Stories
Slash Boxes
Comments

News for nerds, stuff that matters

IRC Improvements

Posted by michael on Sat Sep 30, 2000 03:54 AM
from the contradiction-in-terms dept.
SUIDNet writes: "The first ever secure IRC network has opened. All your communications on the SUIDNet are completely encrypted so no one can just sniff the network and watch your conversations. In addition, anyone who connects unencrypted automatically has a "-insecure" appended to their hostname and are banned from all SECURE channels. Check it out for yourself at http://suidnet.org or irc.suidnet.org." We also got a submission about a plan to improve IRC routing, Open Redundant-Link IRCd.
This discussion has been archived. No new comments can be posted.
Secure IRC Network | Log In/Create an Account | Top | 75 comments (Spill at 50!) | Index Only | Search Discussion
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1) | 2
  • BITNET relay chat by Anonymous Coward (Score:1) Saturday September 30 2000, @12:08AM
  • Re:SILC by cras (Score:1) Saturday September 30 2000, @04:04AM
  • Re:.. by slut muffin (Score:1) Saturday September 30 2000, @12:14AM
  • by drrobin_ (131741) on Saturday September 30 2000, @05:24AM (#743311)
    Much as you may not like it, you can't set limits on free speech without it becoming un-free. I've seen a lot of jabbering about kiddie porn in the comments. So what? If some people, for their own reasons, like trading that stuff, who are you to tell them they can't, just because you don't like it?

    What if they said that the picture of your kids at the beach, building a sand castle constituted kiddie porn?

    My point is that you can't draw a fuzzy line in an issue like this. Just saying 'Kiddie Porn Is Bad' won't get you anywhere. Sure, it'll make you look better in your community, because the majority of people will agree with you. But that leaves the door open for too much abuse. Where does porn start? Where does your picture at the beach fit into this?

    A hard line, like "Kiddie Porn is when Nipples Are Showing On Children Under 18" is also ridiculous. Ever seen a Huggies commercial? Would you call it porn? This also leaves room for they people you are trying to stop to maneuver around the law. ("See? She's not showing her nipples!")

    If you support an encrypted IRC network, then great. If you don't support an encrypted IRC network, then great. If you support a specially monitored, only 'nice' channels allowed, Absolutely No Kiddie Porn network, you're in for a tough time. How are you going to regulate it? Are -You- going to do it? Who would come to your network, anyways?

    Comments like 'Encryption makes spreading kiddie porn' easier are pretty silly. Of course it does. Does that mean I shouldn't use encryption? Does that mean there should be a trusted IRCop in every channel, watching for any kiddie porn? Much as it's nice to have morals, whining won't solve your problem.

    PS- If you really want help your kiddie porn crusade, I suggest you contribute to developments in AI. If you accept the idea that people will eventually create a self-aware computer program, you can accept the idea that it will probably be used to monitor internet traffic.

  • Try Gale. IRC is NOT the platform to build on. by Shayde (Score:2) Saturday September 30 2000, @05:24AM
  • Re:Negative people on slashdot. by GigsVT (Score:1) Saturday September 30 2000, @01:17PM
  • Gale Secure Messaging Service gale.org by billstewart (Score:2) Saturday September 30 2000, @02:09PM
  • Re:Is this kind of security needed for IRC? by ckedge (Score:1) Saturday September 30 2000, @06:05AM
  • Re:In other news.... by dinkmaster (Score:1) Saturday September 30 2000, @02:57PM
  • Re:No, services requiring IDENTD are evil. by cculianu (Score:1) Saturday September 30 2000, @03:00PM
  • Re:Sense of security good but... by sniggly (Score:1) Saturday September 30 2000, @03:02PM
  • Re:Whats the point? by GroovBird (Score:1) Sunday October 01 2000, @04:18AM
  • SILC (Score:3)

    by Bostik (92589) on Saturday September 30 2000, @12:49AM (#743320)

    It seems secure IRC-like systems are spranging up. Quite understandable. From the land of Linux comes one.

    SILC [silc.pspt.fi] takes a new approach. It's not about adding encryption via SSL to existing networks, but building secure network and clients from ground up.

    And no, it's not intended as a replacement for IRC. It's an alternative. - And if I understood C any better, I'd be developing this one as well.

  • Avatar comms systems mostly a step backwards by Morgaine (Score:2) Saturday September 30 2000, @12:53AM
  • by h1kari (238532) on Saturday September 30 2000, @12:54AM (#743322) Homepage
    I am one of the suidnet admins and I'd just like to comment to some of the posts here to make things a little more clearer.

    Suidnet is a very new network, it has only been around for less than a week and we're still working on getting the kinks out, and we have never fully guaranteed security. All we do guarantee is that your link to the server and the links connecting the servers will be encrypted and that we are trying our best to ensure that all of the servers are secure. This is not fully implemented yet, but it will be within a week, so please do not exchange sensitive information until notified on the website.

    Currently the ircd source is experimental but will be publicly released when fully finished (it is based on hybrid6rc4). I can say that we use stunnel to ssl wrap all of the connections between the servers and for connected clients (useful for running one server for encrypting/decrypting and one for ircd). I can also say that we only made modifications to the ircd to obtain hostnames of users connected through stunnel and to append -insecure to unencrypted connections and that none of them are run in debug mode.

    The basic idea is that unencrypted users get -insecure appended to their hostname so if you are connected securely and want to run in secure mode, you can /ignore *!*@*-insecure, or if you want to run a secure channel you can /ban *!*@*-insecure, etc.

    Oh, and all of the swapping of MP3s and kid porn that is done over /dcc will not be encrypted unless both ends run irc clients that encrypt dcc. We can't even guarantee that dcc will work the same as with normal irc yet.

    Any/all comments are welcome as always, and I'm glad to see all of the discussion going on here on /.

    -Ttyl

  • Where, Pray tell, is the Source? by Jays (Score:2) Saturday September 30 2000, @01:08AM
  • Re:Demystifying Suidnet by DFX (Score:1) Saturday September 30 2000, @01:15AM
  • Re:Resonable explecation of privacy by Vegeta99 (Score:1) Saturday September 30 2000, @06:41AM
  • Re:Sense of security good but... by bellings (Score:1) Saturday September 30 2000, @06:42AM
  • Software with Sexual Orientation? by AgentX (Score:1) Saturday September 30 2000, @07:25AM
  • Re:Negative people on slashdot. by cosmosis (Score:2) Saturday September 30 2000, @08:19AM
  • Shades of EFNET by Anonymous Coward (Score:1) Saturday September 30 2000, @08:32AM
  • Re:Demystifying Suidnet by BasharTeg (Score:1) Sunday October 01 2000, @05:56PM
  • Don't Laugh... by crisco (Score:2) Saturday September 30 2000, @08:44AM
  • encryption not a big crisis. by Restil (Score:2) Saturday September 30 2000, @08:52AM
  • Re:Demystifying Suidnet by BasharTeg (Score:1) Sunday October 01 2000, @05:57PM
  • Re:Where, Pray tell, is the Source? by BasharTeg (Score:1) Sunday October 01 2000, @05:59PM
  • Re:Language Sexual Orientation: A guide by BasharTeg (Score:1) Sunday October 01 2000, @06:03PM
  • Re:Traffic analysis and secure messaging - thought by BasharTeg (Score:1) Sunday October 01 2000, @06:13PM
  • Re:Negative people on slashdot. by sg_oneill (Score:1) Sunday October 01 2000, @06:16PM
  • Re:Negative people on slashdot. by sg_oneill (Score:1) Sunday October 01 2000, @06:43PM
  • IRC Security and whats really needed. by theflamingmoose (Score:1) Sunday October 01 2000, @08:23PM
  • That's great! (Score:4)

    by pb (1020) on Friday September 29 2000, @10:59PM (#743340)
    Can we make it completely anonymous, too?

    That way, no one else has to know who you are, or what you're saying... wait, if I wanted that, I could just lock myself in the closet...
    ---
    pb Reply or e-mail; don't vaguely moderate [ncsu.edu].
  • Is this kind of security needed for IRC? by vertical-limit (Score:2) Friday September 29 2000, @11:02PM
  • Depends (Score:5)

    by StandardDeviant (122674) on Friday September 29 2000, @11:08PM (#743342) Homepage Journal

    Friend of mine works at (large computer manufacturing company). They have a non-official irc channel, sort of an e-WaterCooler...

    Anyway, internal MIS dept. found out about it and started sniffing the network, and logged EVERYTHING that was said in the channel over a three week period. Talk of stupid bosses, who was screwing who, drug taking at weekend parties, the works.

    Upshot: 6 people fired, 3 more severely reprimanded.

    So, yeah, if you want to chat at work without "the man" hearing everything, this is a pretty important development. :^)


    --

  • less netsplits+and a more intelligent user base by Cire LePueh (Score:1) Friday September 29 2000, @11:09PM
  • Sense of security good but... by A1kmm (Score:2) Friday September 29 2000, @11:03PM
  • Re:Depends by BJH (Score:1) Friday September 29 2000, @11:13PM
  • Re:Is this kind of security needed for IRC? by Cire LePueh (Score:1) Friday September 29 2000, @11:18PM
  • Another tax on the server? Eek... by global (Score:2) Friday September 29 2000, @11:21PM
  • Huh? by Anonymous Coward (Score:1) Friday September 29 2000, @11:22PM
  • Re:Demystifying Suidnet by Masem (Score:2) Saturday September 30 2000, @01:25AM
  • Re:Real security... by Menso (Score:1) Saturday September 30 2000, @01:28AM
  • by isaac (2852) on Saturday September 30 2000, @08:56AM (#743351)
    We ditch the IRC model, which is fundamentally insecure inasmuch as it requires an extra layer of trust (the server op), who's in a prime position to be leaned-on by [insert powerful party].

    Something I haven't seen brought up in these discussions is traffic analysis. Foiling TA is the key to truly secure communications. This is tougher than it sounds, as there are many ways to glean info from an encrypted channel.

    The "Buddy List" (or, if you prefer, list of users on a channel) is the most useful piece of intelligence for any security force. Start with an individual under suspicion, watch who that individual communicates with, when, and how frequently, and you know who to investigate next. Encrypted message traffic doesn't affect this channel of info.

    Consider encrypted ICQ - messages may be encrypted, and broadcast point-to-point, every user's "buddy list" lives on AOL's servers. Every sign-on or -off is recorded. At this point, say you've got a "buddy" in your list who's sharing MP3s or hosting DeCSS. RIAA/MPAA subpoenas user's buddy list from AOL (whoops, since it's AOL/TW, a court order probably isn't necessary!). Now you are brought under suspicion or targeted for harassment, or otherwise dragged into a case you may have known nothing about.

    Now, this has me thinking, what would it take to defeat TA in an instant-messenger type product. I'm not a coder by any means, but I have a few ideas:

    • No centralized servers, of course. "Buddy lists" stored at each client, exclusively

    • Clients continuously send/recieve encrypted traffic to neighboring hosts. Within fixed-sized encrypted blocks there might be user messages (w/ routing information encrypted in an "onion skin" fashion, so that a routing host doesn't know the final destination of the message, nor its true origin), client messages (newly connected client advertising its presence on the network, etc), or padding, if necessary to fill space. Continuously sending and recieving fixed-size chunks means others can't trace messages by monitoring traffic volume over time.

    • The network should only support messaging. The latency and scalability limits to this system should be tolerable for text messages, but would be shot to hell by file transfer.

    Any thoughts on this? Anyone working on such a system already?

    -Isaac

  • Forgot to mention... by isaac (Score:2) Saturday September 30 2000, @09:07AM
  • Re:Negative people on slashdot. (OT) by GigsVT (Score:1) Saturday September 30 2000, @09:43AM
  • Re:Negative people on slashdot. by DaveHowe (Score:2) Saturday September 30 2000, @10:48AM
  • web server = losangeles3.ca.us.suidnet.org by jesser (Score:2) Saturday September 30 2000, @11:20AM
  • Hostname by jesser (Score:2) Saturday September 30 2000, @11:25AM
  • Re:How secure is this really? by monas (Score:1) Sunday October 01 2000, @11:35PM
  • Re:Demystifying Suidnet by bugg (Score:1) Saturday September 30 2000, @12:01PM
  • Andy Church's IRC3 proposal by chromatix (Score:1) Monday October 02 2000, @12:09AM
  • Re:Screw encryption, I want redundant links by Mr2001 (Score:1) Saturday September 30 2000, @12:02PM
  • Re:anonirc by Cymbaline (Score:1) Monday October 02 2000, @04:12AM
  • kpr0nz==sexual exploitation by theonetruekeebler (Score:2) Monday October 02 2000, @05:33AM
  • Re:kpr0nz==sexual exploitation by cosmosis (Score:1) Monday October 02 2000, @09:01AM
  • What about Jabber? by lamour (Score:1) Monday October 02 2000, @09:48AM
  • Re:Demystifying Suidnet by bugg (Score:1) Monday October 02 2000, @11:26AM
  • Re:Negative people on slashdot. by DaveHowe (Score:2) Tuesday October 03 2000, @03:40AM
  • Re:kpr0nz==sexual exploitation by Spoobie (Score:1) Tuesday October 03 2000, @07:44AM
  • Real security... by subreality (Score:2) Friday September 29 2000, @11:24PM
  • by GigsVT (208848) on Friday September 29 2000, @11:27PM (#743369) Journal
    My god... I can't believe you people sometimes. You think carnivore is bad, and you pontificate about encryption being the only way to secure your email from the Government's prying eyes. Then this story comes out, and of the comments so far, no one has anything good to say about it.

    Don't you think the Government already has some sort of monitoring system for IRC? Don't you think that this would at least provide some higher level of security than none at all? Sure, none of you all will admit to using IRC, but that doesn't matter, because hundreds of thousands of other people do use IRC, and in the end, we are the ones that know how to protect ourselves, they are the ones that don't.

    I think this system is a good idea, and while some of you have valid points, there are limits to the security of a public messaging system. After all, all security eventually boils down to trusted authority regarding identity, which is something IRC may never have.
    -
  • Re:Is this kind of security needed for IRC? by nchip (Score:1) Friday September 29 2000, @11:31PM
  • Re:Negative people on slashdot. by ShadowRayven (Score:2) Friday September 29 2000, @11:34PM
  • by Isomer (48061) on Friday September 29 2000, @11:35PM (#743372) Homepage
    All IRC is, is a glorified multiplexor on steriods
    with delusions of grandeiur. If all the links are
    encrypted from clientsservers then how much security have you really gained? Noone can sniff your network, but do you trust the admin's of the servers not to patch the daemon and sniff your traffic? What about the local SS coming and forcing you to install those patches? You'd be far better to extend the CTCP (Client To Client Protocol) that runs over the top of irc to support encryption. IRC already has this in the 'SED' CTCP, which unfortunately isn't too secure. Someone with some spare time could easily hack this up.

    The next point is how much cpu do you have? Encryption is
    all very fine, but having the servers do all the work causes all sorts of problems, when you hit 10k clients per server as some networks have done how much cpu are you going to need to use then?
  • Re:Negative people on slashdot. by GigsVT (Score:1) Friday September 29 2000, @11:39PM
  • Re:Resonable explecation of privacy by Bwerf (Score:1) Saturday September 30 2000, @02:09AM
  • Re:Developing alternatives: by Bwerf (Score:1) Saturday September 30 2000, @02:23AM
  • Screw encryption, I want redundant links by Mr2001 (Score:1) Saturday September 30 2000, @02:32AM
  • anonirc by Bake (Score:2) Saturday September 30 2000, @03:06AM
  • Interesting... by Isomer (Score:2) Friday September 29 2000, @11:52PM
  • In other news.... (Score:3)

    by soulsteal (104635) <estisdal AT gmail DOT com> on Friday September 29 2000, @11:54PM (#743379) Homepage

    Today was the announcement of the encryption toilet, SecureJohn (SJohn). When flushed, it scrambled it's contents as to render them useless to prying eyes. Microsoft has chosen to implement it's own version in it's latest OS with stand alone versions available for purchase. While MS John will not be full compatible with SJohn, open source proponents are rumored to be working on OpenJohn for the various flavours of Unix.
    Back to you CmdrTaco.

  • Resonable explecation of privacy by Felinoid (Score:1) Saturday September 30 2000, @12:04AM
  • .. by slut muffin (Score:1) Saturday September 30 2000, @12:05AM
  • Developing alternatives: by Mike Connell (Score:2) Saturday September 30 2000, @12:05AM
(1) | 2