Live data from Hacker News

Encrypt your Google chats and make the NSA sad

github.com

101–110 of 195 posts

Re: Encrypt your Google chats and make the NSA sad

#101
post #87
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

Where would the private keys be stored? How do you handle the use-case of a non-technical user losing their laptop?

I'm talking about the non-extreme-security case of where the online email provider stores your private keys.

Re: Encrypt your Google chats and make the NSA sad

#102

Earlier quoted context omitted.

This doesn't make sense to me. There are two main stages to having your data analysed by such an organisation. In the first stage everybody's data is run through, let's call it, pattern matching, to narrow down a very specific number of cases that have the highest likelihood of doing, having done or planning "something". In the second stage, you might apply more resources to gather more data from your suspects, for e…

I was wondering the opposite: How do you get as many people as possible to trigger the match so that it becomes a losing proposition to do this sort of traffic monitoring.

I don't know how many known terrorist organizations would you like to correspond with on a regular basis?

Re: Encrypt your Google chats and make the NSA sad

#103

Earlier quoted context omitted.

Partisan towards... what? He is a very strong civil libertarian.

Here's Glenn either being intellectually dishonest or intellectually incompetent. http://www.samharris.org/blog/item/dear-fellow-liberal2

Thanks for bringing that up. I'd have to agree that Glenn Greenwald is an intellectual rotten apple. You don't accuse intelligent atheists of "racist islamophobia" if you're a good actor.

That said, he might just have an irrational us vs. them "liberals vs. racists" complex and be able to speak sensibly on other matters.

Re: Encrypt your Google chats and make the NSA sad

#105
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

Most people aren't going to get themselves into webs of trust - and certificate authorities and webmail servers and the like can be compromised. The only thing you can vest any significant trust in, with NSLs and so on flying around, is what's on your computer. And, if you want to be really sure, what's on a computer with no radio protected by an airgap into which you never insert removable media....

I'm not talking about deploying/using PGP to be secure from gov't (or Gmail) monitoring. I'm talking its use in the context of 99% of normal interactions online. Yes, we wouldn't have tinfoil-hat-level security if it was managed by Gmail, Yahoo, etc. But we'd be lightyears further ahead in our ability to interact securely with others online.

Re: Encrypt your Google chats and make the NSA sad

#106
post #6

Still waiting for Google to implement OTR and ZRTP in Hangouts by default... especially now after all this.

Probably not gonna happened, but it would solve so many problems with public key crypto. Key distribution? No problem, tie your public key to your gmail account. Need to communicate with someone? Just send them your public key. Goole would verify that key X belongs to mail Y, another problem solved. Mix it together with some javascript library (source code available by design) and you have almost perfect and simple t…

Except for the minor issue that, in the context of PRISM, the NSA mostly collects metadata - who corresponded with who, when and how much.

Public key cryptography is great for this, because it means if you match one person to a key, you've then reliably matched every message they sent and have fairly strong proof it's the same person.

Re: Encrypt your Google chats and make the NSA sad

#107
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

this would make "intercepts" far more difficult Yup, Google is doubtless completely in cahoots with the NSA. ... Really? Is that what you are thinking? Apply some rational thinking here. It's simpler than that. Google advertises to you based on the contents of your email. It is not in Google's interests to prevent themselves from being able to read your email, and if they can read it so can the NSA.

I don't understand why everyone seems to think this is an issue. It's as though the only alternative to the status quo is local host browser-level crypto.

The implementation I'm referring to doesn't preclude Gmail from reading emails it has of yours. It just means that only Gmail can read them, because only Gmail has your private key, a private key that's associated with two-factor authentication, and a private key you could optionally use elsewhere, too.

Re: Encrypt your Google chats and make the NSA sad

#108
post #36

Earlier quoted context omitted.

For Android, see the Guardian Project's work, especially Gibberbot: https://guardianproject.info/apps/gibber/ For iOS, you could try ChatSecure: http://chrisballinger.info/apps/chatsecure/ If you want to use the same key on both clients (which carries some additional risks if, say, your phone gets stolen, given that key is stored in plaintext) you may find the Guardian Project's documentation of different OTR key fil…

Thanks! I'll take a look at Gibberbot.

There's also Xabber which has OTR support (and can speak MSN, which is very helpful).

Re: Encrypt your Google chats and make the NSA sad

#109

Why doesn't Google up the security in its own apps? The government may "force" them to provide access, but can it "force" them to remove safeguards like encrypting email/chats/etc? Even if they just gave us the option to check a box, and it wasn't on by default. The problem I'm seeing with all these solutions is that they're very specific to two users, they both need to have everything set up. Well, great, the NSA wi…

can't force them not to encrypt emails but it can force them to give out the keys

Re: Encrypt your Google chats and make the NSA sad

#110

Why doesn't Google up the security in its own apps? The government may "force" them to provide access, but can it "force" them to remove safeguards like encrypting email/chats/etc? Even if they just gave us the option to check a box, and it wasn't on by default. The problem I'm seeing with all these solutions is that they're very specific to two users, they both need to have everything set up. Well, great, the NSA wi…

can't force them not to encrypt emails but it can force them to give out the keys
Post reply on HN