If you start using PGP for all your email, then you by inference "have something to hide". Brilliant logic.
What a mess.
21–30 of 116 posts
If you start using PGP for all your email, then you by inference "have something to hide". Brilliant logic.
What a mess.
The NSA operates a Tor exit node at Georgia Tech, and likely at other research institutes and universities. The fact of the matter is, people who use Tor are the ones trying to hide from the government, and it only makes sense for the NSA to run Tor exit nodes and analyze all traffic passing through them. You probably have more privacy by not using Tor at all.
I do not mean this to be snarky -- if you have a legitimate source other than hearsay, I'd love to see it.
If one uses Tor, the article states that the person will not be treated as a United States person unless "proven" otherwise. If that's the case, all the traffic from a Tor exit node will be considered as traffic from non U.S. persons and all data will be stored. Doesn't make sense to me because if you are using Tor right, then requests cannot be traced back to you. How does that help?
It depends on what you mean by "using TOR right" - and that depends on who/where you are and what you're trying to protect yourself against. A Chinese/Egyptian/Turkish dissident might consider it perfectly sensible to use TOR to access their gmail account - that's a perfectly valid way of hiding from your local (non-US) government and spy agencies.
All good news!
1: The Guardian is still time-releasing, I thought they caved under a IGIC -sorry, what ever its called over there - gag order.
2: Now we know what to do to backup into the NSA cloud! Another USA world benefit: a highly secure service for all the world to avail themselves for free.
3: web app $opportunity$! tor p2p delivery and crypto of your files into free NSA Cloud, for only $0.99!
The only long-term way to hide data is not to use public networks for communication. Eventually, quantum computers should be able to eat though any of today's crypto. It will be interesting to see what happens when everyone running for public office has their entire life on display.
Probably not. Quoting from http://blog.agilebits.com/2013/03/09/guess-why-were-moving-t...:
A quantum of bits [Update: March 20, 2013]
I reached out to the cryptographic community for any insight into Molly’s question about why the NSA insists that TOP SECRET material be encrypted using 256-bit keys. The answer came from Steven Bellovin of Columbia University:
@jpgoldberg @marshray Just heard that during the AES competition, NSA said in the open meetings it was for defense against quantum computing
Quantum computers, if they are every made practical, will be able to do amazing things. They will certainly change how we design cryptographic systems. It’s not that quantum computers will be faster or more powerful. Indeed, in some very important respects they will be less powerful than current computers. But there are some things that they will be able to do in less “time”. I put “time” in scare quotes because it has a different meaning in this context from the ordinary use of the word. Oh, what a big difference it is. In this context it means the number of distinct steps an algorithm must take in performing some computation.
Searching through 2128 keys (on a classical, non-quantum, computer) takes a number of steps that is proportional to 2128. But for a quantum computer it takes a number of steps proportional to the square root of that number, 264. If a quantum computer is ever built capable of performing that task, we don’t know how the actual speed of each individual step will compare to those of current computers, but the NSA is taking no chances. Something with the effective strength of a 64-bit key isn’t strong enough. A 256-bit key against a quantum brute force attack would have the effective strength of a 128 bit key against a classical brute force attack.
I very much doubt that we will see a quantum computer actually capable of handing such things within the next thirty years. But if the past is any guide, my predictions about the future should be taken with a large grain of salt.
How about steganography? We all fire off so many pictures and attachments that there has to be an avenue here.
This is fairly obvious. From the NSA's perspective, people that act like people who have something to hide are more likely to be hiding something. I'd be surprised if they didn't take it into account.
Since I (and the majority of global internet users) are not "US persons", they're claiming they're entitled to intercept and store all my communications anyway - so my personal reaction to this is going to be to increase the use of tor and crypto for random everyday stuff. I'll start GPG encrypting email to anybody I know will be able ro deal with it. I might even start randomly mailing GPG encrypted mail for no reas…
As sad as it is to say, lets be honest and admit that this is a fairly small number. How long do you think it will be till your less committed friends get tired of decrypting your emails and just ignore what you send? Make sure you only pick people that use actual email clients because gpg and Gmail is no fun.
As far as the "Thomas Crowne Affair attack" goes generating effective cover traffic is not easy and random traffic is definitely a bad idea. Basic traffic analysis would be able to separate your legit emails from your cover traffic.
Addendum: I noticed you just generated your new gpg key yesterday. Why not go big and use a 4096 bit key?
If you want to read the documents without having to use that awful viewer or load js from every social networking site known to man: (increment the p# from 1-9) Procedures used by NSA to target non-US persons: Exhibit A: https://s3.amazonaws.com/s3.documentcloud.org/documents/7166... Procedures used by NSA to minimize data collection from US persons: Exhibit B: https://s3.amazonaws.com/s3.documentcloud.org/documents/…