Live data from Hacker News

SecureDrop

ssl.washingtonpost.com

91–99 of 99 posts

Re: SecureDrop

#91
post #89
post #71

Earlier quoted context omitted.

A Tor user at Harvard was successfully tracked when he sent a bomb threat, since he was the only user on the Harvard LAN using Tor at the time the threat was issued. That wasn't proof , of course, but it didn't need to be proof, just a good lead for law enforcement to kick-start their investigation.

My analysis of that incident: http://grugq.github.io/blog/2013/12/21/in-search-of-opsec-ma...

Enjoyed, thanks. Particularly liked "Let's call it half a win."

Re: SecureDrop

#92
post #18

Earlier quoted context omitted.

Fortunately, they can't do that for all the open/WEP/WPS wireless APs everywhere.

They've done a pretty good job of scaring people into securing their APs (which is also a legitimate thing in most cases); just publishing some stories about people having ISP service cut off due to freeloaders doing bad stuff would probably be enough; wouldn't even need to try to prosecute some.

A short walk with Wigle shows literally dozens with WPS on, and usually 4-5 with WEP, plus a couple of open ones that aren't paid. WPS is a massive gaping vulnerability as long as you can stay nearby for a few hours, while WEP gives the illusion of security to clueless people but is worthless (yay RC4... worst algorithm ever.).

Re: SecureDrop

#93

If the leaker visits this page before opening the Tor Browser from a regular browser to copy the onion url, the whole thing is as safe as SSL as there will be a trail of the SSL connection just before the visit to SecureDrop. And they don't even explain to avoid it. OPSEC is hard.

Please correct me if I'm wrong but, right now, at home, I visited that site. Hardly suspicious at all, since it's on HN front page. I could write down the .onion url on a piece of paper (or just print the page, as reference) and then later follow the instructions posted there, at a semi-anonymous Internet cafe, without having to visit that page, right?

Re: SecureDrop

#94

If the leaker visits this page before opening the Tor Browser from a regular browser to copy the onion url, the whole thing is as safe as SSL as there will be a trail of the SSL connection just before the visit to SecureDrop. And they don't even explain to avoid it. OPSEC is hard.

Please correct me if I'm wrong but, right now, at home, I visited that site. Hardly suspicious at all, since it's on HN front page. I could write down the .onion url on a piece of paper (or just print the page, as reference) and then later follow the instructions posted there, at a semi-anonymous Internet cafe, without having to visit that page, right?

I accidentally clicked the down arrow for your comment. Up-voted another to (somewhat) make up for this. Sorry.

Re: SecureDrop

#95
post #5
post #4

In case you don't have Tor installed and want to know what it looks like: https://imgur.com/GbwKfuG,D2aWi25,glApNg3

Very refreshing to see a big, red warning in the screenshot about the fact that Javascript is enabled ! Usually you see the same thing when Javascript is disabled, asking you to enable it.

In August 2013, the FBI injected a Javascript exploit with a MITM attack to uncloak the real IP addresses of people accessing Silk Road over Tor: http://arstechnica.com/security/2013/08/attackers-wield-fire...

[edit] Nerdier link with exploit demo: http://resources.infosecinstitute.com/fbi-tor-exploit/

Re: SecureDrop

#96
If all Post correspondents used SecureDrop to submit their stories that would be a start.

One would have to assume that all the traffic going to the server is logged by the NSA and anyone else who can manage it. If the traffic volume is low then timing correlation with even a large pool of suspects is simple. An active attacker can differentiate between the SSL connection from a web browser and one from a tor node, so the background SSL traffic to the Post would not provide cover.

I think it could be improved by using a mix network (eg mixminion) accessed over tor, rather than just tor.

Unfortunately the mixmaster/mixminion networks are currently too small to provide meaningful complexity. Large scale adoption by, eg, newspapers, is not technically hard and would significantly complicate the adversary problem.

I'd love to see more discussion of bitmessage and Pond (https://pond.imperialviolet.org/)

cf http://www.syverson.org/

Re: SecureDrop

#97
post #27

Earlier quoted context omitted.

I think the technology confuses two things: 1. Encrypted traffic between device and wireless hotspot 2. Restricted access to the wireless hotspot (you need a password or it won't give you service) I want to allow anonymous access, but let the traffic be encrypted. Is there a technical reason why this is not implemented? I'm very sad by the culture (and moreso, the legal necessity) of restricting wireless access. I wa…

You can run an access point with all the benefits of WPA2/AES, but make the password really simple. Setting your SSID to "PasswordIsBacon" or just using the same SSID and password is a fairly easy way to share access, without running a completely insecure, unencrypted network.

That's "easy to share" which is a much greater hurdle than "publicly accessible". I want strangers to be able to use my wifi in the middle of the night from outside my home. I want devices to connect without any questions or hassle.

Re: SecureDrop

#98
post #42
post #14

The Guardian has also released a secure drop platform: http://www.theguardian.com/technology/2014/jun/05/guardian-l... https://securedrop.theguardian.com/

This is a different deployment of the same product [1]. Which, incidentally, was originally created by Aaron Swartz. The Wikipedia page[2] has a list of well-known deployments. [1] https://pressfreedomfoundation.org/securedrop [2] http://en.wikipedia.org/wiki/SecureDrop

Thanks for posting the links, I am guessing the deployment list will grow.

Re: SecureDrop

#99
post #45
post #42

Earlier quoted context omitted.

This is a different deployment of the same product [1]. Which, incidentally, was originally created by Aaron Swartz. The Wikipedia page[2] has a list of well-known deployments. [1] https://pressfreedomfoundation.org/securedrop [2] http://en.wikipedia.org/wiki/SecureDrop

Thanks for pointing that out. I just watched "The Internet's Own Boy", the documentary about Aaron, and it is positively incredibly how many projects Aaron created or played a critical role in creating. An unthinkable shame that he left us so soon — one can only imagine all the things he had left to create.

[deleted]
Post reply on HN