Live data from Hacker News

Use of Tor and e-mail crypto could increase chances that NSA keeps your data

arstechnica.com

21–30 of 116 posts

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#21
I think this is the saddest aspect of these spying programs and the ensuing paranoia... it actually might discourage people from using encryption or anonymizing proxies... for fear it will get them on a watch list.

If you start using PGP for all your email, then you by inference "have something to hide". Brilliant logic.

What a mess.

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#22
post #14

The NSA operates a Tor exit node at Georgia Tech, and likely at other research institutes and universities. The fact of the matter is, people who use Tor are the ones trying to hide from the government, and it only makes sense for the NSA to run Tor exit nodes and analyze all traffic passing through them. You probably have more privacy by not using Tor at all.

Can you cite your source regarding the NSA operated Tor exit?

I do not mean this to be snarky -- if you have a legitimate source other than hearsay, I'd love to see it.

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#23
post #13
post #5

If one uses Tor, the article states that the person will not be treated as a United States person unless "proven" otherwise. If that's the case, all the traffic from a Tor exit node will be considered as traffic from non U.S. persons and all data will be stored. Doesn't make sense to me because if you are using Tor right, then requests cannot be traced back to you. How does that help?

It depends on what you mean by "using TOR right" - and that depends on who/where you are and what you're trying to protect yourself against. A Chinese/Egyptian/Turkish dissident might consider it perfectly sensible to use TOR to access their gmail account - that's a perfectly valid way of hiding from your local (non-US) government and spy agencies.

What I mean by using Tor right, for instance, is avoiding use of certain browser plugins that can potentially give away your location.

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#24
"The document, titled Minimization Procedures Used by the National Security Agency in Connection with Acquisitions of Foreign Intelligence, is the latest bombshell leak to be dropped by UK-based newspaper The Guardian."

All good news!

1: The Guardian is still time-releasing, I thought they caved under a IGIC -sorry, what ever its called over there - gag order.

2: Now we know what to do to backup into the NSA cloud! Another USA world benefit: a highly secure service for all the world to avail themselves for free.

3: web app $opportunity$! tor p2p delivery and crypto of your files into free NSA Cloud, for only $0.99!

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#25
post #17

The only long-term way to hide data is not to use public networks for communication. Eventually, quantum computers should be able to eat though any of today's crypto. It will be interesting to see what happens when everyone running for public office has their entire life on display.

> Eventually, quantum computers should be able to eat though any of today's crypto

Probably not. Quoting from http://blog.agilebits.com/2013/03/09/guess-why-were-moving-t...:

A quantum of bits [Update: March 20, 2013]

I reached out to the cryptographic community for any insight into Molly’s question about why the NSA insists that TOP SECRET material be encrypted using 256-bit keys. The answer came from Steven Bellovin of Columbia University:

@jpgoldberg @marshray Just heard that during the AES competition, NSA said in the open meetings it was for defense against quantum computing

Quantum computers, if they are every made practical, will be able to do amazing things. They will certainly change how we design cryptographic systems. It’s not that quantum computers will be faster or more powerful. Indeed, in some very important respects they will be less powerful than current computers. But there are some things that they will be able to do in less “time”. I put “time” in scare quotes because it has a different meaning in this context from the ordinary use of the word. Oh, what a big difference it is. In this context it means the number of distinct steps an algorithm must take in performing some computation.

Searching through 2128 keys (on a classical, non-quantum, computer) takes a number of steps that is proportional to 2128. But for a quantum computer it takes a number of steps proportional to the square root of that number, 264. If a quantum computer is ever built capable of performing that task, we don’t know how the actual speed of each individual step will compare to those of current computers, but the NSA is taking no chances. Something with the effective strength of a 64-bit key isn’t strong enough. A 256-bit key against a quantum brute force attack would have the effective strength of a 128 bit key against a classical brute force attack.

I very much doubt that we will see a quantum computer actually capable of handing such things within the next thirty years. But if the past is any guide, my predictions about the future should be taken with a large grain of salt.

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#28
post #7

This is fairly obvious. From the NSA's perspective, people that act like people who have something to hide are more likely to be hiding something. I'd be surprised if they didn't take it into account.

I have plenty to hide. Like... my server passwords!

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#29
post #9

Since I (and the majority of global internet users) are not "US persons", they're claiming they're entitled to intercept and store all my communications anyway - so my personal reaction to this is going to be to increase the use of tor and crypto for random everyday stuff. I'll start GPG encrypting email to anybody I know will be able ro deal with it. I might even start randomly mailing GPG encrypted mail for no reas…

"I will start GPG encrypting email to anybody I know who will be able to deal with it"

As sad as it is to say, lets be honest and admit that this is a fairly small number. How long do you think it will be till your less committed friends get tired of decrypting your emails and just ignore what you send? Make sure you only pick people that use actual email clients because gpg and Gmail is no fun.

As far as the "Thomas Crowne Affair attack" goes generating effective cover traffic is not easy and random traffic is definitely a bad idea. Basic traffic analysis would be able to separate your legit emails from your cover traffic.

Addendum: I noticed you just generated your new gpg key yesterday. Why not go big and use a 4096 bit key?

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#30
post #15

If you want to read the documents without having to use that awful viewer or load js from every social networking site known to man: (increment the p# from 1-9) Procedures used by NSA to target non-US persons: Exhibit A: https://s3.amazonaws.com/s3.documentcloud.org/documents/7166... Procedures used by NSA to minimize data collection from US persons: Exhibit B: https://s3.amazonaws.com/s3.documentcloud.org/documents/…

[deleted]
Post reply on HN