Riffle: an efficient communication system with strong anonymity
dspace.mit.edu
dspace.mit.edu
I know where you're coming from but I don't think this is the case. There are too many examples to give but here are some nice ones:
In 2013, there were only a small number of E2E encrypted messenger users. Now there are over a billion Signal Protocol users alone, not even including other systems. This isn't getting deployed because it's easier to develop, support, or use than plaintext.
In 2013, RC4 was widely used in TLS and random number generation (on BSD systems). It has been kicked out and now ChaCha is seeing wide deployment in the same places (although FreeBSD is lagging behind).
Let's Encrypt has substantially increased TLS availability and usage.
In 2013, the default crypto in OpenSSH was (IIRC) P-256 and AES-CTR, with ECDSA host keys. It's now X25519 and ChaCha20-Poly1305 with EdDSA host keys.
In 2013, TLS was mostly RC4 and CBC. Now (on my servers) it's mostly GCM and ChaCha. Even the IETF has said to stop using RC4.
The NaCl family, including in particular Libsodium, has a TON of users. Besides supporting only strong crypto, the high-level API has made it almost impossible to publish a successful new crypto library today that's in the style of OpenSSL where the only answer to "how to I accomplish X?" is "go fuck yourself." Good riddance to Russian roulette crypto libraries.
We're even seeing movement in pqcrypto. So while some people are being reactive and switching out bad crypto for good (as in above examples), some are being proactive. Google is experimenting with pq-safe key agreement, as just one example. Tor is working on it as well. So not only has there been a positive reaction since 2013, but people are beginning to be more proactive as well, trying to stay ahead of the curve.
The number of users of strong crypto has increased by several billion since 2013.
This doesn't mean much, in my opinion. It might stop several thousand teams of garage hacker heroes but it's hard to argue it would stop NSA / GCHQ / anybody else on their level.
With all of the leaks (good chunk of them are just theories, admittedly) that claim that agencies can utilize hardware backdoors remotely, it's hard for me to imagine I am safe from snooping, ever. What good would a stronger SSL/TLS key do if the agencies can directly connect to my CPU? What good would a strong VPN and a network like Tor do if my NIC reports my traffic via a backdoor in its driver without a chance of me ever noticing?
I definitely agree some progress has been made. No two opinions about it.
I do question if these countermeasures achieve anything at all against the biggest and most formidable snoopers however. I feel like they are letting us argue over things they've cracked long ago and are letting us think we're safe.
Usually when public statements are made by them which try to smear/outlaw a technology, it's then I'd think the agencies are having a hard time. If they don't say anything, I'm presuming they got things well under control and where they want them to be.
Not the ideal theory but all of this reply was just my thoughts anyway. If I had any facts whatsoever, I'd most likely be in a prison, so there's that. We can mostly only theorize here.
But you're right that endpoint security is the next monumental task and the challenges are not entirely unknown [1]. How do you suggest we proceed to achieve trustworthy hardware?
However, projects like Raspberry Pi are admirable and are efforts in the right direction (even though recently it has been questioned if it can be hacked the same way that Qualcomm-based Androids can). I recently heard about that 1000-core CPU as well. I wonder if that's entirely public? If it is, it might render the x86 / AMD64 model irrelevant so we shouldn't spend gigantic efforts in trying to catch up with 10-15 years of hard work from Intel.
So probably the general direction would be to make old and good hardware protocols famous by trying to "libre"-ify them and bring them up to speed to today's computational requirements (mind you, I still want to play my games on Ultra settings). Even if we start replacing things one by one, every iteration could decrease the attack sufrace. That'll force the malicious actors to take counter-measures; for example, I'd think trying to outlaw ARM (or economically attack its usage, which is the much more used way of doing things IMO) and only license Intel/AMD for certain applications would be a telling sign that somebody doesn't like what's happening.
I am not a hardware person (wish I was; I am not even electrical / electronical engineer!) but I am a privacy-conscious person, and quite paranoid too. I am sure there's a way but alas, I can't answer you in as constructive manner as I'd want to. I can only do a "boss speak" and be oblivious to the details. And at 36 with a well-built career I am beginning to doubt I'll ever try and become a hardcore hardware engineer in addition to my programming/sysadmin experience.
My apologies if I wasted your time reading this.
EDIT: btw, the linked article is scary....
I guess their project has been really successful if “privacy-conscious” and “paranoid” persons consider it “admirable” based on nothing but the internet hype.
What would you recommend in terms of a really "libre" hardware?
The question is not whether some proprietary solution looks “free enough” if you squint your eyes more than the other proprietary solution. The question is whether people understand that chain of trust that ends in someone else's hands has its problems no matter how big that someone is, and bother to fix that vulnerability.
Performance is definitely a difficult sacrifice. Consider however that your general computing could be split into a privacy sensitive component: sending emails/messages, assembling documents, banking website, etc, and a privacy insensitive component: compiling OSS, playing games, etc. Composing/sending email for example is not computationally demanding... so one might use a high performance Intel machine for insensitive computing and a lower performance libre machine for sensitive work. It's not perfect (web browsing can be both private and not, and demanding and not) but a refinement of this separation approach could be an interim solution until high performance libre hardware is available.
Would the developing J-Cores[0] being worked on by 0pf[1] be able to catch up (I'm thinking more along the lines of performance of recent mobile processors, not desktop processors)? I am under the impression that, while a monumental task is ahead of them, they have the boon of hindsight. Of a dozen processor architectures competing back then only a handful survived the decade and only 2 or 3 are being fabbed now (i386/amd64, ARMvX, and IBM?) and they can base decisions on the successes and failures of other chipsets, speeding up the development process. Is that fallacious thinking?
I know most of their goals are along the lines of getting custom fabs down to $20k and making the term "penny processor" a household term, but is there potential (read:hope) for a secure, performant (whatever that means to you) processor that we can use for daily computing without fear of a hardware-based backdoor?
Phil Rogaway called it 'elegant', fwiw.
Granted, the second sentence leaves open the possibility that perhaps all users aren't required to upload a message, at the cost of increased susceptibility to analysis, but I don't think that's really intended: worst-case, there's one client message per round, which provides no real anonymity against the client's primary server.
I'm not putting it down, really: Riffle is a remarkable achievement. Sadly, it appears that anonymity is really, really hard to do truly efficiently.
I also wonder if the presence of distinguishably-mandatory plaintext messages could be used within an epoch, particularly with respect to the previous point. E.g. maybe knowing the the same client was active in rounds 1 & 2, the inactive in round 3, then active in round 4, then inactive in rounds 5 & 6, then active in rounds 7 & 8 could be used to identify the client (imagine a low-latency system, and keystroke timings or voice packet lengths).
So I wonder if this will be updated.
This is not a general-purpose mix network.
Is it?
For a certain subset of societies that suppress information and views, anonymous communication becomes more important. Enabling more voices is in essence making the society more democratic (or leading towards).
In addition, if you look at what's going on in Poland[1] at the moment, then you could very well argue that a popular service that can't be censored would help present a more balanced view of what is going on.
From that perspective it becomes a safeguard to prevent slipping, even if things are sailing along fine at the moment.
[1]: http://www.independent.co.uk/news/world/americas/barack-obam...
After some bogus FOIA redactions and misinterpretations, I submitted a Request for Review (RFR) to the Illinois attorney general's office who refused to continue without a signature with a valid first and last name to associate the RFR to the original FOIA request.... even though my first and last name weren't actually on any previous requests (their argument made no sense, especially with ESIGN in mind). My lawyer even told me that it would be a waste of time to fight it and to just accept it - since a lawsuit would very likely require my name anyway. Or alternatively give up on the request.
Since my writing style stand out like a sore thumb, staying "anonymous" seemed pretty silly going forward, so I stopped. These days, I feel naked when submitting a request and in a lot of ways, it definitely feels like it does limit certain types of requests. If anything, my requests are a little bit more agitated - I definitely no longer have the same peace of mind as before.
Secret ballots are probably indispensible for democracy, but it is debatable (note I said "debatable") whether anonymity is necessary for freedom of speech and democracy. After all we've had many revolutions and regime changes in societies past where there was no anonymity of communication. Now arguably you could say that said regime changes might have occurred with less blood had anonymity been available, but then it is also arguable whether anonymous communication is anything like as forceful and persuasive as someone prepared to risk themselves by taking a public stance. IE we could argue that anonymous stances would not have created the regime change in the first place.
A whole bunch of avatars screaming a slogan is not persuasive.
Pre-internet, this was accomplished in many ways. Secret meeting groups, anonymous newsletters, etc. With modern communication and data collection, it is much easier than ever before to know who is talking to who. If a government always knows who is talking to who, it becomes much easier to suppress detractors.
I didn't say that, I was talking about the value of anonymous communication in a democracy. Surely voting is a form of communication.
In the US, police accountability activists may find additional civil offense summonses on the windshields of their cars--even when parked in their own driveways. That is childish and petty harassment, and the forms of retribution can be much worse. Various regulatory agencies have been used to attack political opponents, such as IRS audit rates showing a marked difference between supporters and non-supporters. EPA may demand more land use restrictions on owners with less political strength.
It is very important to be able to tell other people about your grievances without fear of someone saying, "Oh yeah? If you thought that was bad, just wait 'til you see what you get for blabbing about it!"
If you're still not convinced, ask Publius[2].
[1] https://www.indexoncensorship.org/2014/01/five-activists-pun...
Anonymous communications are the same thing. Pretty much all civil rights are born out of law breaking: A black and white person marrying, someone drinking beer (prohibition), people having homosexual sex. If all statements required an identity attached to them, no one would be able to anonymously campaign the merits of their ethical lawbreaking to advance social mores.
Edit: I'm too afraid of the downvotes to take responsibility for my speech.