Adam W. wrote:
So maybe it would
be a good idea to abandon the NNTP-Posting-Host and restrict
Injection-Info to username?
Yes. Most (all?) larger non-commercial servers here in Germany (news.individual.net, news.eternal-september.org) drop or encrypt not only posting-host, but also posting-account. That makes all posts pseudonymous,
but but still enables abuse management, even if relevant log files have
already expired.
What do you think? Are there servers out there that refuse posts from anonymizing servers, even if these servers require registration (and
there's manual verification of accounts)?
I don't think so, and if there are, they already miss quite a lot of
Usenet traffic (as both news.individual.net and news.eternal-september.org
have many international users).
Are there any drawbacks of abandoning NNTP-Posting-Host?
As long as you can reliable connect a posting to an account, no.
- encrypt it with some key and provide the encrypted part in headers (so
I'm able to decrypt it even if I lose the logs)
Yes, that seems to be the usual way it's done:
| Injection-Info: dont-email.me; posting-host="e6f4fdaeb1993510e7a7ff2ec7e2da2c";
| logging-data="1575502"; mail-complaints-to="
[email protected]";
| posting-account="U2FsdGVkX18Y8QLNhoe7CQWt2YZRnhF9"
| Injection-Info: paganini.bofh.team; logging-data="66671"; posting-host="Q3L9UIlFyMxrk9jCqyDbug.user.paganini.bofh.team"; mail-complaints-to="
[email protected]"; posting-account="9dIQLXBM7WM9KzA+yjdR4A";
news.individual.net already had a custom system in place, but also uses encryption:
| X-Trace: individual.net UMDzOdHeM50jCB6O774fvAe8JeOpQ4XDKv9MsG9WuZG50iIBud
-thh
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)