Live data from Hacker News

COMSEC: Beyond Encryption [pdf]

grugq.github.io

21–30 of 54 posts

Re: COMSEC: Beyond Encryption [pdf]

#21
I have been trained well by now. Every time I see stuff like "try Pond" or click and use this tool. I am thinking -- I will be bumped up on the black list somewhere. I guess it is called thought self-censorship...

Re: COMSEC: Beyond Encryption [pdf]

#22
This is great. Explicitly calling out Communication Events helps to remind us that everything we do is leaking information.

Also like the mention of cover. Every action you do should have some explanation. Why were you here? Why were you doing that? Why were you taking to them? How will these questions be posed and answered to random LEOs, lawyers, judges, etc.?

People seem to focus on some flashy part, like using Tor, but forget overall basics.

Like that kid nailed for making bomb threats. He had no cover story for why he was on Tor. He didn't shut up, and cracked. All be had to do was get embarrassed and say he was looking for porn, or looking at drug prices, and he'd have been fine.

Edit: It might be good for the cover to be slightly illegal, or damaging. Investigator grills someone, finally gets them to confess, and it's cause they were buying weed, or having an affair with illegal prostitues or hiding something from their family. Then the all the covert actions and software and nervousness make sense. (And the investigator will move on cause a simple possession charge isn't worth their time.) Just make sure the story checks out.

Re: COMSEC: Beyond Encryption [pdf]

#23

This is great. Explicitly calling out Communication Events helps to remind us that everything we do is leaking information. Also like the mention of cover. Every action you do should have some explanation. Why were you here? Why were you doing that? Why were you taking to them? How will these questions be posed and answered to random LEOs, lawyers, judges, etc.? People seem to focus on some flashy part, like using To…

The police/interrogators want you to lie to them with a cover story so your alibi can be picked a part easily, correct response is to say nothing and get a lawyer. Even worse is admitting something illegal to them thinking they will just let it slide, more likely they will use your confession as cause to search your property.

Re: COMSEC: Beyond Encryption [pdf]

#24
post #19
post #3

Also relevant, and by the same author: http://www.slideshare.net/grugq/opsec-for-hackers

I don't get why he says "VPN connection to TOR => GOTOJAIL". How is it OK that your ISP sees you connecting to Tor, but dangerous if your VPN provider does? Or is this about some other issue?

The NSA sees all. Using both a VPN and Tor is more suspicious than just using Tor.

Re: COMSEC: Beyond Encryption [pdf]

#25

This is great. Explicitly calling out Communication Events helps to remind us that everything we do is leaking information. Also like the mention of cover. Every action you do should have some explanation. Why were you here? Why were you doing that? Why were you taking to them? How will these questions be posed and answered to random LEOs, lawyers, judges, etc.? People seem to focus on some flashy part, like using To…

The police/interrogators want you to lie to them with a cover story so your alibi can be picked a part easily, correct response is to say nothing and get a lawyer. Even worse is admitting something illegal to them thinking they will just let it slide, more likely they will use your confession as cause to search your property.

Yes if you can avoid saying anything, fine. In the case of the bomb threat kid, there is no way to verify an alibi of "I was looking for drugs using Tor". And, a nervous seeming kid finally admitting he was looking for drugs fits pretty well and may have gotten the investigators to move on. They've limited time and resources.

At other places, like border crossings, you might not have the ability to refuse to say anything (especially as a non citizen). Being able to have a good cover may be the difference in being let go after a cursory look versus being detained for in depth examination.

And I really cannot imagine counter terrorism agents bothering to actually go forward charging that kid with attempting to buy pot or something. After all, if they suspect him off terrorism, that alone should be enough to get a search warrant and take his computers.

Re: COMSEC: Beyond Encryption [pdf]

#26
post #21

I have been trained well by now. Every time I see stuff like "try Pond" or click and use this tool. I am thinking -- I will be bumped up on the black list somewhere. I guess it is called thought self-censorship...

"chilling effect" is probably the term you're looking for, though maybe it's not an exact match.

Re: COMSEC: Beyond Encryption [pdf]

#27
post #7

Earlier quoted context omitted.

The ad-lib appears to be included in the provided PDF.

And is pretty much a statement of fact. "Sticking out like a white guy in a Mayan village" would probably have been non notable so I don't follow how it's offensive by switching the subjects.

Mentioning in minorities in contexts that aren't explicitly positive is pretty much a holocaust-tier offense.

Re: COMSEC: Beyond Encryption [pdf]

#28
post #21

I have been trained well by now. Every time I see stuff like "try Pond" or click and use this tool. I am thinking -- I will be bumped up on the black list somewhere. I guess it is called thought self-censorship...

Know what you mean. I know grugq to some extent, and really doubt this was his motivation. However, yes .. passive global network analysis (eg. NSA) can benefit. So I still have the same thought process, and switch signatures (browser+IP) before reading things like this. Just for compartmentalization...

Re: COMSEC: Beyond Encryption [pdf]

#29
Page 36: "Windows is currently the most secure mainstream OS. I mean, we can’t stand _using_ it, but that doesn’t change the facts. The kernel is golden, the userland protections are stellar, and the user experience is somewhere between the 8th and 9th circle of Hell."

Re: COMSEC: Beyond Encryption [pdf]

#30
post #19
post #3

Also relevant, and by the same author: http://www.slideshare.net/grugq/opsec-for-hackers

I don't get why he says "VPN connection to TOR => GOTOJAIL". How is it OK that your ISP sees you connecting to Tor, but dangerous if your VPN provider does? Or is this about some other issue?

Yes, hard to understand why he says that, maybe he meant TOR connection to VPN?
Post reply on HN