Live data from Hacker News

An encrypted message to Edward Snowden

wired.com

61–70 of 164 posts

Re: An encrypted message to Edward Snowden

#61
post #23

Earlier quoted context omitted.

In a world where the US government is scanning all your electronic communications, and (we'll next discover) searching your OS X- and Windows-based computers at will, how do you, as a practical matter, keep your private key "private"?

Only use your private key with Tinfoil Hat Linux on an offline air-gapped computer: http://tinfoilhat.shmoo.com/ I recommend disconnecting your monitor and only receiving output by having it blinked out at you through your capslock light on your keyboard. Bonus points if you can get your hands on some TEMPEST hardened hardware, and/or tamper-resistant hardware. Anything less will leave you vulnerable to the black hel…

Well, if you can do that (program a computer via a blinking keyboard LED in Morse code to avoid Van Eck phreaking,) you're well on your way to discovering the lost Nazi gold in the Philippines.

Re: An encrypted message to Edward Snowden

#62
post #26
post #22

If Edward Snowden does have a pgp key (I can't find one online), it hasn't been revealed in this message. It looks like the signing and encryption keys are the same: gpg: armor: BEGIN PGP MESSAGE gpg: armor header: Version: GnuPG/MacGPG2 v2.0.19 (Darwin) gpg: armor header: Comment: GPGTools - http://gpgtools.org :pubkey enc packet: version 3, algo 1, keyid 5B50940B79DEBE35 data: [4096 bits] gpg: public key is 79DEBE3…

There's no way to tell when a key was uploaded to a keyserver without the keyserver's logs.

But that's metadata. You dont need a court order for THAT!

Oh wait. That plan only works for federal agencies and secret courts. Never mind.

Re: An encrypted message to Edward Snowden

#63
post #49
post #41

Earlier quoted context omitted.

I would be very interested in a a tutorial or guide for getting something like this set up on OS X.

OS X has smart card support for FileVault 1 but not FileVault 2. It only includes enough drivers to support US DoD CAC cards, and other NATO countries that have standardized on our stuff.

With regard to PGP, you can get a reader and smartcard from Kernel Concepts. Assuming you already know how to use GPG, it's pretty easy to set up.

http://shop.kernelconcepts.de/index.php?cPath=1_26&sort=2a&l...

Re: An encrypted message to Edward Snowden

#64
There are a few things about this that seem odd to me. From elsewhere in the comments, the key is encrypted with 79DEBE35, which, if you look it up on your keyserver of choice, belongs to "Verax (Informed Democracy Front)", created on May 20, 2013.

Verax was the name used by Snowden to communicate with Laura Poitras (and perhaps others as well), but the story didn't break until June 5 and his identity wasn't revealed until days later.

So why is Wired encrypting a message with a key using that name that was generated before the name was publicly known in association with Snowden?

EDIT: Disregard the above—the "encrypted with" key is the recipient's key, not the sender/signer. 79DEBE35 may well be Snowden's key (but that's not proven either).

Re: An encrypted message to Edward Snowden

#65
post #15

The target key was published on 5/20. # gpg --list-packets /tmp/snowden.asc :pubkey enc packet: version 3, algo 1, keyid 5B50940B79DEBE35 data: [4096 bits] :encrypted data packet: length: unknown mdc_method: 2 gpg: encrypted with 4096-bit RSA key, ID 79DEBE35, created 2013-05-20 "Verax (Informed Democracy Front)" (79DEBE35 can be found on the subkeys.pgp.net keyserver)

Meanwhile, per the Washington Post article, he asked the guardian to setup PGP in Feb, and his contact finally did so in March, both before this key's listed creation date.

Re: An encrypted message to Edward Snowden

#66
post #16

Snowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.

> isn't safe because of timing attacks What about that it isn't safe because of who is running many of the exit nodes?

It has more to do with the structure of the public internet. A fully passive observer in a few key locations has a surprisingly high probability of being able to perform correlation attacks.

This is a pretty interesting "where do I start?" paper if you want to know more but don't have much background on the subject:

http://www.syverson.org/tor-vulnerabilities-iccs.pdf

Re: An encrypted message to Edward Snowden

#67
post #11

I don't get it, unless Snowden's published his public key somewhere and Wired has some really, really important information for him?

The reason you would advertise a page like this is to get lots of people to visit it. It gives Snowden the ability to look like any of the other (tens?) of thousands of people who visit the URL in the next little while.

I imagine anything to do with Snowden pales in comparison to getting lots of people to visit it so they can get ad revenue.

Re: An encrypted message to Edward Snowden

#68
post #7

Earlier quoted context omitted.

yeah, I was wondering about how strong GPG was. Back in the day, i.e. the 90's, the assumption was it would take years for then-current NSA supercomputers to factor the keys. Nowadays, with all sorts of new attacks, analyses, and cheap as hell compute time, I would wager that time requirement has gone significantly down.

AFAIK, the current publicly-known record for breaking RSA keys is the factorization of RSA-768 in 2010: http://eprint.iacr.org/2010/006.pdf That paper says it took about 1500 CPU-years to break a 768-bit key, and that the difficulty increases 1000x for each additional 256 bits of key length. For a back-of-the-envelope cost estimate, I'm going to assume that there have been no major theoretical breakthroughs in the la…

Assuming there's no known exploit. The NSA might know of an exploit for that algorithm.

Re: An encrypted message to Edward Snowden

#69
post #45

Earlier quoted context omitted.

The light reflected off your eyes from the capslock key is readable from high-res cameras. It's better to have leads hooked up to one of your toes and to toggle a 24V source so you can interpret the pulses in morse code. Edit: obviously the 24V must come from a battery which is charged only at specific intervals -- otherwise they can interpret your messages by watching mains voltage variation.

obviously! It's times like these, I'm grateful for limited terms of office, and a politically divided country.

You mean it's nice to see Democrats oppose Bush's illegal spying and Republicans oppose Obama's illegal spying?

http://www.guardian.co.uk/commentisfree/2013/jun/14/nsa-part...

Re: An encrypted message to Edward Snowden

#70
post #23

Earlier quoted context omitted.

Only use your private key with Tinfoil Hat Linux on an offline air-gapped computer: http://tinfoilhat.shmoo.com/ I recommend disconnecting your monitor and only receiving output by having it blinked out at you through your capslock light on your keyboard. Bonus points if you can get your hands on some TEMPEST hardened hardware, and/or tamper-resistant hardware. Anything less will leave you vulnerable to the black hel…

Well, if you can do that (program a computer via a blinking keyboard LED in Morse code to avoid Van Eck phreaking,) you're well on your way to discovering the lost Nazi gold in the Philippines.

Haha, yes. Actually, I'm not sure about this but I believe Cryptonomicon may have been an inspiration for Tinfoil Hat Linux.
Post reply on HN