Live data from Hacker News

An encrypted message to Edward Snowden

wired.com

81–90 of 164 posts

Re: An encrypted message to Edward Snowden

#81
post #18

Earlier quoted context omitted.

In a world where the US government is scanning all your electronic communications, and (we'll next discover) searching your OS X- and Windows-based computers at will, how do you, as a practical matter, keep your private key "private"?

If you want a realistic chance of not losing control of your private key the only real answers are hardware based - using a tamper resistant smart card, hardware security module, tpm or similar systems in which the signing is done inside the chip that contains your signing keys and no general purpose device ever sees the key at all. Most people using software only solutions won't ever have their keys stolen, but that…

[deleted]

Re: An encrypted message to Edward Snowden

#82
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

This seemed relevant from Wikipedia ( https://en.wikipedia.org/wiki/Adrian_Lamo#Greenwald.2C_Lamo.... ): Lamo's role in the Manning case drew the ire of Glenn Greenwald, of Salon Magazine. An ardent supporter of WikiLeaks, Greenwald has been a passionate critic of Lamo, suggesting that Lamo lied to Manning by turning him in, and also lied after the fact to cover up the circumstances of Manning's confessions. Greenwal…

> Greenwald has been a passionate critic of Lamo, suggesting that Lamo lied to Manning by turning him in, and also lied after the fact to cover up the circumstances of Manning's confessions.

Not sure about the second part, but the fact that Lamo lied to Manning isn't controversial. He's talked about it in a few interviews.

This one was a little odd: http://www.guardian.co.uk/world/2013/jan/03/adrian-lamo-brad...

Re: An encrypted message to Edward Snowden

#83
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

This is Kevin Poulsen. Just popping in to correct this. Adrian Lamo turned in Bradley Manning. All I did (being a reporter) is break the news.

http://www.wired.com/threatlevel/2010/06/leak/ http://www.wired.com/threatlevel/2010/06/conscience/

Re: An encrypted message to Edward Snowden

#84
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

I think he will keep things to sporadic in-person interviews and frequent changes of where he stays. But I don't think he will stay hidden. I bet as soon as an indictment is handed down, he will turn himself in to the Hong Kong authorities and start fighting extradition.

Re: An encrypted message to Edward Snowden

#85
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

This is Kevin Poulsen. Just popping in to correct this. Adrian Lamo turned in Bradley Manning. All I did (being a reporter) is break the news. http://www.wired.com/threatlevel/2010/06/leak/ http://www.wired.com/threatlevel/2010/06/conscience/

My guess is more people liked you when you were just a hacker that almost got in Bradley Manning's shoes.

Re: An encrypted message to Edward Snowden

#86
post #52
post #40

Earlier quoted context omitted.

Not safe at all. Timing analysis can detect correlations between data arriving at the interviewers computer with data sent by the suspect's computer. Encryption is good at keeping the contents secret, but not the source of traffic.

I2P has protection against timing attacks. Bitmessage has deniability, but if the receiver end is compromised or untrustworthy, then the deniability is gone, and the timing attack might be possible. Combining Bitmessage and I2P would be solution, I think, but I don't know of any Bitmessage nodes on I2P.

Not really. From the I2P FAQ: Without protocol scrubbing or higher latency, global active adversaries can gain substantial information. As such, people concerned with these attacks could increase the latency (using nontrivial delays or batching strategies), include protocol scrubbing, or other advanced tunnel routing techniques, but these are unimplemented in I2P

Bitmessage is only plausibly deniable, meaning a traffic analysis is likely to narrow down the list of senders to a few, which is good enough in a manhunt.

Re: An encrypted message to Edward Snowden

#87
post #19
post #11

Earlier quoted context omitted.

The reason you would advertise a page like this is to get lots of people to visit it. It gives Snowden the ability to look like any of the other (tens?) of thousands of people who visit the URL in the next little while.

The Snowden could use Tor to access the website. Also, there's no other way to get the message to Snowden unless you give it publicity. If he browses the Internet for news, he will find there's a message from Wired for him.

If you were hiding from the NSA.... I'd avoid browsing the internet for a while...

Re: An encrypted message to Edward Snowden

#88

Earlier quoted context omitted.

>79DEBE35 is a key in the possession of Wired How do you know this?

It was the signing key on Wired's broadcast.

So? You can download my public key and encrypt something with it... and only I'll be able to read it with my private key.

It's still "my" key even though you're signing or rather encrypting a message with it.

Re: An encrypted message to Edward Snowden

#89

Earlier quoted context omitted.

It was the signing key on Wired's broadcast.

So? You can download my public key and encrypt something with it... and only I'll be able to read it with my private key. It's still "my" key even though you're signing or rather encrypting a message with it.

I believe some people, myself included initially, misinterpreted the "encrypted with" key as being the sender's key rather than the recipient's.

We don't know who that key belongs to for sure, of course, but it could be Snowden's.

Post reply on HN