[117422] in Cypherpunks
Re: Goldberg Does PrivacyX
daemon@ATHENA.MIT.EDU (Ian Goldberg)
Thu Sep 2 21:16:34 1999
To: cypherpunks@cyberpass.net
From: iang@cs.berkeley.edu (Ian Goldberg)
Date: 3 Sep 1999 00:54:43 GMT
Message-ID: <7qn68j$5e5$1@abraham.cs.berkeley.edu>
Reply-To: iang@cs.berkeley.edu (Ian Goldberg)
In article <199909022139.OAA28306@hardly.hotwired.com>,
James Glave <james@wired.com> wrote:
>http://www.wired.com/news/news/technology/story/21561.html
>
>Secure Browsing? Not So Fast
>by James Glave, Wired News
>1:45 p.m. 2.Sep.99.PDT
>
>As soon as a new Web service was launched this week promising completely
>anonymous and private Internet use, along came a renowned crypto expert to
>punch a huge hole in the claim.
>
>And what was the immediate reaction of the director of technology for
>PrivacyX, which uses a Web browser's built-in digital certificate
>technology to offer completely anonymous Web browsing, email, and chat?
>
>"Cool," said Wil Boucher.
>
>His next reaction was to fix it.
>
>"The hole has been repaired, and will not be a problem," Boucher said
>within an hour of being alerted to the flaw.
>
>In any event, this wasn't the way PrivacyX CEO Douglas Whorrall had hoped
>to launch his service after building it up for the last year and a half.
I've been busy with this and other things today. "Fix" is perhaps a strong
term. In the sense that "secure" is a strong term for rot-13. Here's the
rebuttal from my web site:
Update (2 Sept, 6:10 pm EDT)
In a Wired News article, Wil Boucher of PrivacyX claims to have
fixed the problem.
In a word, bullshit. His entire ``fix'' is to simply replace all
occurences of the word ``java'' in ANY page you visit with the
word ``FILTERED''. Since the demonstration link to the site which
displayed the user's real URL happened to have the word ``java''
in the URL, the *link* broke. But the site still learned your IP
address; it just stopped displaying it to you. I've fixed the link
so it no longer gets filtered in this way.
Note that PrivacyX may do some other ``hack'' to stop this
demonstration from working, without fixing the actual problem.
To see what a ridiculous situation the ``java'' replacement
causes, try visiting java.sun.com. (This link will only work
properly when using PrivacyX, because of other, unrelated, bugs in
their software.)
Claiming that this simple text replacement fixed the problem is
simply outright lying.
And now, in fact, they've simply shut the whole thing down.
They also put up their own document: https://www.privacyx.com/response.html
A choice piece:
> We would also like to point out that the flaw that was detected only
> allowed a remote site to determine what IP address a user was coming
> from -- at no time was the identity of the user ever revealed.
They're also claiming their secure email is still secure, but in fact, we
here haven't been able to get it to work *at all*. It *could* be something
we're doing wrong, but looking at the raw messages stored on their POP
servers, it looks to us (myself and Philippe Boucher, another engineer here
at Zero-Knowledge) like they're *badly* munging the messages as they go
in.
- Ian