Re: [i2p] Tunnel cryptography for I2P 0.5 (corrected typo)

2005-01-18 Thread jrandom
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Thanks Connelly for the writeup and the discussion,

 The following is a discussion of tunnel cryptography plans for
 I2P 0.5.  There are two options; one will be chosen.

A few key changes were missed in this draft, and I've incorporated
all of the suggestions from yesterday into [1].  The explanation of
the overall rationale for the two different strategies is largely
correct.  This is still a work in progress, and will be improved as
we get both more feedback and clarify some issues.

[1]http://dev.i2p.net/cgi-bin/cvsweb.cgi/i2p/router/doc/tunnel-alt.html?rev=HEAD

An implementation of the crypto for first strategy [2] has been
created [3], but as there are some weaknesses in inbound tunnels
when dealing with colluding attackers who also control the gateway,
the second strategy seems more appealing.  Next up I'd like to get
that implemented into code so that any further issues can be fleshed
out, as well as to make concrete what it is that is being specified.

[2]http://dev.i2p.net/cgi-bin/cvsweb.cgi/i2p/router/doc/tunnel.html?rev=HEAD
[3]http://dev.i2p.net/cgi-bin/cvsweb.cgi/i2p/router/java/src/net/i2p/router/tunnel/

Of course, none of those html docs are a finished spec for I2P
overall as they assume familiarity with the other non-tunnel-related
parts of I2P and do not include the relevent references to where we
snagged our ideas ;)  This is just a state-of-the-design view into
the 0.5 tunnel revamp.

Anyway, thanks again for the updates Connelly, and if anyone is
looking for the details currently planned for, please see [1].
Suggestions/comments/criticisms always welcome, or if you want to
get involved, please get in touch!  We're in #i2p on irc.freenode.net
and on irc.duck.i2p pretty much all the time.

=jr
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFB7PDaGnFL2th344YRAnP2AKDuaTX7TNnYa0AuCpc2B90XSluy6QCg7LDv
uPddHM1YB6v3RqwBbCXPUGg=
=+AIK
-END PGP SIGNATURE-



FW: Securing Wireless Apps in Vertical Markets Webinar from Unstrung

2005-01-18 Thread Tyler Durden
Sometimes these webinars can be informative, sometimes they're thinly 
disguised marketing efforts (that can still have some small value, though).

Dear Colleague,
As an industry professional, you may be interested to know about an 
upcoming online event being presented by Unstrung (www.unstrung.com), the 
worldwide source for analysis of the wireless economy. This free Web 
seminar -  Securing Wireless Apps in Financial, Government  Military 
Markets - will evaluate recent progress in a critical market.

Keeping information out of the hands of interlopers is an important task 
for any net manager - but it's critical for those with the responsibility 
for keeping financial, governmental, and military applications secure. 
Security issues continue to be the main concern holding back widespread 
wireless adoption in these environments.

During this presentation we'll focus on:
- The critical role of security in these vertical markets - why does it 
matter?
- Potential effects of wireless network attacks in each market
- The diverse security demands of these three markets
- Case studies of deployments in each market and lessons learned

Join us on Thursday,  January 27, at 2:00 p.m. New York / 7:00 p.m. London 
time, for this live Webinar sponsored by Bluesocket and Proxim.

To sign up for the Webinar, please register through the following link:
http://metacast.agora.com/link.asp?m=23153s=4936527l=0
Hope to see you there!
Unstrung




If you wish to be taken off this list, simply reply to this message and
include the word unsubscribe in the subject field - or visit the link
provided below. You will be taken off automatically.
http://www.lightreading.com/unsubscribe.asp?subscriberid=4936527
Light Reading Inc.
23 Leonard St.
New York, NY 10013



Type III Anonymous Message from Antani anonymous remailer

2005-01-18 Thread nobody
This is a Type III anonymous message, sent to you by the Winston Smith
Project mixminion server at firenze.linux.it. If you do not want to
receive anonymous messages, please contact antani-
[EMAIL PROTECTED] For more information about anonymity, see
https://remailer.firenze.linux.it or
https://e-privacy.firenze.linux.it.

-BEGIN TYPE III ANONYMOUS MESSAGE-
Message-type: plaintext

Where are the remailer mail2news gateways still operating?  
If there are any anymore...
Stale pages serving up dead links to defunct services.
Google has let me down.
-END TYPE III ANONYMOUS MESSAGE-



Re: panix.com hijacked

2005-01-18 Thread Justin
On 2005-01-16T09:46:28-0500, R.A. Hettinga wrote:
 On Sun, 16 Jan 2005 [EMAIL PROTECTED] wrote:
  On Sun, 16 Jan 2005 01:32:46 EST, Henry Yen said:
  
   . panix.net usable as panix.com (marcotte) Sat Jan 15 10:44:57 2005
 
  So let's see.. the users will see this when they log into shell.panix.net
  (since shell.panix.com is borked). Somehow that doesn't seem to help much.
 
 and the hijackers could be, potentially, running a box pretending to be
 shell.panix.com, gathering userids and passwds :(

Object lesson in why using replayable passwords is not a good idea.
Allah invented nonce-based password hashes and public key crypto for a
reason.

-- 
War is the father and king of all, and some he shows as gods, others as
men; some he makes slaves, others free. -Heraclitus Kahn.83/D-K.53



Re: Type III Anonymous Message from Antani anonymous remailer

2005-01-18 Thread R.A. Hettinga
At 9:06 PM +0100 1/18/05, [EMAIL PROTECTED] wrote:
Where are the remailer mail2news gateways still operating?
If there are any anymore...

This is great. I've been watching, via bittorrent, Lucy Lawless' Warrior
Women series. The last episode is about Lozen, the Apache medicine-woman
who was sister of Antonio, one of the last chiefs of the Chiricahaua band,
who raided up and down the Black Range in Southeast New Mexico (Hillsboro,
a town in the front range of which, was where my father retired and died,
which was why I was interested in the episode; I remember reading Black
Range Tales, and other western memoirs of the time, when I was a kid).

She died in Alabama (by way of Florida and Oklahoma) of tuberculosis, 20
years after being captured in New Mexico.

There's an echo in here.

Cheers,
RAH

-- 
-
R. A. Hettinga mailto: [EMAIL PROTECTED]
The Internet Bearer Underwriting Corporation http://www.ibuc.com/
44 Farquhar Street, Boston, MA 02131 USA
... however it may deserve respect for its usefulness and antiquity,
[predicting the end of the world] has not been found agreeable to
experience. -- Edward Gibbon, 'Decline and Fall of the Roman Empire'