home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.org.eff.talk:7779 alt.privacy:2687 alt.comp.acad-freedom.talk:3804 comp.security.misc:2332
- Path: sparky!uunet!mcsun!uknet!comlab.ox.ac.uk!pcl
- From: pcl@ox.ac.uk (Paul C Leyland)
- Newsgroups: comp.org.eff.talk,alt.privacy,alt.comp.acad-freedom.talk,comp.security.misc
- Subject: Re: CERT and the Dept. of Justice on keystroke monitoring
- Message-ID: <PCL.92Dec18102928@rhodium.ox.ac.uk>
- Date: 18 Dec 92 10:29:28 GMT
- References: <q50qgdg@dixie.com> <1992Dec11.164849.3491@nic.csu.net>
- <e6TZ03sdc2.200@amdahl.uts.amdahl.com>
- <1992Dec12.064534.3499@nic.csu.net>
- <26Cu03elc3du00@amdahl.uts.amdahl.com>
- <PCL.92Dec15173300@rhodium.ox.ac.uk>
- <1992Dec16.211155.19172@klaava.Helsinki.FI>
- Organization: Oxford University Computing Services, 13 Banbury Rd Oxford OX2
- 6NN
- Lines: 57
- In-reply-to: viljanen@klaava.Helsinki.FI's message of 16 Dec 92 21:11:55 GMT
-
- In article <1992Dec16.211155.19172@klaava.Helsinki.FI> viljanen@klaava.Helsinki.FI (Lea Viljanen) writes:
- ] In <PCL.92Dec15173300@rhodium.ox.ac.uk> pcl@ox.ac.uk (Paul C Leyland) writes:
-
- ] >In article <26Cu03elc3du00@amdahl.uts.amdahl.com> grjost@uts.amdahl.com (Garrett Jost) writes:
-
- ] > I'll leave on this note: On many systems, if you mail a letter to a non-
- ] > existent user, the message gets sent back, but a copy also goes to
- ] > "postmaster". So if you mistype a friend's e-mail address and write
- ] > he/she a very personal message, it isn't very personal anymore, is it?
-
- ] >For this very reason, I made very strong requests to our mail guru to
- ] >fix it for Postmaster to get only the mail headers. She did, and now
- ] >only the originator gets the message body. I, as joint-postmaster
- ] >still get to see the headers in case they indicate problems with the
- ] >system. Still not ideal privacy, perhaps, but better than the
- ] >alternative.
-
- ] This is a two edged sword here. By enhancing the user's privacy
- ] you also diminish their chances to get information. Just guess
- ] how many internet guides tell people to mail postmaster@site
- ] to get information about e-mail addresses. These mail messages
- ] get truncated too.
-
-
- I'm sorry, my comment was not phrased very well. The message body
- only gets omitted from mailer-generated failure messages.
-
-
- DIRECT MAIL TO POSTMASTER IS DELIVERED TO POSTMASTER IN ITS ENTIRITY.
-
-
- ] It's not altogether obvious where to cut off the rest of
- ] the the mail message either.
-
- ] >I strongly recommend that everyone else either fixes their mailer
- ] >similarly, or gets their Postmaster to fix it.
-
- ] I strongly recommend everybody to at least think this carefully over.
-
- ] I think the best solution would be to encrypt the message body
- ] (by rot-13 or something) to eliminate the accidental reading
- ] of the message. But the message in its entirety should be available
- ] to the Postmaster if he/she needs it.
-
-
- Maybe. However, it still allows Postmaster to snoop with great ease.
- Our solution requires that Postmaster must explicitly seek out mail addressed
- and delivered to the originator.
-
- Paul
-
- --
- Paul Leyland <pcl@oxford.ac.uk> | Hanging on in quiet desperation is
- Oxford University Computing Service | the English way.
- 13 Banbury Road, Oxford, OX2 6NN, UK | The time is come, the song is over.
- Tel: +44-865-273200 Fax: +44-865-273275 | Thought I'd something more to say.
- Finger pcl@black.ox.ac.uk for PGP key |
-