TIP: Click on subject to list as thread! ANSI
echo: 10th_amd
to: Russ Johnson
from: Bob Ackley
date: 2003-04-09 06:19:42
subject: From Risks Digest 22.66

Replying to a message of Russ Johnson to Wayne Chirnside:

 >> One of the scarier bits you've posted here and should it pass
 >> will most likely have a chilling effect on internet based commerce.
 >> Looks like ALL our freedoms and liberties have gone away in the name
 >> of security and cradle to grave government invasion of privacy.
 >> Personally I say give back the civil lierties and I'll take my
 >> chances! IOW's I'm more afraid of _U.S._ than _them_.

 RJ> As I've said elsewhere, I believe a valid arguement could be made that
 RJ> the HEADER of the packet still lists where it came from (your
 RJ> machine) and where it's going (the destination). 

 RJ> Regardless of the content, the header MUST list the origin and
 RJ> destination. Unless you are spoofing packets, you have nothing to
 RJ> worry about. 

 RJ> Case in point, when transfering a binary file, it looks like
 RJ> encryption. How would someone tell the difference between transfering
 RJ> a binary file, and sending an encrypted email?

The encryption software - PGP, f'rinstance - has to build specific
data blocks/identifiers into the encrypted text so that it can later
decrypt it.  And some sort of flagging to identify the encrypted text to
PGP so that PGP will recognize it.  Those tags and flags can
be used by others to differentiate encrypted text (and data) from ordinary
binary traffic.

Having said that, I fully support the idea of occasionally dumping the
contents of one's video buffer, or a large program (better, *part* of a
large binary program, preferably out of the middle of it), thru a UUE
encoder to give ASCII text (which will look like garbage) and then PGP that
output and send the encrypted result around.  That sort of thing will drive
the snoops bonkers because even though it's PGP encrypted and they know it,
even with their secret back doors and supercomputers they can't decrypt it
- because it was never intelligible text to begin with.  Even if they can
get to the aforementioned ASCII garbage text it's meaningless, and running
it thru UUE *still* results in garbage, even though it's the decrypted
result of what was originally sent.

A real sadist would do the same thing with the 4th Amendment to the
Constitution with a comment added at the end to the effect "Government
snoops reading this have just violated their sworn oath to protect and
defend the Constitution of the United States from all enemies, foreign and
DOMESTIC."

---
* Origin: Bob's Soapbox, Plattsmouth, Nebraska, USA (1:379/103.104)
SEEN-BY: 633/267 270
@PATH: 379/103 1 106/1 2000 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.