From Newsgroup: news.admin.peering
Privacy is a million things, of which most people know about 3.
To add at least 1 more thing to that privacy implication list...
Q: Do we have an updated privacy table of what free news servers do
with respect to nntp posting host/account obfuscation practices?
(aioe) (albasani) (bbs.nz) (bofh) (chmurka) (csiph) (dizum)
(endoftheline) (eternalsept) (freedyne) (gmane.org) (hispagatos)
(mixmin) (mozilla.org) (neodome) (netfront) (news4all) (novabbs)
(pugleaf) (samolyk) (solani) (sunsite) (tcpreset) (usenet.ovh) (xsusenet)
I ask only because once every decade (or two) I revisit the privacy
status of nntp posting hosts and account obfuscation (or lack thereof).
Below is the nucleation particle that caused me to re-think about it,
as I likely haven't updated this table in well over a decade myself.
This is an old table so it is NOT accurate, nor is it inclusive!
--- < begin old table > ---
The worst servers reveal your NNTP posting host/acct in cleartext.
Most servers obfuscate, but they never change their obfuscation.
The best servers (wrt privacy) switch up the obfuscation.
However, the obfuscation method may or may not be sophisticated.
aioe = obfuscates the NNTP Posting Host & never changes it
esept = obfuscates account information & never changes it
mixmin = first obfuscated NNTP posting host on a monthly hash, but
then reverted to static due to it being a PITA to maintain
albasani = obfuscates NNTP posting host & account for each post
solani = obfuscates NNTP posting host & account differently for each post
netfront = for decades it reveals NNTP posting host in cleartext
but I think it now displays a permanent obfuscation
sunsite = reveals NNTP posting host in cleartext
mozilla = used to post in the clear but I'm no longer sure what it does
---- < cut here for the referenced Usenet header analysis > ----- Newsgroups: comp.mobile.android
Subject: Re: Contacts
Date: Sat, 12 Sep 2026 17:31:03 -0000 (UTC)
Message-ID: <118428m$el6$
1@nnrp.usenet.blueworldhosting.com>
AJL wrote:
What more info does that snitch?
Hi AJL,
I like that you're inquisitive about what is revealed in the wrapping paper (especially since the gift of the largesse is actually in the article body).
I'm not an expert in Usenet headers but what I can glean from your headers, only from what your headers report, are the following visual observations.
[Note Frank & I have had this discussion twice about what can easily be spoofed vs what isn't as easily spoofed (e.g., part of the PATH but not the whole PATH, & certainly some of the time stamps & certainly newsreaders.]
1. Your header identifies you as AJL <
noemail@none.com> where
most newsreaders require an email, although it's usually spoofed.
2. Thunderbird 45.0 is being advertised by your User-Agent header.
That is a claim made by the client but it could be falsified.
3. It's a 32-bit Windows application running on 64-bit Windows.
4. rv:45.0 is the Mozilla/Gecko runtime version associated with
that old Thunderbird build.
5. Gecko/20100101 is largely a compatibility/user-agent token.
It does not mean the machine dates from 2010.
6. The combination of charset=windows-1252, format=flowed and
Content-Transfer-Encoding: 7bit is consistent with the older
Mozilla/Thunderbird-era software, which doesn't tell us much,
but the MIME headers are consistent with the claimed newsreader.
7. The Date: header says the sender's claimed local time was
08:32:36 -0700. The corresponding UTC time is 15:32:36.
8. Your machine is set to the -0700 timezone offset, which, in
September, is consistent with Pacific Daylight Time (PDT)
9. The Injection-Date is also 15:32:40 UTC, only four seconds later.
That suggests the posting software/server preserved a plausible
client timestamp, though it doesn't prove the clock was accurate.
10. Your PATH (some of which can be spoofed) indicates the flow between
a. Your posting host was "a6cd7ce76502b24500f03c493873f13a"
b. Your posting account was "U2FsdGVkX1/ooDefZcb8oiDcPO2zbn2w"
c. nntp.eternal-september.org -> feeder.eternal-september.org ->
eternal-september.org -> feeder8.news.weretis.net -> weretis.net ->
nntp.giganews.com -> border-4.nntp.ord.giganews.com -> mine -> me
Summarized, you posted via an Eternal September account which then
propagated through Weretis, then Giganews, until it got to my server.
Perhaps "ord" indicates Chicago O'Hare, so perhaps the Giganews server
is located nearby, but that would be simply a heuristic wild-ass guess.
Regarding the posting host and account, I didn't bother to check Eternal September headers, over time, but they could be static, i.e., only assigned
to you, or, perhaps they're changed every day, or every post. Didn't check.
I never bother decrypting the obfuscated posting host (i.e., your IP
address) and account, but we can see U2FsdGVkX1 which is the familiar
Base64 representation of data beginning with Salted_, which is somewhat characteristic of OpenSSL's traditional salted encryption format.
So it does not look like a conventional SHA-1/SHA-256 hash, which, if it's
a hash that Wolfgang M. Weyand <
wolfgang@eternal-september.org> (aka Ray Banana) devised himself, is likely long ago broken by typical TLAs, which,
I realize, none of us care about, but it's something you should just know.
Likewise, your IP address (posting host) is 32 hexadecimal characters,
which looks like an MD5-sized value, but appearance isn't enough to
establish that it's MD5. As with the account, it could be Wolfgang's obfuscated 128-bit value or simply an arbitrary identifier for you.
Note: If we look at an old post from you, we can tell if it's static.
If it's static, then changing all of the other headers will still identify that it's you, which, I know you don't care about but it's a datapoint in terms of understanding what a Usenet header can reveal about your location.
With respect to privacy, if the posting account is static, I can find all
your posts from the beginning of time, thru that server using that account, and, if I cared to invest in the energy of decrypting the IP address (which
I certainly do not), then it's maybe possible to find out your IP address.
Again, I'm only telling you this to answer your question about what your headers snitch about you, as I have no desire to hunt you down by them. :)
Note that Frank used to run his own NNTP server so he likely knows more,
and, perhaps, he'll find flaws in my analysis above, which I would welcome.
--
On Usenet, old men with vast experience voluntarily share that knowledge.
Path: news.blueworld.net!border-4.nntp.ord.giganews.com!nntp.giganews.com!weretis.net!feeder8.news.weretis.net!eternal-september.org!feeder.eternal-september.org!nntp.eternal-september.org!.POSTED!not-for-mail
From: AJL <
noemail@none.com>
Newsgroups: comp.mobile.android
Subject: Re: Contacts
Date: Sat, 12 Sep 2026 08:32:36 -0700
Organization: A noiseless patient Spider
Lines: 20
Message-ID: <1183ran$3serr$
1@dont-email.me>
References: <
0iljmmx7hp.ln2@Telcontar.valinor> <
jks1al9jgtjm4r1l5kre21u1291gtatg0p@4ax.com> <117s321$1amgb$
1@dont-email.me> <117tsi8$1rla8$
1@dont-email.me> <117ulvv$29vm$
1@nnrp.usenet.blueworldhosting.com> <117uqil$277vs$
1@dont-email.me> <11800ai$2343$
1@nnrp.usenet.blueworldhosting.com> <11808jc$2looe$
1@dont-email.me> <1180abo$20vl$
1@nnrp.usenet.blueworldhosting.com> <1181g4h$34bku$
1@dont-email.me> <1181i9r$71l$
1@nnrp.usenet.blueworldhosting.com> <1181luv$36in6$
1@dont-email.me> <
1183pej.11co.1@ID-201911.user.individual.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=windows-1252; format=flowed Content-Transfer-Encoding: 7bit
Injection-Date: Sat, 12 Sep 2026 15:32:40 +0000 (UTC)
Injection-Info: dont-email.me; logging-data="4078459"; mail-complaints-to="
abuse@eternal-september.org"; posting-account="U2FsdGVkX1/ooDefZcb8oiDcPO2zbn2w"; posting-host="a6cd7ce76502b24500f03c493873f13a"
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.0
Cancel-Lock: sha1:fL8/mwyGwdY05IZxnLvwZquw9DQ= sha256:4JvmnDatez9QEXIslvpdh/pcDdgOr4I6eh27KQWbezw= sha1:uOpeH1W4XkiNeqa8yhzZRwOlFOg= sha256:lftB8brUv9mjvb4Tp5ppJeTCV5yfZEP04bu0O+pKJNY=
In-Reply-To: <
1183pej.11co.1@ID-201911.user.individual.net>
Xref: news.netfront.net comp.mobile.android:86939
--- Synchronet 3.22a-Linux NewsLink 1.2