DARPA Is Looking For the Perfect Encryption App
motherboard.vice.com
motherboard.vice.com
The private blockchain will give them state machine replication, some kind of method of encrypted authentication, and a platform for transaction verification across military/dod (or whatever the specific use cases are). The communication bit could work as well since they don't have to store the messages themselves in the blockchain. Since the blockchain is private, this also somewhat solves the problem of transaction speed. There would probably be some lag, but probably just a few seconds or even less if optimized.
Something like Ethereum (with whisper and and swarm) could work if they were looking to use a public blockchain, but they specifically reference Hyperledger.org in their publication.
Same thing that would prevent some one from writing to the private blockchains banks are setting up for clearinghouse purposes.
If your the security of your cryptographic system is dependent on anything but the secret keys being secret it's time to go back to the drawing board.
Bitcoin works because it uses proof of work as a gating mechanism to prevent abuse, closed blockchains usually rely on other mechanisms as the parties involved in them can negotiate the terms via other means.
How is that different from what is used currently?
It let's members of a group create a totally private darknet with a hierarchy of trust among themselves using a chain of signed trust tokens. All packets are encrypted with the key of the receiver and signed by the sender. It even uses random ports and sends filler traffic between nodes to prevent finger printing.
I built on top of it services like IM, VOIP, chat rooms, a versioned file system, mail, message boards, etc.. I had a lot of free time lol. The nodes automatically manage the storage of data around the DHT.
>> " Q2. The criteria for "time to live/self delete for messages" is impossible to achieve with a Blockchain. Is that a problem for this challenge? A2. [Response Pending]"
I guess if the messages are stored in the blockchain, a device would be able to delete the key and other information needed to access the message, effectively deleting the message from the device, protecting the user of the device from having to answer for the content of the message.
There are a lot of problems who seem contradictory until they are solved by cryptography.
https://www.coursera.org/learn/cryptography/lecture/be3ae/th...
Last year I came across a "fair" version of the Socialist Millionaires problem. How can two persons interact with one another to compare their bank statement. If you think about it, you might consider that in any interaction, a party might abort the exchange as soon as he learns the result and would then have an advantage over the other party. But not too long ago cryptography found a way to make this fair :) (https://www.cryptologie.net/article/279/how-to-fairly-compar...)
Barring a human-computer interface that conveys messages directly into someone's brain, I don't see this as possible. If you can see it or if you can hear it, then it is copy-able.
Some crypto work is focused on proving that certain things are impossible. But so far I haven't seen any paper proving that this was impossible.
Before Bitcoin came along a working decentralized P2P currency had been considered impossible, since nobody could figure out a way to make a P2P currency unforgeable (and therefore work as a currency) before that.
The more confusing requirement is that they want instant communications over a blockchain.
But at a higher level, this is a sort of odd set of requirements. "You have to use a blockchain somehow" is a class project requirement, not an actual project deliverable; nobody should care if it actually uses a blockchain and how as long as it satisfies the required security goals, right? It almost sounds like this RFP was written to describe one person's/group's existing product.
I'm implementing a DHT based on Mainline (Bittorrent) to serve as a p2p transport layer for sending asynchronous messages. Then, I want to use the Signal protocol on top of it.
https://medium.com/@thegrugq/anonymous-messaging-3032319192b...
I thought he worked for Apple now? [0]
EDIT: nevermind, I stand corrected... To make this comment non-useless, let me add to the discussion by saying that the linked DoD website is very cool. Has anyone here applied for a grant via this website (or the underlying DoD protocols)? It seems very foreign and convoluted to me, I'm wondering what the application process is like.
[0] http://techcrunch.com/2016/02/25/apple-hires-developer-behin...
Since the article mentions Signal, I think the author just wanted to make it clear that Fred's quotes come with a potential bias since he worked on Signal in the past.
But we're hiring if you want to be quoted in future Motherboard articles on private messaging! =)
This is similar to PGP over Usenet, but has the advantage of fooling traffic analysis as well.
It is actually more like dead drops, storing something secret or obfuscated in a very public place, and agents check it only every so often. Since it would just look like a giant torrent, it would be very hard to detect legitimate torrent mirroring from also pulling information out.
Only problem is still the message expiration, which I don't really believe is possible except when using a third party server.
I wish there was an easy solution to this problem but we already see how badly Bitcoin scale and there are great articles why Bitcoin with its current design can't be used in the real world simply because the block chain has a pretty low limit on transactions per second.
Does anyone have experience with DARPA projects, and if individuals can apply for it? (I'm not from the US)
Edit: My app does not use a blockchain because the data, bandwidth and power usage aren't an option for mobile devices.
DARPA wants “a public wall anyone can monitor or post
messages on, but only correct people can decrypt.”
Great related talk "Defcon 21 - De-Anonymizing Alt.Anonymous. Messages"In this case, a "perfect app" would probably be a dedicated department of human beings overseeing the ongoing development and proactive defense of whatever encryption scheme they settle on.
What DARPA apparently wants is a way to hide messages in a broadcast medium. USENET alt binary groups, PornHub, and Twitter would be suitable. It should be something that gets through the Great Firewall of China, probably.
Do those things get through the Great Firewall? Does HN?
https://en.wikipedia.org/wiki/Steganography
http://www.instructables.com/id/How-to-hide-one-image-in-ano...
If common image formats get through, then yes, there is a network broadcast format that you can use to securely communicate through the great firewall.
To their merit, blockchain based messaging is an easy way to prevent a great deal of traffic analysis.
Instead, you can use a hash of the public key for an address. That's what I'm doing for Ensichat [1]