Live data from Hacker News

An encrypted message to Edward Snowden

wired.com

121–130 of 164 posts

Re: An encrypted message to Edward Snowden

#121

Earlier quoted context omitted.

At the moment, the NSA still permits use of 2048-bit RSA for classified information up to SECRET. It would be highly questionable for them to do so if they knew of easily exploitable weaknesses, as they're taking the chance that other governments won't find them. Remember, the NSA's mandate is twofold: They are a signals intelligence agency, but they are also charged with protecting government communications, much of…

That's not the only form of "exploit" http://www.scip.ch/en/?vuldb.2721

Uh, the existence of a buffer overflow (which doesn't even cause disclosure of an encrypted message) has nothing to do with the strength of the RSA algorithm, which is what the comment I replied to was talking about.

Re: An encrypted message to Edward Snowden

#123
post #110

Earlier quoted context omitted.

> Proof that an Ars Technica reader can amount to something. Cute. I'm sure he read Dilbert a few times too. It takes quite an astonishing level of arrogance to suggest that being an "Ars Technica reader" was an important part of his identity, as that article did. Internet nerd makes a few comments on tech website, huge shock there.

I'm pretty sure he was being sarcastic, playing on the fact that Wired and Ars Technica are sort of competitors.

Perhaps they are 'sort of' competitors, but both are owned by Condé Nast, so probably more a friendly corporate rivalry.

Re: An encrypted message to Edward Snowden

#124
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

A couple of days ago I read that 'As of 2012, 80% of the Tor Project's $2M annual budget comes from the United States government.'

http://online.wsj.com/article/SB1000142412788732467720457818...

That might be another reason that TOR isn't safe. You don't ever know who any of the other servers belong to ... and the staff at the Exit Node can (and has) read anything. I wouldn't bet my life on software 'originally sponsored by the U.S. Naval Research Laboratory'.

Re: An encrypted message to Edward Snowden

#126
post #124
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

A couple of days ago I read that 'As of 2012, 80% of the Tor Project's $2M annual budget comes from the United States government.' http://online.wsj.com/article/SB1000142412788732467720457818... That might be another reason that TOR isn't safe. You don't ever know who any of the other servers belong to ... and the staff at the Exit Node can (and has) read anything. I wouldn't bet my life on software 'originally spons…

you can simply run a node yourself and make your client use it.

Re: An encrypted message to Edward Snowden

#127
post #23

Earlier quoted context omitted.

Only use your private key with Tinfoil Hat Linux on an offline air-gapped computer: http://tinfoilhat.shmoo.com/ I recommend disconnecting your monitor and only receiving output by having it blinked out at you through your capslock light on your keyboard. Bonus points if you can get your hands on some TEMPEST hardened hardware, and/or tamper-resistant hardware. Anything less will leave you vulnerable to the black hel…

Well, if you can do that (program a computer via a blinking keyboard LED in Morse code to avoid Van Eck phreaking,) you're well on your way to discovering the lost Nazi gold in the Philippines.

Overlooking for the moment all of the lost Japanese gold in the Philippines. (Which isn't really lost, just remaining where it's safest.)

Re: An encrypted message to Edward Snowden

#128
post #94

Earlier quoted context omitted.

I'm sorry you've found yourself in the crossfire. How do you feel about Snowden?

He's a whistleblower of historic importance. That Verizon FISA order alone has exposed deception at the highest levels of government. Proof that an Ars Technica reader can amount to something.

Thanks for your reply! Also I agree :)

Re: An encrypted message to Edward Snowden

#129
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

[deleted]

Re: An encrypted message to Edward Snowden

#130
post #52

Earlier quoted context omitted.

I2P has protection against timing attacks. Bitmessage has deniability, but if the receiver end is compromised or untrustworthy, then the deniability is gone, and the timing attack might be possible. Combining Bitmessage and I2P would be solution, I think, but I don't know of any Bitmessage nodes on I2P.

Bitmessage doesn't have forward secrecy.

Could OTR be added to Bitmessage?
Post reply on HN