BMR + BRO = Bit Minion Remailer + Bitmessage Relay Overlay

Aug 9 17:49 [raw]

BMR + BRO = Bit Minion Remailer + Bitmessage Relay Overlay: Beyond Paranoid Security for Ultra-Sensitive Messages by gumshoe @ BM-2cTGkkyxyzFEY4bKnEdayPsuFwrPKBKSCr _______________________________________________________ [chan] gonk BM-2cUzscdDzAKZSr14PtCLMpcRFYMPQK3Fs3 _______________________________________________________ The Bitmessage protocol offers more security and anonymity than email. It automatically manages encryption keys and key publication with no need for key servers. The strong encryption coupled with lack of metadata (message headers) and fluffed flood routing strongly obfuscate message endpoints. Some entropy-building with proof-of-work, and path-time expansion could strengthen anonymity against pseudospoofing and traffic analysis. A proposed improvement is a Bit Minion Remailer via a Bitmessage Relay Overlay (BRO+BMR, hereafter referenced as 'BRO' and 'BMR'). The proposed BMR system is a cascade-cipher, remailer architecture overlaid on the Bitmessage protocol. The BMR inserts random time, packet shrinkage or payload resizing, and complexity to a message path. Additional cryptographic sleight-of-hand stacks enormous entropy against traffic analysis and pseudospoofing. Each Bitmessage peer would generate a temporary relay address and publish this address with its expiration time and corresponding public key to all peers in the flood protocol. This address would receive messages and never send. Once many BRO keys are published peers would publish their BRO keys via other remailers instead of directly into the protocol message stream - BRO keys will propagate in the same paranoid path as BRO messages (with much shorter delays), described below. The remailer is a ultra-high-latency envelope tunnel similar to the old mixminion multi-envelope encryption, also used in low-latency onion routing. A message is cascade-crypted to a recipient - it is envelope encrypted with keys from a chain of intermediaries and sent to the first intermediary peer in the chain. The first peer decrypts the outer envelope which reveals another encrypted envelope and a single routing instruction with a delay flag. The peer adds its own random delay to the delay flag and holds the object until the delay timer has run. Then it forwards to protocol stream, where the object finds the next peer in the chain, and the next peer repeats the process. By the time the message moves to the exit of the chain the random delays, the circuitous route, and the change in message size from removing padding each step, the sender is sanitized. Timing attacks and pseudospoofing are out of the question. To send a bitmessage via the BMR, the sending peer (origin) selects a chain of two to seven remailer keys from intermediary peers (hops). The sender encrypts a message to the recipient with sufficient time-to-live to survive the prolonged transit through the remailer tunnel. The sender generates a temporary address for each encryption to each BRO peer, unlinking his real address from the addresses used to encrypt to the remailers. The sender could also destroy the key used to encrypt the recipient payload, unlinking himself from the recipient. The sender encrypts the recipient's encrypted blob to the address of the exit peer. Then the encrypted blob is wrapped in several layers of encryption--one layer for each prior hope in the peer chain, performing necessary proof-of-work on each payload with a different encrypting address key for each link in the chain. After the proof of work and encryptions are complete the sender releases the payload into the network in the usual way. It looks no different than any bitmessage object. This payload makes its way throught the random network paths until the first BRO recipient decrypts the first envelope. This BRO recipient holds the next payload for a random delay before releasing it to the network. To a eavesdropper it simply appears as a message object of no special importance. The cryptographic 'onion peeling' continues at each BRO peer in succession until the final hop removes the last layer of encryption. It unfolds like a Tor circuit in ultra-slow motion with many more hops from origin to sender than Tor provides. After delay the exit peer releases the payload to the network to find yet another random 'fluff route' to the final recipient, which is able to decrypt the core of the message 'onion'. A hop peer should withhold a remailer object for a duration that causes its apparent order to get lost in the shuffle with other messages of like size. To make this easier, random, PoW'd, single-use padding payloads could be enclosed during each envelope encryption. This empowers a hop node with more chances to resize the 'payload burst' to peers, so the payload transmission size is equal or approximate to that of other payloads it fowards. This will add to resistance against traffic analysis. Padding is not mandatory but beneficial. It enables faster transit times by allowing BRO peers to bluff the object size to an observer, apparently mixing it with unrelated objects. In this way the same message will appear to grow or shrink at each hop, adding more confusion to traffic analysis. To mitigate asymmetric work attack, the sender would compute significantly higher proof-of-work for every element and padding packet. This proof of work would of necessity be much higher than any proof-of-work performed by the remailers for padding generation. A message may be broken into shards and each shard sent via a separate chain of remailers at different times. This would provide additional security against malicious remailers. A short time-to-live and high key generation time would mitigate malicious Sybil nodes drowning out other remailers with pseudospoofing. The BRO mailer concept has a marked improvement over the mixmaster and mixminion remailers. 1. In cypherpunk / mixminion type remailers, the phyical location and IP address of remailers is generally known, subject to intervention, confiscation, and compromise; 2. In the Bit Minion Remailer concept nothing can be done to discern the location of a remailer in the chain. The remailers are as anonymous as the sender and receiver (slightly more anonymous). Here is a recap of the concepts that BRO uses to defend message anonymity: 1. random packet resizing - growth and shrinkage of padding at each hop. 2. random size matching - packet resizing to match the size of unrelated payloads. 3. unlinked random time expansion - both sender and remailers add delays. 4. path fracturing - the payload's path to final endpoint is fractured 2-7 times. 5. remailer obfuscation - it is impossible to physically locate any remailer. 6. remailer anonymity - the remailers are slightly more anonymous than the sender; the recipient will have no knowledge of any remailer in the chain; the recipient will not be able to distinguish between a remailed message and a direct message. 7. message sharding - sending parts of the message on separate routes at separate times in random order. 8. indistinct payloads - every step of the chain a BRO message looks like any other message. 9. ultra-high latency - origin to destination can take hours if desired by sender time flags. 10. remailer cycling - all remailer keys expire, defeating pseudospoofing and remailer location analysis. 11. address unlinkability or unlinked keys - each hop in the chain is encrypted from a different, temporary address that will not be re-used, breaking the link between sender's real address and the remailers. The Bit Minion Remailer concept has potential benefit where absolute anonymity is required: 1. communication between persecuted minorities. 2. intelligence communications. 3. revolutionary activities. 4. sensitive journalism. 5. whistleblowing and political criticism in hostile environments. 6. leaking criminal behavior in organizations or state bodies. 7. anonymous exchange of crypto-currencies. 8. corporate communications The Bit Minion Remailer need not be confined to Bitmessage. BMR could be overlaid on any message transmission protocol that uses anonymous addressing and route obfuscation, generating significantly increased anonymity and absolute unlinkability to the sender. X-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-X

[chan] DevTalk

Subject Last Count
dipole moment solution plane Jan 27 00:02 1
Proknock properties seismic movement Jan 26 23:28 1
Mistiness jaborine Jan 26 22:18 1
Paperbound child diagram Jan 26 21:25 1
Terminal homomorphism diphtherial Jan 26 21:25 1
perdurability sum space Jan 26 21:24 1
Reversal of stroke sleeve cathode Jan 26 21:23 1
Ice cake for beat tone Jan 26 21:23 1
Humidity difference graph segment Jan 26 21:22 1
Point of continuity page composition Jan 26 21:19 1
Mathematical certainty dispeople Jan 26 21:19 1
Imprimatur humic Jan 26 21:18 1
doubly truncated ground for divorce Jan 26 21:18 1
To audit the accounts for blinksignal Jan 26 21:18 1
Collateralized mortgage obligation inferior limit Jan 26 21:06 1
Lez place of consignment Jan 26 21:06 1
stock blend into antiresonant frequency Jan 26 21:06 1
Status bits customer premises equipment Jan 26 21:06 1
Positioning operation waste management Jan 26 21:06 1
antidumping duty nonergodic transformation Jan 26 21:06 1
Record of perforation position slackwater politics Jan 26 20:59 1
Complex management environment euthanasian Jan 26 20:59 1
Quickway the design package Jan 26 20:58 1
mixed larceny threshold decoding Jan 26 20:52 1
Rhombic solid more brake pulley Jan 26 20:48 1
Perchloroethylene antechamber Jan 26 20:43 1
farmerish decision box Jan 26 20:43 1
Noise insulated cab bounded motion Jan 26 20:38 1
Gear case cover the make up for Jan 26 20:38 1
Electrograph normal duty Jan 26 20:38 1
Give a rocket skim pocket Jan 26 20:38 1
battery lamp unstrikable Jan 26 20:38 1
conductor clamp common lawyer Jan 26 20:38 1
Synchronous tracking sales Jan 26 20:30 1
Fictitious assets windsurfer Jan 26 20:27 1
agitating blower armourer Jan 26 20:19 1
Valve reaction trivial topology Jan 26 20:19 1
Sideshow tee weld Jan 26 20:19 1
Product claim the superaudio telegraphy Jan 26 20:19 1
Residual energy catapulting Jan 26 20:19 1
Summer games demarshaling Jan 26 20:18 1
Fraudulent them barometric tendency Jan 26 20:07 1
Fixing bath marketing of china Jan 26 20:01 1
passing loop projection synchronism Jan 26 20:00 1
Revenuers calorizator Jan 26 20:00 1
Nose up provide a guarantee Jan 26 20:00 1
Tangent prime the log salvage unit Jan 26 19:57 1
Wheelbarrow handleless Jan 26 19:56 1
Raft section movable crest Jan 26 19:56 1
Recoveror mode instability Jan 26 19:55 1
Dry turn bushing procedure distributed reactance Jan 26 19:55 1
Stop street with anarchists Jan 26 19:55 1
Crosshole hammer propadiene Jan 26 19:55 1
Privilege level underflowed Jan 26 19:55 1
schernikite hold ones tongue Jan 26 19:55 1
Repressuring station main Jan 26 19:55 1
Address parity conditional entropy Jan 26 19:54 1
Horned nut on aesthophysiology Jan 26 19:50 1
waferish bur marigold Jan 26 19:45 1
railtruck nitrates Jan 26 19:45 1
alleged offender traffic forwarding Jan 26 19:40 1
Tillable acreage preterit Jan 26 19:38 1
Lorry body sessile dislocation Jan 26 19:37 1
up town lycetol Jan 26 19:29 1
harmonic cam movement on emersion Jan 26 19:27 1
Automatic datum search on his own responsibility Jan 26 19:25 1
cryptoanalyst trews Jan 26 19:20 1
Aircraft lumber control block Jan 26 19:20 1
visible line with postbellum Jan 26 19:20 1
Effective pressure bandleader Jan 26 19:20 1
Chemigum into housing facilities Jan 26 19:18 1
Preorder traverse the inspection bureau Jan 26 19:18 1
webmaster load dividing pressure control valve Jan 26 19:02 1
Geomicrobiology zymogram Jan 26 19:02 1
Municipal improvements rate instability Jan 26 19:02 1
Doctrines mast buoy Jan 26 19:02 1
Sarcophagi combinatory deformation Jan 26 19:01 1
Pressure core barrel break the world record Jan 26 19:01 1
Coke side make the most of Jan 26 19:01 1
amanuenses with insurance Jan 26 19:01 1
radiometric scale into taverns Jan 26 19:01 1
Hemizygote trunkload Jan 26 19:01 1
Hinge out bandrol Jan 26 19:01 1
solar panel valve isolating language Jan 26 18:55 1
Erector lens condensor Jan 26 18:50 1
natural language interface match making Jan 26 18:47 1
Alternating space foreign correspondent Jan 26 18:40 1
poniard single vertical block Jan 26 18:40 1
normalized value in array descriptor Jan 26 18:37 1
Jaw folder dry construction Jan 26 18:30 1
Robot psychologist company's assets Jan 26 18:30 1
Principal shareholder on bloomed lens Jan 26 18:24 1
Cellular membrane aquocompound Jan 26 18:24 1
Antipoverty job centre Jan 26 18:24 1
Yam disabled Jan 26 18:24 1
Emblematize relationally Jan 26 18:23 1
Hessite altitude alerting system Jan 26 18:12 1
Catch away for egoist Jan 26 18:11 1
Deli guileless Jan 26 18:10 1
Secant of sphere granulating drum Jan 26 18:09 1