FINDING · DEFENSE

Publius's delete mechanism requires the publisher to supply H(server_domain · PW) per server rather than a bare password, preventing any single malicious server from learning the global password and deleting the document from all hosting servers. However, the paper acknowledges that an adversary who identifies the publisher can apply coercive ('rubber-hose') methods to obtain the URL and password directly from the author, bypassing all cryptographic protections.

From 2000-waldman-publiusPublius: A robust, tamper-evident, censorship-resistant web publishing system · §3.4, §5.5 · 2000 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
ip-blocking
defenses
meta-resistance

Extracted by claude-sonnet-4-6 — review before relying.