Either
A. Popular and well known encryption algorithms are not broken by the NSA, and your communication is private.
B. Popular and well known encryption algorithms are broken by the NSA, but the fact that it's broken is top secret and the state will not do any actions that revel the secret. Your communications are not safe, and while what you communicate might make you the target of an investigation (if you're an appealing enough target), the communications will not be directly used against you in court.
EDIT: There is a third option, that your communication is being stored until the encryption algorithm is broken or computation reaches a point where brute force is possible (quantum computers). Long term storage of encrypted communication is only economically feasible for a small subset of all encrypted communication, so it's only a concern for targeted individuals where the communication will be relevant to the state decades from now.
IIRC, the signals intelligence agencies like the NSA learn almost as much from traffic analysis (e.g. who's talking to who and when) and metadata than from actual message content. Mere encryption itself often doesn't protect much from that.
Isn't metadata, practically speaking, a subset of content? (If you have the latter, you almost certainly also have the former?)
Metadata is more useful than content if you're capacity constrained, technologically or legally, in collection and/or analysis.
Importantly to how we think about communication, no.
Metadata is the signature that accompanies or encapsulates content, viewable to the world. You can completely conceal content, through encryption for example, but you can't completely conceal metadata.
In other words there must be a physical exchange of energy somewhere (communication), and metadata tells you something about how the exchange happened, irrespective and ignorant of what the content is.
You can do it with a very high cost (in overhead, latency, and availability) by having a large number of people all send and receive messages, on a fixed or randomized schedule, exceeding their maximum possible amount of communication with one another. Then someone monitoring the network knows that each of the participants in this system could have communicated with any other participant, but not whether or not the communication took place.
The bottom line is that you are going to leave a signature of some sort through communications - the question is, can you properly build a comms system system that is functional within the limits of your risk/reward criteria.
To eliminate the statistical observability of metadata, the padding needs to reach or exceed the maximum capacity of the channel. So you can't have people sending more messages than the padded channel permits per time period. In your example, packets "with variable length/size content" would need to be absolutely prohibited, or else all packets' length would need to be randomized, and message data would need to be sent following strictly the same distribution as padding messages.
For example, you and I could have a rule of exchanging exactly 1 MB of data per day, at a specified time, every day. Then an observer wouldn't be able to tell whether, on a particular day, we had actually communicated something to each other or just allowed the padding data to go out. Clearly in this system we're not ever allowed to use it to transmit more than 1 MB per day, without destroying the metadata unobservability property. An attacker still knows that you and I are part of a system that offers us an otherwise unobservable channel, but not when we do or don't make use of that channel.
There are lots of variants that also allow many-to-many messaging, again at a high cost in overhead, latency, and availability.
> For example, you and I could have a rule of exchanging exactly 1 MB of data per day, at a specified time, every day.
Depending on the size and popularity of the relay network, the fact the two parties are connected to it could be valuable metadata.
If you really wanted to minimize the amount of metadata to something that's almost useless, you'd probably need to use something like a continuously-operating broadcast numbers station.
My hunch is that it wouldn't be possible, and there would be a side-channel vulnerability somewhere.
Edit: the beginning of this research is the Dining Cryptographers.
https://en.wikipedia.org/wiki/Dining_cryptographers_problem
Although Chaum's solution has terrible availability properties, it's unconditionally secure against outsiders!
You're also not ever allowed to transmit links or anything else that goads the user into fetching a remote resource in response to a message.
Directly. But via parallel construction...
I wish judges and defense attorneys would catch on to these tactics more quickly. The rate at which the prosecutors/FBI invent new tricks to fool the courts and defense attorneys so far seems to far outpace the judge and the defense attorneys' understanding of what's even happening.
Take cell site simulators, for instance - the FBI has used those in secret for more than a decade before they were uncovered at all, and then it took another decade for judges here and there to catch-up and start requiring warrants for such operations.
And this goes for a lot of FBI's "investigative techniques", too, which are often illegal, but what judge is really going to know the difference between those highly technical operations?
Is there a tech-law publication which targets judges and defense attorneys?
I feel otherwise.
When Microsoft was about to be broken up an appellate judge overruled the prior judge. That judge went on to be the FISA secret court judge.
Remember that the NSA Key was discovered around the same time[0].
So Microsoft was in bed with NSA prior to 1999 with a crypto key backdoor.
They were helped by an future FISA judge.(Does that background look like a national security judge?)
When I look at the Judges resume I can help but to wonder if she was an NSA plant the whole time.[1]
The Commerce Department is a frequent cover for the NSA.
I have to assume they use deep cover people all around us.
[0]https://www.heise.de/tp/features/How-NSA-access-was-built-in...
Bigger in this case is the pattern of life rendered by just inspecting headers. And they can get a lot of headers sitting on these ATT locations.
That assumes metadata is irrelevant. The destination, time of day, and volume of the traffic all have value separately and especially so when together. The destination can be masked if you control both sides and AT&T is a go between, but timing issues are subject to analysis unless you are a large enough player to give safety in numbers or you push noise across your pipes.
Just decide how thoroughly it must be done, and do what it takes. Plus a safety factor.
Please tell me how i anonymize the metadata of where my cellphone is located, which the telco harvests from towers its connected to.
If you really care, one option is having multiple phones, under different identities. Each one only gets used in a distinct set of locations, for distinct projects, with distinct recipients. When not in use, you store phones in labeled Faraday bags. That is, compartmentalization.
Another option is to nuke the radio in your phone, use only WiFi and VPNs for internet access, and use hosted cellphones from multiple providers. You can still compartmentalize, but need only carry one phone. But you depend on WiFi access.
"It said the BND, a partner of the US National Security Agency (NSA), has placed so-called Y-piece prisms into its data-carrying fibre optic cables that give it an unfiltered and complete copy of the data flow."
https://www.thelocal.de/20180531/german-spies-can-keep-monit...
I'd really like to see CDNs like CloudFlare start requiring Cloud <--> Origin encryption; e.g. what CloudFlare calls "Full SSL" -- https://support.cloudflare.com/hc/en-us/articles/200170416-W.... Right now, you can do TLS termination ("Flexible SSL"), which end-users aren't aware of -- they see a padlock -- and I'm sure the NSA doesn't mind.
Granted, like FB issues and others, we in this community need to realize that most users simply don't care (even many b2b ones) and not get upset when our users don't move their dollars on principle. For us it's a big deal, for many there are real, harmful issues going on in the world and volume collection of data by companies and governments is not one of them. And we can't make it so despite the deluge of articles by a supportive mass media.
EDIT: To clarify, you mentioned "other ISPs" but I want to be clear I'm talking about private pipes and not residential internet though I know they are often shared.
They do. They work with all of them.
http://www.businessinsider.com/the-story-of-joseph-nacchio-a...
AT&T just happens to have the oldest relationships and the largest infrastructure.
Which sane people call Man in the Middle and should not be allowed at all. I have seen people doing this Flexiable SSL with Credit Card data and other PII believing it is "secure"
Cloudflare may have started out with security in mind but their new services centered around centralization of key services (dns) and this kind of security breaking product means IMO they are a net negative in the world of Information Security
It's an easy box to check to pretend to offer HTTPS so you don't get penalized by Google. Before Let's Encrypt there was no free way to get a legit cert for your cat blog. Faking it via Flexible SSL was the next best thing.
Furhter before Lets Encrypt you would not have gotten dinged by google, Google only went that path when wide spread DV Certs where freely avaliable
Further still, the minor costs per year to get a paid DV cert should be factor when choosing to host your own content versus paying a 3rd party to do it, many of those 3rd parties provided SSL as part of their services.
There is zero need for a Man in the Middle for SSL,
Yes, but they could also be lying about it.
Hell, this is pretty much the norm where MPLS is concerned. Your packet may hop through a dozen routers along its way without showing up in a traceroute -- you just see it go in one side (then it goes through a dozen routers) and you see it come out the other side.
Wouldn't be trivial for any other telco (whether foreign or domestic) than at&t to tap the data and lie about it too?
And it doesn't have to show up in the traceroute (they could mirror the traffic, etc)
At a proper one a single IP address belonging to the exchange, which will be assigned to the router port of one member, is only allowed to appear from a specific single MAC address, and specific port on the ix switch, which corresponds with a physical fiber cross connect that matches a specific patch panel port.