Live data from Hacker News

Encrypt your Google chats and make the NSA sad

github.com

11–20 of 195 posts

Re: Encrypt your Google chats and make the NSA sad

#11
post #2

As far as I can tell, this is using CBC mode without any authentication: https://raw.github.com/mdp/gibberish-aes/master/dist/gibberi... If that's the case, then this implementation is vulnerable to a variety of attacks.

Thanks, can you suggest me a better AES implementation ?

Re: Encrypt your Google chats and make the NSA sad

#12

This would definitely be the level of security that falls under this statement from Snowden: Q: Is it possible to put security in place to protect against state surveillance? A: "You are not even aware of what is possible. The extent of their capabilities is horrifying. We can plant bugs in machines. Once you go on the network, I can identify your machine. You will never be safe whatever protections you put in place.…

Why did he not give even a small technical overview on what they are capable of? He should've been able to given he has a lot of technical expertise and it would've helped his evidence a lot.

Did they figure out how to tap complicated SSL? Is it hardware based? He gave no hints but could have easily.

Instead it's this blanket statement that's supposed to imply that all encryption is pointless.

Re: Encrypt your Google chats and make the NSA sad

#13

This would definitely be the level of security that falls under this statement from Snowden: Q: Is it possible to put security in place to protect against state surveillance? A: "You are not even aware of what is possible. The extent of their capabilities is horrifying. We can plant bugs in machines. Once you go on the network, I can identify your machine. You will never be safe whatever protections you put in place.…

Well can they do that in Richard Stallman's laptop ? If so we are doomed :)

Re: Encrypt your Google chats and make the NSA sad

#14

This would definitely be the level of security that falls under this statement from Snowden: Q: Is it possible to put security in place to protect against state surveillance? A: "You are not even aware of what is possible. The extent of their capabilities is horrifying. We can plant bugs in machines. Once you go on the network, I can identify your machine. You will never be safe whatever protections you put in place.…

Why did he not give even a small technical overview on what they are capable of? He should've been able to given he has a lot of technical expertise and it would've helped his evidence a lot. Did they figure out how to tap complicated SSL? Is it hardware based? He gave no hints but could have easily. Instead it's this blanket statement that's supposed to imply that all encryption is pointless.

Glenn Greenwald said on Twitter that he was given the technical details and isn't releasing them.

Re: Encrypt your Google chats and make the NSA sad

#15
post #6

Still waiting for Google to implement OTR and ZRTP in Hangouts by default... especially now after all this.

Have a good time waiting, sir. In the meanwhile you might be interested in the following fact:

1. Google is removing XMPP as protocol http://www.zdnet.com/google-moves-away-from-the-xmpp-open-me...

2. On the other hand, however, duckduck is giving us some alternatives https://duck.co/topic/duckduckgo-s-new-public-xmpp-jabber-se...

Re: Encrypt your Google chats and make the NSA sad

#16
post #6

Still waiting for Google to implement OTR and ZRTP in Hangouts by default... especially now after all this.

I thought Google were being fingered as complicit? I wouldn't trust them, even if they totally super-secret pinky promise they're not handing everything over, honest!

Re: Encrypt your Google chats and make the NSA sad

#18

This would definitely be the level of security that falls under this statement from Snowden: Q: Is it possible to put security in place to protect against state surveillance? A: "You are not even aware of what is possible. The extent of their capabilities is horrifying. We can plant bugs in machines. Once you go on the network, I can identify your machine. You will never be safe whatever protections you put in place.…

This talk about "bugs" in machines makes one wonder if that is related to why Intel was one of the companies mentioned in a recent article. Intel stands apart from the rest of the companies. Google, Apple, Facebook don't specialize in hardware.

Apple obviously does specialize in hardware and if you use iMessage it is already encrypted.

Re: Encrypt your Google chats and make the NSA sad

#19
XMPP on a Raspberry Pi box with minimal raspbian and OTR. Gives you some control and a minimally-hackable box.

Some interesting related reading on the XMPP with Raspberry Pi:

[1] http://russelldavis.org/2013/01/18/setting-up-prosody-on-the...

[2] http://oskarhane.com/make-your-raspberry-pis-and-other-serve...

Re: Encrypt your Google chats and make the NSA sad

#20

This would definitely be the level of security that falls under this statement from Snowden: Q: Is it possible to put security in place to protect against state surveillance? A: "You are not even aware of what is possible. The extent of their capabilities is horrifying. We can plant bugs in machines. Once you go on the network, I can identify your machine. You will never be safe whatever protections you put in place.…

Why did he not give even a small technical overview on what they are capable of? He should've been able to given he has a lot of technical expertise and it would've helped his evidence a lot. Did they figure out how to tap complicated SSL? Is it hardware based? He gave no hints but could have easily. Instead it's this blanket statement that's supposed to imply that all encryption is pointless.

Interesting that he used the word "machines." I wonder if we're talking firmware hacks or even code in firmware that very few people are aware of. Could Intel say no to a NSL without breaking the law?
Post reply on HN