Live data from Hacker News

An encrypted message to Edward Snowden

wired.com

21–30 of 164 posts

Re: An encrypted message to Edward Snowden

#21
post #11

I don't get it, unless Snowden's published his public key somewhere and Wired has some really, really important information for him?

The reason you would advertise a page like this is to get lots of people to visit it. It gives Snowden the ability to look like any of the other (tens?) of thousands of people who visit the URL in the next little while.

Thanks for the comment. I saw this story’s presence on HN as a complete waste of space until now.

Re: An encrypted message to Edward Snowden

#22
If Edward Snowden does have a pgp key (I can't find one online), it hasn't been revealed in this message. It looks like the signing and encryption keys are the same:

  gpg: armor: BEGIN PGP MESSAGE
  gpg: armor header: Version: GnuPG/MacGPG2 v2.0.19 (Darwin)
  gpg: armor header: Comment: GPGTools - http://gpgtools.org
  :pubkey enc packet: version 3, algo 1, keyid 5B50940B79DEBE35
          data: [4096 bits]
  gpg: public key is 79DEBE35
  :encrypted data packet:
          length: unknown
          mdc_method: 2
  gpg: encrypted with RSA key, ID 79DEBE35
  gpg: decryption failed: secret key not available
Of course, they could have used --hidden-encrypt-to, but I think it's more likely a publicity stunt.

Oh, and if you do find a key claiming to be for Edward Snowden online, verify that it's actually him, ideally through the web of trust, and that it isn't just a key that was created after the news was leaked. I'd be wary of any keys on keyservers claiming to be him that have been uploaded after he went public with this.

Re: An encrypted message to Edward Snowden

#23
post #2

From http://www.gnupg.org/gph/en/manual/x110.html "A public and private key each have a specific role when encrypting and decrypting documents. A public key may be thought of as an open safe. When a correspondent encrypts a document using a public key, that document is put in the safe, the safe shut, and the combination lock spun several times. The corresponding private key is the combination that can reopen the safe…

In a world where the US government is scanning all your electronic communications, and (we'll next discover) searching your OS X- and Windows-based computers at will, how do you, as a practical matter, keep your private key "private"?

Only use your private key with Tinfoil Hat Linux on an offline air-gapped computer: http://tinfoilhat.shmoo.com/

I recommend disconnecting your monitor and only receiving output by having it blinked out at you through your capslock light on your keyboard. Bonus points if you can get your hands on some TEMPEST hardened hardware, and/or tamper-resistant hardware.

Anything less will leave you vulnerable to the black helicopters!

Note: I'm joking obviously, but this is something to take seriously.

Re: An encrypted message to Edward Snowden

#24
post #7

Earlier quoted context omitted.

More likely that it's a publicity stunt, raising awareness of strong encryption that the NSA (probably) can't crack yet.

yeah, I was wondering about how strong GPG was. Back in the day, i.e. the 90's, the assumption was it would take years for then-current NSA supercomputers to factor the keys. Nowadays, with all sorts of new attacks, analyses, and cheap as hell compute time, I would wager that time requirement has gone significantly down.

I remember 768 bit asymetric keys in the mid 90's, and the paranoid had perhaps a 1024 bit key (I'm not very paranoid, and I got a 2048 bit key before 2000). A 768 bit RSA key was factored in 2009; the NSA could probably do it earlier. The default now is 2048 bits, and the key used by Wired is 4096 bits.

That's a lot of doublings of the difficulty to brute force a key. 2^3328 increase in difficulty.

Re: An encrypted message to Edward Snowden

#25
post #20

Earlier quoted context omitted.

More likely that it's a publicity stunt, raising awareness of strong encryption that the NSA (probably) can't crack yet.

Snowden called himself Verax[1]. Anyone who wants to send a message to Snowden* can just: $ gpg --keyserver pgp.mit.edu --recv-keys 79DEBE35 $ gpg --encrypt --sign --armor --recipient 79DEBE35 and post it publicly; perhaps on Pastebin. [1]: http://www.washingtonpost.com/world/national-security/code-n... *assuming you believe the key is authentic

79DEBE35 is a key in the possession of Wired, I'm sure they'll enjoy passing your message on the the NSA via their parent media giant.

Edit: Also, it's not very hard to generate a different key with signature 79DEBE35, and put it on the key servers. gpg's displaying of such short abbreviations for keys is one the worst parts of its UI.

Re: An encrypted message to Edward Snowden

#26
post #22

If Edward Snowden does have a pgp key (I can't find one online), it hasn't been revealed in this message. It looks like the signing and encryption keys are the same: gpg: armor: BEGIN PGP MESSAGE gpg: armor header: Version: GnuPG/MacGPG2 v2.0.19 (Darwin) gpg: armor header: Comment: GPGTools - http://gpgtools.org :pubkey enc packet: version 3, algo 1, keyid 5B50940B79DEBE35 data: [4096 bits] gpg: public key is 79DEBE3…

There's no way to tell when a key was uploaded to a keyserver without the keyserver's logs.

Re: An encrypted message to Edward Snowden

#27
post #22

If Edward Snowden does have a pgp key (I can't find one online), it hasn't been revealed in this message. It looks like the signing and encryption keys are the same: gpg: armor: BEGIN PGP MESSAGE gpg: armor header: Version: GnuPG/MacGPG2 v2.0.19 (Darwin) gpg: armor header: Comment: GPGTools - http://gpgtools.org :pubkey enc packet: version 3, algo 1, keyid 5B50940B79DEBE35 data: [4096 bits] gpg: public key is 79DEBE3…

[deleted]

Re: An encrypted message to Edward Snowden

#28
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

That's not safe at all, considering the organization tracking him.

Re: An encrypted message to Edward Snowden

#29
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

This seemed relevant from Wikipedia (https://en.wikipedia.org/wiki/Adrian_Lamo#Greenwald.2C_Lamo....):

Lamo's role in the Manning case drew the ire of Glenn Greenwald, of Salon Magazine. An ardent supporter of WikiLeaks, Greenwald has been a passionate critic of Lamo, suggesting that Lamo lied to Manning by turning him in, and also lied after the fact to cover up the circumstances of Manning's confessions. Greenwald places the incident in the context of what he calls "the Obama administration's unprecedented war on whistle-blowers". Greenwald's critique of Wired Magazine has drawn a response from that magazine which suggests that Greenwald is writing disingenuously: "At his most reasonable, Greenwald impugns our motives, attacks the character of our staff and carefully selects his facts and sources to misrepresent the truth and generate outrage in his readership." In an article about the Bradley Manning case, Greenwald mentions Wired reporter Kevin Poulsen's 1994 felony conviction for computer hacking, suggesting that "over the years, Poulsen has served more or less as Lamo's personal media voice."

Greenwald is skeptical of an earlier story written by Poulsen about Lamo's institutionalization on psychiatric grounds, writing: "Lamo claimed he was diagnosed with Asperger's Syndrome, a somewhat fashionable autism diagnosis which many stars in the computer world have also claimed." In his response, Poulsen accused Greenwald of "name-calling, bizarre conspiracy theories and ad hominem attacks".

Re: An encrypted message to Edward Snowden

#30
post #24
post #7

Earlier quoted context omitted.

yeah, I was wondering about how strong GPG was. Back in the day, i.e. the 90's, the assumption was it would take years for then-current NSA supercomputers to factor the keys. Nowadays, with all sorts of new attacks, analyses, and cheap as hell compute time, I would wager that time requirement has gone significantly down.

I remember 768 bit asymetric keys in the mid 90's, and the paranoid had perhaps a 1024 bit key (I'm not very paranoid, and I got a 2048 bit key before 2000). A 768 bit RSA key was factored in 2009; the NSA could probably do it earlier. The default now is 2048 bits, and the key used by Wired is 4096 bits. That's a lot of doublings of the difficulty to brute force a key. 2^3328 increase in difficulty.

RSA factoring does not increase with keysize increases like you might expect. Factoring, while still very hard, is much better than brute-force and continues to see improvements.
Post reply on HN