[8408] in Commercialization & Privatization of the Internet

home help back first fref pref prev next nref lref last post

Independent Milnet

daemon@ATHENA.MIT.EDU (Brad Templeton)
Thu Nov 18 06:41:21 1993

From: Brad Templeton <brad@looking.clarinet.com>
To: macnabr@cc.ims.disa.mil
Cc: com-priv@psi.com
Date: Thu, 18 Nov 93 3:39:39 PST

I believe most people will feel that this proposal is very ill-advised.
While many will agree with the value of allowing incoming telnet and
other services to be blocked, the idea of strange E-mail addresses
through a relay is pointless and will add great confusion on the net.

It should be possible to disconnect the networks but still allow seamless
e-mail addressing.   It will take a bit of work but it will be worth it.

You don't want open SMTP connections, I assume.  So what you must do is
create nameservice on the internet that says all Milnet mail must use
the gateway as a mail exchanger (MX), and similar nameservice on the
milnet going the other way.

Sites on the internet will ask, "how do I mail to foo.mil" and the
gateway nameserver (on the internet) will tell them to send the mail to
the gateway.  It can then send the mail through some fortified channel
to the gateway machine on the milnet.  And vice versa.

Of course, if you allow outgoing telnet and ftp and etc. from milnet
sites, that is still a security hole, but a lesser one and one you have
decided to accept.

You may consider providing a machine on the internet with an FTP repository
that milnet users can get space on if they wish to put a file up for FTP.
This is no security hole if outgoing ftp is already allowed.

home help back first fref pref prev next nref lref last post