machines littered around the net that
dont bother adding "received" headers to mail.

I dont think that these provide anything near the security and anonymity 
that a single remailer (much less a remailing chain) provide, but it 
seems to me that routing outbound traffic from a remailer through one of 
these sites would provide at least /some/ measure of protection for the 
remailer-operator.

It feels a bit underhanded, but it may be that involving some 
"innocent" bystanders in the remail process would be useful. 
Even if the sites being routed through /were/ keeping logs it would still 
require their participation in any investigation to discover where the 
mail had originated, and this would introduce the question of whether the 
(psuedo)anonymous sendmail host should bear any liability for not
tracking where mail came from. The operator of the particular 
smtp host would seem to have a pretty good defense should a charge be 
raised, but in defending the smtp-host you could also be strengthening 
the defense of the r-ops. 

Another possibility is that rather than operating remailers at all, maybe 
we should be operating non-logging smtp hosts that dont add received 
headers. Building a client to take advantage of these servers would be 
trivial (i wrote one last night, and i am not proficient in C) and it 
could be argued that the situation was not created intentionally to allow 
anonymous messages, merely to preserve disk space and bandwidth.

Flame Away...
NODE b07abb3dRe: Alternative to remailer shutdowns...
>     There are hundreds of machines littered around the net that
> dont bother adding "received" headers to mail.
[ . . . ]
> Another possibility is that rather than operating remailers at all, maybe 
> we should be operating non-logging smtp hosts that dont add received 
> headers. Building a client to take advantage of these servers would be 
> trivial (i wrote one last night, and i am not proficient in C) and it 
> could be argued that the situation was not created intentionally to allow 
> anonymous messages, merely to preserve disk space and bandwidth.

	You really don't even need a client.  RFC822 defines a method
for bouncing mail through another server.  Just use

"user%final.dest.com@laxly.configured.org" 

as the address and laxly.configured.org will send it on to
user@final.dest.com.  

	Wonder what would happened if the sendmail in the
(Linux|NetBSD|your favourite i386 UNIX) distributions came cofigured
to not add Received: headers by default . . . .  Probably would make
diagnosing bounces hell, but it would make a lot of remailer-chain
tail ends.

	Anyone tried out whitehouse.gov to see if it's adding
Received:'s or not yet? :)

---
Fletch                                                     __`'/|
fletch@ain.bls.com  "Lisa, in this house we obey the       \ o.O'    ______
404 713-0414(w)      Laws of Thermodynamics!" H. Simpson   =(___)= -| Ack. |
404 315-7264(h) PGP Print: 8D8736A8FC59B2E6 8E675B341E378E43  U      ------