Earlier quoted context omitted.
In a world where the US government is scanning all your electronic communications, and (we'll next discover) searching your OS X- and Windows-based computers at will, how do you, as a practical matter, keep your private key "private"?
If you want a realistic chance of not losing control of your private key the only real answers are hardware based - using a tamper resistant smart card, hardware security module, tpm or similar systems in which the signing is done inside the chip that contains your signing keys and no general purpose device ever sees the key at all. Most people using software only solutions won't ever have their keys stolen, but that…
An encrypted message to Edward Snowden
41–50 of 164 posts
Re: An encrypted message to Edward Snowden
#42Earlier quoted context omitted.
Only use your private key with Tinfoil Hat Linux on an offline air-gapped computer: http://tinfoilhat.shmoo.com/ I recommend disconnecting your monitor and only receiving output by having it blinked out at you through your capslock light on your keyboard. Bonus points if you can get your hands on some TEMPEST hardened hardware, and/or tamper-resistant hardware. Anything less will leave you vulnerable to the black hel…
The light reflected off your eyes from the capslock key is readable from high-res cameras. It's better to have leads hooked up to one of your toes and to toggle a 24V source so you can interpret the pulses in morse code. Edit: obviously the 24V must come from a battery which is charged only at specific intervals -- otherwise they can interpret your messages by watching mains voltage variation.
Bonus: Anyone surveilling you via audio bugs will need new ears.
Re: An encrypted message to Edward Snowden
#43Re: An encrypted message to Edward Snowden
#44What's with the posted image? Is that just for illustration, or is there steganography going on too? I couldn't find anything running a couple of programs on it, but then again I don't have the contents of the attached message.
Re: An encrypted message to Edward Snowden
#45Earlier quoted context omitted.
Only use your private key with Tinfoil Hat Linux on an offline air-gapped computer: http://tinfoilhat.shmoo.com/ I recommend disconnecting your monitor and only receiving output by having it blinked out at you through your capslock light on your keyboard. Bonus points if you can get your hands on some TEMPEST hardened hardware, and/or tamper-resistant hardware. Anything less will leave you vulnerable to the black hel…
The light reflected off your eyes from the capslock key is readable from high-res cameras. It's better to have leads hooked up to one of your toes and to toggle a 24V source so you can interpret the pulses in morse code. Edit: obviously the 24V must come from a battery which is charged only at specific intervals -- otherwise they can interpret your messages by watching mains voltage variation.
It's times like these, I'm grateful for limited terms of office, and a politically divided country.
Re: An encrypted message to Edward Snowden
#46Earlier quoted context omitted.
79DEBE35 is a key in the possession of Wired, I'm sure they'll enjoy passing your message on the the NSA via their parent media giant. Edit: Also, it's not very hard to generate a different key with signature 79DEBE35, and put it on the key servers. gpg's displaying of such short abbreviations for keys is one the worst parts of its UI.
>79DEBE35 is a key in the possession of Wired How do you know this?
Re: An encrypted message to Edward Snowden
#47Earlier quoted context omitted.
79DEBE35 is a key in the possession of Wired, I'm sure they'll enjoy passing your message on the the NSA via their parent media giant. Edit: Also, it's not very hard to generate a different key with signature 79DEBE35, and put it on the key servers. gpg's displaying of such short abbreviations for keys is one the worst parts of its UI.
>79DEBE35 is a key in the possession of Wired How do you know this?
EDIT: While what I said was technically true, in that it is encrypted with the 79DEBE35 key, that's not Wired's key, it's the recipient's key.
Re: An encrypted message to Edward Snowden
#48Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.
That's not safe at all, considering the organization tracking him.
Maybe Bitmessage helps receiving messages anonymously, but the timing attack might still be possible when sending messages. I2P can mitigate the problem, but I don't think Bitmessage has any nodes in I2P.
I would say that, if you don't trust Poulsen, don't talk to him.
Re: An encrypted message to Edward Snowden
#49Earlier quoted context omitted.
If you want a realistic chance of not losing control of your private key the only real answers are hardware based - using a tamper resistant smart card, hardware security module, tpm or similar systems in which the signing is done inside the chip that contains your signing keys and no general purpose device ever sees the key at all. Most people using software only solutions won't ever have their keys stolen, but that…
I would be very interested in a a tutorial or guide for getting something like this set up on OS X.
Re: An encrypted message to Edward Snowden
#50Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.
This seemed relevant from Wikipedia ( https://en.wikipedia.org/wiki/Adrian_Lamo#Greenwald.2C_Lamo.... ): Lamo's role in the Manning case drew the ire of Glenn Greenwald, of Salon Magazine. An ardent supporter of WikiLeaks, Greenwald has been a passionate critic of Lamo, suggesting that Lamo lied to Manning by turning him in, and also lied after the fact to cover up the circumstances of Manning's confessions. Greenwal…