Live data from Hacker News

An encrypted message to Edward Snowden

wired.com

31–40 of 164 posts

Re: An encrypted message to Edward Snowden

#31
post #25
post #20

Earlier quoted context omitted.

Snowden called himself Verax[1]. Anyone who wants to send a message to Snowden* can just: $ gpg --keyserver pgp.mit.edu --recv-keys 79DEBE35 $ gpg --encrypt --sign --armor --recipient 79DEBE35 and post it publicly; perhaps on Pastebin. [1]: http://www.washingtonpost.com/world/national-security/code-n... *assuming you believe the key is authentic

79DEBE35 is a key in the possession of Wired, I'm sure they'll enjoy passing your message on the the NSA via their parent media giant. Edit: Also, it's not very hard to generate a different key with signature 79DEBE35, and put it on the key servers. gpg's displaying of such short abbreviations for keys is one the worst parts of its UI.

>79DEBE35 is a key in the possession of Wired

How do you know this?

Re: An encrypted message to Edward Snowden

#32
post #25
post #20

Earlier quoted context omitted.

Snowden called himself Verax[1]. Anyone who wants to send a message to Snowden* can just: $ gpg --keyserver pgp.mit.edu --recv-keys 79DEBE35 $ gpg --encrypt --sign --armor --recipient 79DEBE35 and post it publicly; perhaps on Pastebin. [1]: http://www.washingtonpost.com/world/national-security/code-n... *assuming you believe the key is authentic

79DEBE35 is a key in the possession of Wired, I'm sure they'll enjoy passing your message on the the NSA via their parent media giant. Edit: Also, it's not very hard to generate a different key with signature 79DEBE35, and put it on the key servers. gpg's displaying of such short abbreviations for keys is one the worst parts of its UI.

Both valid points; I have no way to verify that's an authentic key.

Re: An encrypted message to Edward Snowden

#33
post #25
post #20

Earlier quoted context omitted.

Snowden called himself Verax[1]. Anyone who wants to send a message to Snowden* can just: $ gpg --keyserver pgp.mit.edu --recv-keys 79DEBE35 $ gpg --encrypt --sign --armor --recipient 79DEBE35 and post it publicly; perhaps on Pastebin. [1]: http://www.washingtonpost.com/world/national-security/code-n... *assuming you believe the key is authentic

79DEBE35 is a key in the possession of Wired, I'm sure they'll enjoy passing your message on the the NSA via their parent media giant. Edit: Also, it's not very hard to generate a different key with signature 79DEBE35, and put it on the key servers. gpg's displaying of such short abbreviations for keys is one the worst parts of its UI.

> Edit: Also, it's not very hard to generate a different key with signature 79DEBE35, and put it on the key servers. gpg's displaying of such short abbreviations for keys is one the worst parts of its UI.

Yup: http://www.asheesh.org/note/debian/short-key-ids-are-bad-new...

Re: An encrypted message to Edward Snowden

#34
post #20

Earlier quoted context omitted.

More likely that it's a publicity stunt, raising awareness of strong encryption that the NSA (probably) can't crack yet.

Snowden called himself Verax[1]. Anyone who wants to send a message to Snowden* can just: $ gpg --keyserver pgp.mit.edu --recv-keys 79DEBE35 $ gpg --encrypt --sign --armor --recipient 79DEBE35 and post it publicly; perhaps on Pastebin. [1]: http://www.washingtonpost.com/world/national-security/code-n... *assuming you believe the key is authentic

* That's a pretty big assumption now isn't it.

Re: An encrypted message to Edward Snowden

#35
post #23

Earlier quoted context omitted.

In a world where the US government is scanning all your electronic communications, and (we'll next discover) searching your OS X- and Windows-based computers at will, how do you, as a practical matter, keep your private key "private"?

Only use your private key with Tinfoil Hat Linux on an offline air-gapped computer: http://tinfoilhat.shmoo.com/ I recommend disconnecting your monitor and only receiving output by having it blinked out at you through your capslock light on your keyboard. Bonus points if you can get your hands on some TEMPEST hardened hardware, and/or tamper-resistant hardware. Anything less will leave you vulnerable to the black hel…

The light reflected off your eyes from the capslock key is readable from high-res cameras. It's better to have leads hooked up to one of your toes and to toggle a 24V source so you can interpret the pulses in morse code.

Edit: obviously the 24V must come from a battery which is charged only at specific intervals -- otherwise they can interpret your messages by watching mains voltage variation.

Re: An encrypted message to Edward Snowden

#36
Every now and then I start thinking that Poulsen is starting to get the hang of honest journalism and some amount of professionalism, and then something like this comes along that makes it obvious he's still the same pathological attention whore whose primary hacking talents amounted to getting caught a lot.

Re: An encrypted message to Edward Snowden

#37
post #25

Earlier quoted context omitted.

79DEBE35 is a key in the possession of Wired, I'm sure they'll enjoy passing your message on the the NSA via their parent media giant. Edit: Also, it's not very hard to generate a different key with signature 79DEBE35, and put it on the key servers. gpg's displaying of such short abbreviations for keys is one the worst parts of its UI.

>79DEBE35 is a key in the possession of Wired How do you know this?

[deleted]

Re: An encrypted message to Edward Snowden

#39
post #28
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

That's not safe at all, considering the organization tracking him.

If not that, then what? If anything?

Re: An encrypted message to Edward Snowden

#40
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

Not safe at all. Timing analysis can detect correlations between data arriving at the interviewers computer with data sent by the suspect's computer.

Encryption is good at keeping the contents secret, but not the source of traffic.

Post reply on HN