Live data from Hacker News

Encrypt your Google chats and make the NSA sad

github.com

171–180 of 195 posts

Re: Encrypt your Google chats and make the NSA sad

#171
post #167

Earlier quoted context omitted.

I took that to mean that they have exploits they can run once they which will let them take over your machine and install keyloggers etc. to report back any further activity. It wouldn't take much for them to purchase or develop a suite of vulnerabilities for all the major operating systems/browsers which they keep current, and once they have that any encryption is pointless as they can see what you see/type/hear. He…

Some major military contractors (Raytheon I think is one, BAH another maybe) were looking to hire security experts to find vulnerabilities. There is a robust black market for 0days and I can't imagine the govt. isn't interested in playing. Especially after the cyber-terror war drum has been beating for a while and Chinese hackers scaring everyone's grandmas (most likely articles seeded by PR agencies in preparation f…

I thought it was common knowledge that governments actively buy and use 0days? They certainly do, just look at Stuxnet's astounding and ham handed usage of 4 0days (in the first version) for an easy example all the way back in 2010.

Re: Encrypt your Google chats and make the NSA sad

#172
post #132

Earlier quoted context omitted.

Have a good time waiting, sir. In the meanwhile you might be interested in the following fact: 1. Google is removing XMPP as protocol http://www.zdnet.com/google-moves-away-from-the-xmpp-open-me... 2. On the other hand, however, duckduck is giving us some alternatives https://duck.co/topic/duckduckgo-s-new-public-xmpp-jabber-se...

Forget about DuckDuckGo, it's based in the US. Better use Startpage.com, which is based in the Netherlands.

It's not the fact that US=bad, EU=good. The fact is that you can use free software programs over xmpp which support OTR cryptography.

Re: Encrypt your Google chats and make the NSA sad

#173
post #4

While this is a nice effort, why use Google Talk at all for chatting if you're going to do all this effort (per user configuration etc) if you could just use an XMPP client with OTR[1] support, or use an XMPP server you can trust? [1] https://en.wikipedia.org/wiki/Off-the-Record_Messaging

Because then you'd be talking to yourself as nobody uses XMPP with OTR.

So true :( so sad. I've got a bunch of friends that know how to use it. They're just annoyed if I enable it. :(

Re: Encrypt your Google chats and make the NSA sad

#174

This would definitely be the level of security that falls under this statement from Snowden: Q: Is it possible to put security in place to protect against state surveillance? A: "You are not even aware of what is possible. The extent of their capabilities is horrifying. We can plant bugs in machines. Once you go on the network, I can identify your machine. You will never be safe whatever protections you put in place.…

Why did he not give even a small technical overview on what they are capable of? He should've been able to given he has a lot of technical expertise and it would've helped his evidence a lot. Did they figure out how to tap complicated SSL? Is it hardware based? He gave no hints but could have easily. Instead it's this blanket statement that's supposed to imply that all encryption is pointless.

Technical details are in the remaining 37 slides he gave to reporters which they are refusing to release

Re: Encrypt your Google chats and make the NSA sad

#175
post #2

As far as I can tell, this is using CBC mode without any authentication: https://raw.github.com/mdp/gibberish-aes/master/dist/gibberi... If that's the case, then this implementation is vulnerable to a variety of attacks.

It's worse that that. It uses a questionable javascript crypt library (written by a former twitter dev, not a cryptographer) and a fixed IV derived from the password which is re-used for each message. This is oh I read the wikipedia article on AES level cryptography deployed against people who would have written the Wikipedia entry if not for that fact that what they know is probably not public. Better idea: Just mak…

It's definitely a questionable javascript library, I wrote it back in 2008 after reading the wikipedia article :)

It was designed to interop with OpenSSL's default command line AES crypto, which has some weak points, mostly around the IV selection.

That being said, the biggest weakness will always be that it's running in the browser and open to injection attacks.

But while I think there's definitely better crypto chat solutions out there, it's nice to see people taking an interest in the subject. And let's not kid ourselves, the vast majority of NSA data collection is probably less about sophisticated encryption attacks, and more about the clever application of political/police powers.

Re: Encrypt your Google chats and make the NSA sad

#176
post #4

While this is a nice effort, why use Google Talk at all for chatting if you're going to do all this effort (per user configuration etc) if you could just use an XMPP client with OTR[1] support, or use an XMPP server you can trust? [1] https://en.wikipedia.org/wiki/Off-the-Record_Messaging

Because then you'd be talking to yourself as nobody uses XMPP with OTR.

Nobody is using this solution either, and setting it up is harder than setting up OTR (provided your conversation partner is already using an app for XMPP).

I can explain my girlfriend and brother how to enable and configure OTR. I would have a hard time getting them to execute the instructions for this addon.

Re: Encrypt your Google chats and make the NSA sad

#177

Earlier quoted context omitted.

Partisan towards... what? He is a very strong civil libertarian.

Here's Glenn either being intellectually dishonest or intellectually incompetent. http://www.samharris.org/blog/item/dear-fellow-liberal2

Greenwald has written many things, most extremely valuable. I also am critical of his exchange with Sam Harris but that's one discussion in hundreds or thousands.

Re: Encrypt your Google chats and make the NSA sad

#178

Earlier quoted context omitted.

This doesn't make sense to me. There are two main stages to having your data analysed by such an organisation. In the first stage everybody's data is run through, let's call it, pattern matching, to narrow down a very specific number of cases that have the highest likelihood of doing, having done or planning "something". In the second stage, you might apply more resources to gather more data from your suspects, for e…

I was wondering the opposite: How do you get as many people as possible to trigger the match so that it becomes a losing proposition to do this sort of traffic monitoring.

Getting them all to make online friends in foreign countries would do it. Iran, Yemen, Gaza, lots of places would trigger I would think.

Re: Encrypt your Google chats and make the NSA sad

#179
post #39

Earlier quoted context omitted.

Thanks, can you suggest me a better AES implementation ?

Your implementation is vulnerable to MITM attacks. That will be the case no matter which AES mode you choose. You are on the tip of the greatest problem with modern cryptography, which is that there is no real way for widespread confidentiality to be created without trusting a third party such as a CA. But once you trust a CA, then you become vulnerable to the backdoors available through the CA community (not just on…

Thanks, where will the man in the middle be ?

Re: Encrypt your Google chats and make the NSA sad

#180
post #83

Earlier quoted context omitted.

Further thinking along this line: most people in the world today are dependent on their phones and internet for information and communication. A lot of people suspected total listening capabilities and now we mostly know that's the case. But what if the NSA had total interference capabilities, as Snowden's quote implies? I suspect it does. I've been finding HN to be a hub for all the facets, ideas, and fallout from t…

When I told my grandparents (who now live in Russia/former Eastern Bloc) about what's happening in the US, they brought up this exact issue (with a less tech-oriented example). My grandmother said that this was the most terrifying part of living in the Soviet Union. Since most of my grandparents were high up military (doctors, not soldiers), aerospace research, and medicine in the Soviet Union, they saw the reality o…

After living outside the US for a decade, this is how I feel when I go back and watch the news.
Post reply on HN