• Victor: mail2news v1.0.0

    From Gabx@victor@virebent.onion to mail2news on Thu Dec 4 00:09:36 2025
    From Newsgroup: alt.privacy

    Just pushed a major upgrade to the mail2news gateway.
    Lots of under-the-hood work to make traffic analysis harder.

    What's new:

    CSPRNG everywhere (bye bye math/rand)
    Constant-time comparisons against timing attacks
    SHA-256 hashed Message-ID cache
    Secure memory wiping for sensitive data

    Anti-traffic analysis goodies:

    Adaptive message padding (512-4096 bytes)
    Randomized delays (50-500ms + jitter)
    Metadata stripping on steroids

    Heads up:
    X-Hashcash header no longer makes it to NNTP.
    Why?
    It contains your exact posting timestamp - kind of defeats the purpose of all that timing obfuscation.
    Don't worry, PoW validation still happens server-side before anything gets posted.
    Full docs: https://news.tcpreset.net/mail2news.html

    Gabx

    --- Digital Signature --- w+UBcYr7D+rf8gUwg6j9ELMzc7nbMmeqQ84P6O3VGBTSGkclcfEzUdg1i1EYkDVd1H9KCEr5BHv/SH+2WZHWDA==

    --- Synchronet 3.21a-Linux NewsLink 1.2
  • From Stefan Claas@noreply@oc2mx.net to alt.privacy.anon-server,alt.privacy,alt.cypherpunks on Thu Dec 4 01:39:56 2025
    From Newsgroup: alt.privacy

    Gabx wrote:

    Just pushed a major upgrade to the mail2news gateway.
    Lots of under-the-hood work to make traffic analysis harder.

    What's new:

    CSPRNG everywhere (bye bye math/rand)
    Constant-time comparisons against timing attacks
    SHA-256 hashed Message-ID cache
    Secure memory wiping for sensitive data

    Anti-traffic analysis goodies:

    Adaptive message padding (512-4096 bytes)
    Randomized delays (50-500ms + jitter)
    Metadata stripping on steroids

    Heads up:
    X-Hashcash header no longer makes it to NNTP.
    Why?
    It contains your exact posting timestamp - kind of defeats the purpose of all that timing obfuscation.
    Don't worry, PoW validation still happens server-side before anything gets posted.
    Full docs: https://news.tcpreset.net/mail2news.html

    Gabx

    --- Digital Signature --- w+UBcYr7D+rf8gUwg6j9ELMzc7nbMmeqQ84P6O3VGBTSGkclcfEzUdg1i1EYkDVd1H9KCEr5BHv/SH+2WZHWDA==


    Small suggestion. When posting such important updates, would it not
    be nice for people that your postings contains a digital signature
    one can verify and associate with you?

    Regards
    Stefan
    --
    https://tilde.club/~pollux/
    --- Synchronet 3.21a-Linux NewsLink 1.2