[Cryptography] Mail Lists In the Post-Snowden Era

Devin Reade gdr at gno.org
Mon Oct 21 06:39:25 EDT 2013


At the risk of stating the obvious, going to an anonymized list
is not without its own problems.  One big part of the usability of
many mailing lists involves the reputation of the poster.  Take
this list for example:  I am not a cryptographer (I'm a software
architect and developer).  I've found the conversations on this
list interesting and it gives me things to think about in the
design and implementations of my own systems (and those of my
clients).

So what's the difference between this list and some arbitrary
list full of crackpots?  Here, if there is an argument that I
can't quite follow in sufficient detail to satisfy myself, one
option is to examine other sources with respect to the posters
and the topics at hand, and how they are considered by other
publicly-known cryptographers.  It's not the the best, but it
helps.

An analog exists, at least to some extent, on other mailing
lists.

As an aside, on a public list or bulletin board (anonymous or not)
I would be surprised if there is not software in existence that
could correlate poster's mannerisms against publicly available
non-anonymized postings to in effect de-anonymize the supposedly
anonymous postings with a reasonable degree of accuracy.

Devin




More information about the cryptography mailing list