Live data from Hacker News

Wikileaks Releases New 'Insurance' Files

facebook.com

51–60 of 115 posts

Re: Wikileaks Releases New 'Insurance' Files

#51
post #10

Earlier quoted context omitted.

Unless the insurance files are bluffs, you may as well give the US government the keys yourself so that they know you are not bluffing. The threat that makes the insurance files work is that the public/press and/or foreign governments may get the keys.

The problem with doing that is that the US government might release the information themselves, just dampened a bit with some PR, so the insurance files aren't worth anything and so WikiLeaks don't get the credit.

I'm not sure WikiLeaks would find that to be a problem. Isn't the whole goal to eventually convince governments to release things themselves?

Re: Wikileaks Releases New 'Insurance' Files

#52

Earlier quoted context omitted.

Clearly, just use a standard solution (PGP). Don't do this with a weak passphrase, and use key-strengthening (bcrypt etc.) just in case. Assange is pretty good at crypto, so I'd expect Wikileaks to broadly get this right. Also, they already got in trouble for reusing a password ( http://boingboing.net/2011/08/31/wikileaks-guardian-journali... ), so I'm pretty sure they won't do that again...

> Assange is pretty good at crypto Not really. He gave a moron the password to a publicly distributed insurance file instead of making a new encrypted file just for him.

Are you aware of http://en.wikipedia.org/wiki/Rubberhose_(file_system)?

Re: Wikileaks Releases New 'Insurance' Files

#54
post #30

I wonder what are the risks associated with downloading and sharing such torrents. Evidently, anyone getting them becomes a highly visible target and once the content of these torrents is known, you could become involved in the distribution of classified data. Even if the content is not known, it could be viewed as an 'unfriendly' act and could make you become a "target of interest" to some zealous 3-letter agency...…

If I understand the law correctly, only military people have any prohibition about touching, reading, distributing, etc classified data.

Normal citizens agreed to no such terms.

Re: Wikileaks Releases New 'Insurance' Files

#55

Earlier quoted context omitted.

> Assange is pretty good at crypto Not really. He gave a moron the password to a publicly distributed insurance file instead of making a new encrypted file just for him.

Are you aware of http://en.wikipedia.org/wiki/Rubberhose_(file_system) ?

No, I wasn't aware of it. The concept looks similar to TrueCrypt's plausible deniability.

Re: Wikileaks Releases New 'Insurance' Files

#56

Earlier quoted context omitted.

Clearly, just use a standard solution (PGP). Don't do this with a weak passphrase, and use key-strengthening (bcrypt etc.) just in case. Assange is pretty good at crypto, so I'd expect Wikileaks to broadly get this right. Also, they already got in trouble for reusing a password ( http://boingboing.net/2011/08/31/wikileaks-guardian-journali... ), so I'm pretty sure they won't do that again...

No, the key strengthening is probably built-in. Also, most likely it doesn't use a passphrase, but a big generated gpg key (with a passphrase protecting it, of course)

At least for symmetric encryption, gpg defaults (defaulted?) to SHA-1'ing the passphrase 2^16 times, which is not a very large number - http://passwords12.at.ifi.uio.no/Jeremi_Gosney_Password_Crac... [pdf] talks of ~2^36 operations per second.

This isn't the worst thing ever, but using GPG for passphrase-protected encryption is not as strong as you might expect - just use a slightly longer/better one.

(Obviously, don't switch to another tool if you can't evaluate it in depth - GPG isn't perfect, but picking a random other tool won't be an improvement.)

Re: Wikileaks Releases New 'Insurance' Files

#57

Earlier quoted context omitted.

Are you aware of http://en.wikipedia.org/wiki/Rubberhose_(file_system) ?

No, I wasn't aware of it. The concept looks similar to TrueCrypt's plausible deniability.

Yes, basically; RubberhoseFS helped bring the idea into more-mainstream tools.

Re: Wikileaks Releases New 'Insurance' Files

#58
post #30

I wonder what are the risks associated with downloading and sharing such torrents. Evidently, anyone getting them becomes a highly visible target and once the content of these torrents is known, you could become involved in the distribution of classified data. Even if the content is not known, it could be viewed as an 'unfriendly' act and could make you become a "target of interest" to some zealous 3-letter agency...…

"You could become involved in the distribution of classified data."

IANAL, but I believe the espionage act contains a mens rea requirement.

Re: Wikileaks Releases New 'Insurance' Files

#59

Earlier quoted context omitted.

If you want that domain to die please continue to spam this forum. Of all the places on the web this is probably the least smart to pull stunts like this.

Does anyone actually fall for this stuff ?

Here on Brazil.recently.the justice.caught a.group.that stole.several millions that way..one third of a certain state.population here signed up.

Most depressingly,.after the justice shut the thing down, they asked it to allow it to.continue, because they were still.profitable... ( it was a ponzi )

Post reply on HN