COMSEC: Beyond Encryption [pdf]
21–30 of 54 posts
Re: COMSEC: Beyond Encryption [pdf]
#22Also like the mention of cover. Every action you do should have some explanation. Why were you here? Why were you doing that? Why were you taking to them? How will these questions be posed and answered to random LEOs, lawyers, judges, etc.?
People seem to focus on some flashy part, like using Tor, but forget overall basics.
Like that kid nailed for making bomb threats. He had no cover story for why he was on Tor. He didn't shut up, and cracked. All be had to do was get embarrassed and say he was looking for porn, or looking at drug prices, and he'd have been fine.
Edit: It might be good for the cover to be slightly illegal, or damaging. Investigator grills someone, finally gets them to confess, and it's cause they were buying weed, or having an affair with illegal prostitues or hiding something from their family. Then the all the covert actions and software and nervousness make sense. (And the investigator will move on cause a simple possession charge isn't worth their time.) Just make sure the story checks out.
Re: COMSEC: Beyond Encryption [pdf]
#23This is great. Explicitly calling out Communication Events helps to remind us that everything we do is leaking information. Also like the mention of cover. Every action you do should have some explanation. Why were you here? Why were you doing that? Why were you taking to them? How will these questions be posed and answered to random LEOs, lawyers, judges, etc.? People seem to focus on some flashy part, like using To…
Re: COMSEC: Beyond Encryption [pdf]
#24Also relevant, and by the same author: http://www.slideshare.net/grugq/opsec-for-hackers
I don't get why he says "VPN connection to TOR => GOTOJAIL". How is it OK that your ISP sees you connecting to Tor, but dangerous if your VPN provider does? Or is this about some other issue?
Re: COMSEC: Beyond Encryption [pdf]
#25This is great. Explicitly calling out Communication Events helps to remind us that everything we do is leaking information. Also like the mention of cover. Every action you do should have some explanation. Why were you here? Why were you doing that? Why were you taking to them? How will these questions be posed and answered to random LEOs, lawyers, judges, etc.? People seem to focus on some flashy part, like using To…
The police/interrogators want you to lie to them with a cover story so your alibi can be picked a part easily, correct response is to say nothing and get a lawyer. Even worse is admitting something illegal to them thinking they will just let it slide, more likely they will use your confession as cause to search your property.
At other places, like border crossings, you might not have the ability to refuse to say anything (especially as a non citizen). Being able to have a good cover may be the difference in being let go after a cursory look versus being detained for in depth examination.
And I really cannot imagine counter terrorism agents bothering to actually go forward charging that kid with attempting to buy pot or something. After all, if they suspect him off terrorism, that alone should be enough to get a search warrant and take his computers.
Re: COMSEC: Beyond Encryption [pdf]
#26I have been trained well by now. Every time I see stuff like "try Pond" or click and use this tool. I am thinking -- I will be bumped up on the black list somewhere. I guess it is called thought self-censorship...
Re: COMSEC: Beyond Encryption [pdf]
#27Earlier quoted context omitted.
The ad-lib appears to be included in the provided PDF.
And is pretty much a statement of fact. "Sticking out like a white guy in a Mayan village" would probably have been non notable so I don't follow how it's offensive by switching the subjects.
Re: COMSEC: Beyond Encryption [pdf]
#28I have been trained well by now. Every time I see stuff like "try Pond" or click and use this tool. I am thinking -- I will be bumped up on the black list somewhere. I guess it is called thought self-censorship...
Re: COMSEC: Beyond Encryption [pdf]
#29Re: COMSEC: Beyond Encryption [pdf]
#30Also relevant, and by the same author: http://www.slideshare.net/grugq/opsec-for-hackers
I don't get why he says "VPN connection to TOR => GOTOJAIL". How is it OK that your ISP sees you connecting to Tor, but dangerous if your VPN provider does? Or is this about some other issue?