TweetFollow Us on Twitter

July 02 Viewpoint

Volume Number: 18 (2002)
Issue Number: 07
Column Tag: Viewpoint

by Rich Morin

Privacy by Default

Making Rendezvous safe
“for the rest of us”

Although Apple does not use these words to describe it, their new Rendezvous system is designed to enable “opportunistic, promiscuous” IP discovery. That is, it will take advantage of any opportunity to collect IP information (hence, opportunistic) and it will happily interact with any cooperative system (hence, promiscuous). These characteristics make Rendezvous extremely convenient for the user.

Unfortunately, the same characteristics could also make Rendezvous extremely convenient for anyone who wants to “listen in” on network traffic. If a user walks into a conference facility or coffee bar with a PowerBook, how many uninvited recipients will see his network traffic?

I’d like to see Apple provide “convenient privacy”, as part of its convenient networking. To be specific, I’d like them to implement “opportunistic, promiscuous” packet-level encryption, basedon IPSec and related standards. This isn’t a new idea, by any means. The “Linux FreeS/WAN” project (http://www.freeswan.org) has been working on it for several years now; their early releases are currently being tried out in the field.

The high-level view of FreeS/WAN is quite simple. If my system has a packet to send to your system, it will first attempt to set up a VPN (Virtual Private Network), using IPSec, etc. If your system doesn’t honor the request, my system will simply send the packet “in the clear”.

If your system does understand the request, however, both systems will send off for each others’ public keys (e.g., from each others’ DNS servers). The two systems will then perform a key exchange, with the result that they both end up with the needed “session keys”. Et voila, we have a VPN!

The low-level description is a bit more complicated, but some folks may find it interesting. See http://www.freeswan.org/freeswan_trees/freeswan-1.95/doc/intro.html if you’re into that sort of thing...

Meanwhile, let’s look at some of the implications of the technology. In general, privacy and security tend to be at odds with convenience. And, as we all know, when “I really should” gets in a fight with “I don’t want to”, it usually loses. Consequently, although PGP and other strong privacy tools have been around for several years, they aren’t actually used very much. Even SSH has had an uphill fight against its (demonstrably insecure) predecessors.

By making network privacy the default, however, Apple could remove the “convenience factor” from the equation. Joe and Sally Sikspak don’t have to install privacy software, set up keywords, or any of that hassle. Better yet, they don’t have to decide which programs (or files, or ...) deserve encryption. No decisions, so no mistakes! In fact, they don’t even have to know that encryption is going on; their packets are simply a bit safer from snooping.

Apple likes to be seen as a standard-setter. By allying themselves with the Linux FreeS/WAN project (and, ideally, providing an Open Source BSD implementation), Apple could help to make opportunistic privacy an established standard. There are no guarantees, of course, but privacy and authentication are very salable attributes these days...

Even without total buy-in by the computer industry, the effects of opportunistic encryption could be quite dramatic. For instance, it would be quite possible to set up a FreeS/WAN “gateway server” at an ISP or on the border of a LAN, providing encryption capability for any external traffic. Like the Sikspaks, the machines being protected would never need to know that their packets were being encrypted.

In addition, large-scale use of packet-level encryption would make it much harder to single out encrypted data streams for attack. If even 5% of the Internet’s traffic is encrypted, the mere fact of encryption is no longer an “interesting” characteristic for snoopers.


Rich Morin has been using computers since 1970, Unix since 1983, and Mac-based Unix since 1986 (when he helped Apple create A/UX 1.0). When he isn’t writing this column, Rich runs Prime Time Freeware (www.ptf.com), a publisher of books and CD-ROMs for the Free and Open Source software community. Feel free to write to Rich at rdm@ptf.com.

 

Community Search:
MacTech Search:

Software Updates via MacUpdate

Latest Forum Discussions

See All


Price Scanner via MacPrices.net

Take $150 off every Apple 11-inch M3 iPad Air
Amazon is offering a $150 discount on 11-inch M3 WiFi iPad Airs right now. Shipping is free: – 11″ 128GB M3 WiFi iPad Air: $449, $150 off – 11″ 256GB M3 WiFi iPad Air: $549, $150 off – 11″ 512GB M3... Read more
Apple iPad minis back on sale for $100 off MS...
Amazon is offering $100 discounts (up to 20% off) on Apple’s newest 2024 WiFi iPad minis, each with free shipping. These are the lowest prices available for new minis among the Apple retailers we... Read more
Apple’s 16-inch M4 Max MacBook Pros are on sa...
Amazon has 16-inch M4 Max MacBook Pros (Silver and Black colors) on sale for up to $410 off Apple’s MSRP right now. Shipping is free. Be sure to select Amazon as the seller, rather than a third-party... Read more
Red Pocket Mobile is offering a $150 rebate o...
Red Pocket Mobile has new Apple iPhone 17’s on sale for $150 off MSRP when you switch and open up a new line of service. Red Pocket Mobile is a nationwide MVNO using all the major wireless carrier... Read more
Switch to Verizon, and get any iPhone 16 for...
With yesterday’s introduction of the new iPhone 17 models, Verizon responded by running “on us” promos across much of the iPhone 16 lineup: iPhone 16 and 16 Plus show as $0/mo for 36 months with bill... Read more
Here is a summary of the new features in Appl...
Apple’s September 2025 event introduced major updates across its most popular product lines, focusing on health, performance, and design breakthroughs. The AirPods Pro 3 now feature best-in-class... Read more
Apple’s Smartphone Lineup Could Use A Touch o...
COMMENTARY – Whatever happened to the old adage, “less is more”? Apple’s smartphone lineup. — which is due for its annual refresh either this month or next (possibly at an Apple Event on September 9... Read more
Take $50 off every 11th-generation A16 WiFi i...
Amazon has Apple’s 11th-generation A16 WiFi iPads in stock on sale for $50 off MSRP right now. Shipping is free: – 11″ 11th-generation 128GB WiFi iPads: $299 $50 off MSRP – 11″ 11th-generation 256GB... Read more
Sunday Sale: 14-inch M4 MacBook Pros for up t...
Don’t pay full price! Amazon has Apple’s 14-inch M4 MacBook Pros (Silver and Black colors) on sale for up to $220 off MSRP right now. Shipping is free. Be sure to select Amazon as the seller, rather... Read more
Mac mini with M4 Pro CPU back on sale for $12...
B&H Photo has Apple’s Mac mini with the M4 Pro CPU back on sale for $1259, $140 off MSRP. B&H offers free 1-2 day shipping to most US addresses: – Mac mini M4 Pro CPU (24GB/512GB): $1259, $... Read more

Jobs Board

All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.