Live data from Hacker News

Use of Tor and e-mail crypto could increase chances that NSA keeps your data

arstechnica.com

51–60 of 116 posts

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#51
post #29
post #9

Since I (and the majority of global internet users) are not "US persons", they're claiming they're entitled to intercept and store all my communications anyway - so my personal reaction to this is going to be to increase the use of tor and crypto for random everyday stuff. I'll start GPG encrypting email to anybody I know will be able ro deal with it. I might even start randomly mailing GPG encrypted mail for no reas…

"I will start GPG encrypting email to anybody I know who will be able to deal with it" As sad as it is to say, lets be honest and admit that this is a fairly small number. How long do you think it will be till your less committed friends get tired of decrypting your emails and just ignore what you send? Make sure you only pick people that use actual email clients because gpg and Gmail is no fun. As far as the "Thomas…

Now I'm thinking of a patched SMTP server, that queues all outgoing mail - and sends mail every hour on the hour to each of my GPG enabled recipients, with a queued "real mail" if there is one or a random encrypted NSA RickRoll if there's no real mail to send.

(I suspect that'd last about 121 minutes before most of my friends spam filtered me forever)

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#52
post #47
post #40

Earlier quoted context omitted.

You do realize that: "A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary. Instead, we assume an adversary who can observe some fraction of network traffic; who can generate, modify, delete, or delay traffic; who can operate onion routers of his own; and who can com…

The "renew my car registration" example was intended to imply that'd I've chosen to "give them some connected dots" - dots which are operationally useless (or worse - preferably adding noise to make the job harder and evidence that the job is sometimes wasted effort). I'm assuming "they" have access to government servers and networks, and that they'll easily be able to connect me - as a real and (at least mostly) law…

I don't get what you mean. You think that once you connect to https://site.gov/ they can easily match the traffic entering the tor network with the traffic that exited tor and initiated the web connection?

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#53
post #19
post #7

This is fairly obvious. From the NSA's perspective, people that act like people who have something to hide are more likely to be hiding something. I'd be surprised if they didn't take it into account.

And this is why we should (and we should encourage everybody we can to) regularly do the most mundane of browsing using TOR. I'm making a personal effort to use TorBrowser whenever I have some trivial need to use a government website. I suspect I'd stop short of applying for a visa via TOR, but I'll happily look up my local state or federal politicians and their websites, or renew my car registration, or any of the o…

And this is why we should (and we should encourage everybody we can to) regularly do the most mundane of browsing using TOR.

And that's why I encourage everybody I can to run a tor node

https://www.torproject.org/docs/tor-doc-relay.html.en

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#54
post #52
post #47

Earlier quoted context omitted.

The "renew my car registration" example was intended to imply that'd I've chosen to "give them some connected dots" - dots which are operationally useless (or worse - preferably adding noise to make the job harder and evidence that the job is sometimes wasted effort). I'm assuming "they" have access to government servers and networks, and that they'll easily be able to connect me - as a real and (at least mostly) law…

I don't get what you mean. You think that once you connect to https://site.gov/ they can easily match the traffic entering the tor network with the traffic that exited tor and initiated the web connection?

That's assuming they've got compromised tor nodes that they're able to watch both my entrance and exit node.

Which may well be true.

(But I'm still hoping my new 2048bit GPG key and a significant portion of tor nodes are _not_ NSA bugged...)

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#55
post #37
post #12

Earlier quoted context omitted.

> This shouldn't be a surprise at all. Using Tor hides your location, so they assume you are foreign unless proven otherwise. That covers Tor, but not the rest... > As a European, what I find more disturbing about all the news about PRISM and related programs, is how US centric the reports Agreed. I worry that the American government has done damage to the cause of globalisation that will take a very long time to hea…

Don't take this the wrong way, but you mention the effect on globalization as if it were obvious that the damage should worry the American government. On the contrary, the U.S. has vacillated between isolationism and interacting with other nations before. I don't know if you've been over to the U.S. but we have a stunningly large continent of people who feel that it is absolutely treasonous to give foreign aid at all…

> Don't take this the wrong way, but you mention the effect on globalization as if it were obvious that the damage should worry the American government

Oh, certainly not. I don't think they are or will be concerned...

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#56
post #26

How about steganography? We all fire off so many pictures and attachments that there has to be an avenue here.

Know of any non-obvious stego of 10MB, 100MB, and larger file size?

I suppose you need a large carrier for a large message to be hidden. Very high resolution home movies maybe? I assume you can't use content that is already public, as then the original can be compared with the modified version to prove that hidden data exists.

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#57
I think that the idea that "using crypto will cause the nsa to keep your data longer" is a hindrance to progress. Everyone should be using crypto and everyone should have privacy. When we begin to be afraid of what someone will do if we protect our interests, we start giving up those interests and that is not something I am prepared to do.

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#58

How about steganography? We all fire off so many pictures and attachments that there has to be an avenue here.

What the world needs is spammers who would be diligent enough to encrypt their spam with your public key. You would have to use a client-based spam filter, but such a small price to pay.

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#59
post #54
post #52

Earlier quoted context omitted.

I don't get what you mean. You think that once you connect to https://site.gov/ they can easily match the traffic entering the tor network with the traffic that exited tor and initiated the web connection?

That's assuming they've got compromised tor nodes that they're able to watch both my entrance and exit node. Which may well be true. (But I'm still hoping my new 2048bit GPG key and a significant portion of tor nodes are _not_ NSA bugged...)

More confused now. You are worried about a GPA or a lesser adversary?

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#60
post #6

This is somewhat unrelated, but I was listening to "Leo Laporte The Tech Guy" on the local talk radio with my dad (who is a big fan, but less into tech than I) and he started describing GPG and PGP to non-tech enthusiasts. This whole NSA scandal may really push forward the use of encryption of securer communication methods.

Only if it pushes developers to make the tools dead-simple to use. If it is harder to use than facebook, 99% of the population will not bother.
Post reply on HN