Live data from Hacker News

An encrypted message to Edward Snowden

wired.com

41–50 of 164 posts

Re: An encrypted message to Edward Snowden

#41
post #18

Earlier quoted context omitted.

In a world where the US government is scanning all your electronic communications, and (we'll next discover) searching your OS X- and Windows-based computers at will, how do you, as a practical matter, keep your private key "private"?

If you want a realistic chance of not losing control of your private key the only real answers are hardware based - using a tamper resistant smart card, hardware security module, tpm or similar systems in which the signing is done inside the chip that contains your signing keys and no general purpose device ever sees the key at all. Most people using software only solutions won't ever have their keys stolen, but that…

I would be very interested in a a tutorial or guide for getting something like this set up on OS X.

Re: An encrypted message to Edward Snowden

#42
post #23

Earlier quoted context omitted.

Only use your private key with Tinfoil Hat Linux on an offline air-gapped computer: http://tinfoilhat.shmoo.com/ I recommend disconnecting your monitor and only receiving output by having it blinked out at you through your capslock light on your keyboard. Bonus points if you can get your hands on some TEMPEST hardened hardware, and/or tamper-resistant hardware. Anything less will leave you vulnerable to the black hel…

The light reflected off your eyes from the capslock key is readable from high-res cameras. It's better to have leads hooked up to one of your toes and to toggle a 24V source so you can interpret the pulses in morse code. Edit: obviously the 24V must come from a battery which is charged only at specific intervals -- otherwise they can interpret your messages by watching mains voltage variation.

Those leads are gonna generate magnetic distortions. You should only do this with your feet next to a giant 18" subwoofer while blasting dubstep in order to mask any electromagnetic fluctuations.

Bonus: Anyone surveilling you via audio bugs will need new ears.

Re: An encrypted message to Edward Snowden

#44

What's with the posted image? Is that just for illustration, or is there steganography going on too? I couldn't find anything running a couple of programs on it, but then again I don't have the contents of the attached message.

It's a picture of the NSA headquarters at Ft. Meade. That may be all there is to it.

Re: An encrypted message to Edward Snowden

#45
post #23

Earlier quoted context omitted.

Only use your private key with Tinfoil Hat Linux on an offline air-gapped computer: http://tinfoilhat.shmoo.com/ I recommend disconnecting your monitor and only receiving output by having it blinked out at you through your capslock light on your keyboard. Bonus points if you can get your hands on some TEMPEST hardened hardware, and/or tamper-resistant hardware. Anything less will leave you vulnerable to the black hel…

The light reflected off your eyes from the capslock key is readable from high-res cameras. It's better to have leads hooked up to one of your toes and to toggle a 24V source so you can interpret the pulses in morse code. Edit: obviously the 24V must come from a battery which is charged only at specific intervals -- otherwise they can interpret your messages by watching mains voltage variation.

obviously!

It's times like these, I'm grateful for limited terms of office, and a politically divided country.

Re: An encrypted message to Edward Snowden

#46
post #25

Earlier quoted context omitted.

79DEBE35 is a key in the possession of Wired, I'm sure they'll enjoy passing your message on the the NSA via their parent media giant. Edit: Also, it's not very hard to generate a different key with signature 79DEBE35, and put it on the key servers. gpg's displaying of such short abbreviations for keys is one the worst parts of its UI.

>79DEBE35 is a key in the possession of Wired How do you know this?

It was the signing key on Wired's broadcast.

Re: An encrypted message to Edward Snowden

#47
post #25

Earlier quoted context omitted.

79DEBE35 is a key in the possession of Wired, I'm sure they'll enjoy passing your message on the the NSA via their parent media giant. Edit: Also, it's not very hard to generate a different key with signature 79DEBE35, and put it on the key servers. gpg's displaying of such short abbreviations for keys is one the worst parts of its UI.

>79DEBE35 is a key in the possession of Wired How do you know this?

The message posted on Wired is encrypted with that key.

EDIT: While what I said was technically true, in that it is encrypted with the 79DEBE35 key, that's not Wired's key, it's the recipient's key.

Re: An encrypted message to Edward Snowden

#48
post #28
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

That's not safe at all, considering the organization tracking him.

When using Bitmessage, everybody receives all the messages in the blockchain. How is the timing attack going to identify him?

Maybe Bitmessage helps receiving messages anonymously, but the timing attack might still be possible when sending messages. I2P can mitigate the problem, but I don't think Bitmessage has any nodes in I2P.

I would say that, if you don't trust Poulsen, don't talk to him.

Re: An encrypted message to Edward Snowden

#49
post #41
post #18

Earlier quoted context omitted.

If you want a realistic chance of not losing control of your private key the only real answers are hardware based - using a tamper resistant smart card, hardware security module, tpm or similar systems in which the signing is done inside the chip that contains your signing keys and no general purpose device ever sees the key at all. Most people using software only solutions won't ever have their keys stolen, but that…

I would be very interested in a a tutorial or guide for getting something like this set up on OS X.

OS X has smart card support for FileVault 1 but not FileVault 2. It only includes enough drivers to support US DoD CAC cards, and other NATO countries that have standardized on our stuff.

Re: An encrypted message to Edward Snowden

#50
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

This seemed relevant from Wikipedia ( https://en.wikipedia.org/wiki/Adrian_Lamo#Greenwald.2C_Lamo.... ): Lamo's role in the Manning case drew the ire of Glenn Greenwald, of Salon Magazine. An ardent supporter of WikiLeaks, Greenwald has been a passionate critic of Lamo, suggesting that Lamo lied to Manning by turning him in, and also lied after the fact to cover up the circumstances of Manning's confessions. Greenwal…

Count me among those suspicious of Lamo and Poulsen. I don't care for them.
Post reply on HN