[12959] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: Logging of Web Usage

daemon@ATHENA.MIT.EDU (Bill Frantz)
Thu Apr 3 23:51:09 2003

X-Original-To: cryptography@wasabisystems.com
X-Original-To: cryptography@wasabisystems.com
In-Reply-To: <20030403021618.GB15220@zork.net>
Date: Thu, 3 Apr 2003 11:32:03 -0800
To: Seth David Schoen <schoen@loyalty.org>, cypherpunks@lne.com,
	cryptography@wasabisystems.com
From: Bill Frantz <frantz@pwpconsult.com>

At 6:16 PM -0800 4/2/03, Seth David Schoen wrote:
>Bill Frantz writes:
>
>> The http://cryptome.org/usage-logs.htm URL says:
>>
>> >Low resolution data in most cases is intended to be sufficient for
>> >marketing analyses.  It may take the form of IP addresses that have been
>> >subjected to a one way hash, to refer URLs that exclude information other
>> >than the high level domain, or temporary cookies.
>>
>> Note that since IPv4 addresses are 32 bits, anyone willing to dedicate a
>> computer for a few hours can reverse a one way hash by exhaustive search.
>> Truncating IPs seems a much more privacy friendly approach.
>>
>> This problem would be less acute with IPv6 addresses.
>
>I'm skeptical that it will even take "a few hours"; on a 1.5 GHz
>desktop machine, using "openssl speed", I see about a million hash
>operations per second.  (It depends slightly on which hash you choose.)
>This is without compiling OpenSSL with processor-specific optimizations.

Ah yes, I haven't updated my timings for the new machines that are faster
than my 550Mhz.  :-)

The only other item is importance is that the exhaustive search time isn't
the time to reverse one IP, but the time to reverse all the IPs that have
been recorded.

Cheers - Bill


-------------------------------------------------------------------------
Bill Frantz           | Due process for all    | Periwinkle -- Consulting
(408)356-8506         | used to be the         | 16345 Englewood Ave.
frantz@pwpconsult.com | American way.          | Los Gatos, CA 95032, USA



---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@wasabisystems.com

home help back first fref pref prev next nref lref last post