Live data from Hacker News

An encrypted message to Edward Snowden

wired.com

151–160 of 164 posts

Re: An encrypted message to Edward Snowden

#151
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

I hope Snowden realizes that none of this matters if an FBI agent is sitting beside the reporter as they communicate.

Re: An encrypted message to Edward Snowden

#152
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

I am not sure about Bitmessage. It is a very new project and has not been subject to any deep security test. Also, VPNs are as safe as long as the VPN provider is on your side. Tor is your best option.

Re: An encrypted message to Edward Snowden

#153
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

I am not sure about Bitmessage. It is a very new project and has not been subject to any deep security test. Also, VPNs are as safe as long as the VPN provider is on your side. Tor is your best option.

I was talking about combining all them three: Bitmessage through Tor through VPN.

Re: An encrypted message to Edward Snowden

#154
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

I hope Snowden realizes that none of this matters if an FBI agent is sitting beside the reporter as they communicate.

Presumably the contents of the conversation will not be secret. Only the location of Snowden.

Re: An encrypted message to Edward Snowden

#156
post #42

Earlier quoted context omitted.

Those leads are gonna generate magnetic distortions. You should only do this with your feet next to a giant 18" subwoofer while blasting dubstep in order to mask any electromagnetic fluctuations. Bonus: Anyone surveilling you via audio bugs will need new ears.

I know this is all in good fun, but you all are uncomfortably close to describing things that will soon get added to the practical threat landscape. As long as you have a flexible hardware platform that lets you crank up some of the voltage regulator outputs, gpios that can be attached to a long trace/external wire as a makeshift antenna and have a decently fast cpu clock you have all the ingredients for a crude but…

Paranoid thinking is an extremely valuable asset for security researchers. The things we're all joking about are impractical for an average person, but in a spy vs. spy scenario, especially when each side is well funded, these are the kind of things that will actually get used.

Examples of genuine vulnerabilities that would make you look paranoid just by defending against:

* Make educated guesses about passwords from a microphone recording of the keypresses. Both the intervals between keypresses indicate the region of the keyboard being touched, and the sound of each key differs slightly. Given a statistically significant sample of typing, you could deduce which keys are which based on the frequency of their use. http://www.securityfocus.com/news/11318

* Read a screen through a reflection, even from far away http://www.schneier.com/blog/archives/2008/05/spying_on_comp...

Re: An encrypted message to Edward Snowden

#157
post #97
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

It's reasonable to not trust Lamo, and maybe even Kevin Poulsen (although IMO he's just reported the news in the PFC Manning case; it's Adrian who turned PFC Manning in. OTOH, if I'd been in Lamo's position (convicted felon!), I probably would have turned him in, too, thinking the whole thing was a sting or otherwise a setup since it was so fucking brazen. The only other safe option is "I HAVE NO IDEA WHAT YOU ARE SA…

I miss politechbot. I will never understand why so many discussion venues transitioned to forums from mailing lists.

Re: An encrypted message to Edward Snowden

#158
post #157
post #97

Earlier quoted context omitted.

It's reasonable to not trust Lamo, and maybe even Kevin Poulsen (although IMO he's just reported the news in the PFC Manning case; it's Adrian who turned PFC Manning in. OTOH, if I'd been in Lamo's position (convicted felon!), I probably would have turned him in, too, thinking the whole thing was a sting or otherwise a setup since it was so fucking brazen. The only other safe option is "I HAVE NO IDEA WHAT YOU ARE SA…

I miss politechbot. I will never understand why so many discussion venues transitioned to forums from mailing lists.

Ad revenue. :(

liberationtech seems good; p2p-hackers was ok for a while. the old cryptography list was ok in a couple of the incarnations. cypherpunks before the great decline is still my gold standard, though. (remops has been ok at times; some of the digital gold lists were also interesting).

Re: An encrypted message to Edward Snowden

#159
post #158
post #157

Earlier quoted context omitted.

I miss politechbot. I will never understand why so many discussion venues transitioned to forums from mailing lists.

Ad revenue. :( liberationtech seems good; p2p-hackers was ok for a while. the old cryptography list was ok in a couple of the incarnations. cypherpunks before the great decline is still my gold standard, though. (remops has been ok at times; some of the digital gold lists were also interesting).

The p2p-hackers channel was also interesting around the same time. The fact that you have to differentiate between the "old cryptography list" and its newer incarnations is sad. I think with each move the list went down hill. It seems half the posts to cryptography are either cc'ed to cpunks and a bunch of other lists or the message is a conference announcement.

Re: An encrypted message to Edward Snowden

#160
post #158
post #157

Earlier quoted context omitted.

I miss politechbot. I will never understand why so many discussion venues transitioned to forums from mailing lists.

Ad revenue. :( liberationtech seems good; p2p-hackers was ok for a while. the old cryptography list was ok in a couple of the incarnations. cypherpunks before the great decline is still my gold standard, though. (remops has been ok at times; some of the digital gold lists were also interesting).

When I get bored/nostalgic I will search gmane for one of the prolific mailing list subscribers like Eugen Leitl or that Vladis dude from VT. I found liberationtech via Eugene.
Post reply on HN