mixminion
play

Mixminion Designing a Type-III Anonymous Remailer Protocol Nick - PowerPoint PPT Presentation

Mixminion Designing a Type-III Anonymous Remailer Protocol Nick Mathewson nickm@freehaven.net Our Goals Fix holes in Mixmaster (Type-II) remailers Conservative design Working implementation; deployed network Our Adversary


  1. Mixminion Designing a Type-III Anonymous Remailer Protocol Nick Mathewson nickm@freehaven.net

  2. Our Goals • Fix holes in Mixmaster (Type-II) remailers • “Conservative” design • Working implementation; deployed network

  3. Our Adversary • Global passive adversary • Owns some of the nodes • Can generate some traffic We are not real-time, packet-based, or steganographic.

  4. Changes from Mixmaster...

  5. Key Rotation/Replay prevention • Type II has no automated key rotation • Type II has sketchy replay prevention • Solve them together: keep hash of all headers seen since last key roation

  6. Secure replies • Cypherpunk has reply blocks, but is vulnerable to replay attacks (and everything else...) • Mixmaster has no reply blocks; people who want replies must use Cypherpunk. • Mixminion provides single-use reply blocks: • Indistinguishable from forward messages • ...even by the nodes!

  7. Link Encryption • Cypherpunk and Mixmaster use SMTP for transport • Mixminion uses TLS over TCP • Forward anonymity against future compromise

  8. And more... • Integrated directory service • Integrated exit policies • Nymservers with single-use reply blocks.

  9. Read our papers Play with our code http://mixminion.net/ We’ll be at Oakland (IEEE Security and Privacy) in May

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend