Encryption of X-Trace and NNTP-Posting-Host
To preserve your privacy the header fields X-Trace and NNTP-Posting-Host are encrypted using the algorithm below. In return we add the encrypted field X-User-ID. Our setup has a few implications:
- All data necessary to identify a poster (at least all data available to us) is contained in the posting itself. No need to keep log files.
- The same key is used for all users. Should legal authorities ask for the key to identify the authority of one posting, they can identify all.
- We change the key in irregular intervals. However, we keep a backup of old keys.
- The key is stored in plain text on the host, leaving no protection in case the machine gets hacked or confiscated.
Thoughts on key length (German)
Schnuerpel::Crypt.pm
Schnuerpel::INN::Filter.pm
filter_nnrpd.pl






