How many petabytes of mirroring before the whole operation becomes too expensive to justify?
How many petabytes of mirroring before the whole operation becomes too expensive to justify?
I get the joke, but an Internet trained bit of code, like GPT-3, isn't what you want writing text files all over your drive.
You'd probably end up on 43 watch lists, and thrown in jail for having time travel child porn, featuring Katie Sagel and Trump in the 60s.
It takes a lot of effort to make all of the metadata also not have distinguishable patterns. See DJB's "Elligator" papers for all of the work that goes into designing elliptic curves for this purpose.
It's really a pain to have a full protocol that looks like white noise even if the attacker has millions of message exchanges to look at. I designed a protocol like that about 20 years ago, using the Station-to-Station protocol with the largest 4096-bit safe prime as the DH modulus. I couldn't use the semantically secure version of DH, because in that case, the first 4096 bits exchanged each way would always be a quadratic residue. The modulus needed to be just under a power of 256, so that even with billions of samples, it wouldn't be surprising that none of them were between the modulus and the maximum N-byte integer. For the individual messages within the stream, I needed to encrypt the message length headers, etc., etc. Even with this white noise-looking protocol, I'm pretty sure the pattern of packet sizes used by TCP to encapsulate the stream would give away the protocol being used. It just really increased the amount of analysis a filtering firewall would need, and increased the false positive rate of attempts to block the protocol. These days, TLS is so common and the pain caused by blindly dropping all TLS connections is so great, that you're probably best off either tunnelling your hidden protocol through TLS, or else making your protocol look like a TLS handshake with common parameters.
One of them knew their apartment was going to be raided by the FBI so they left a suitcase full of encrypted cassette tapes in there for the FBI to salivate over.
After finally decrypting the first one, I believe it was just static noise :)
Yes, I earned the downvotes, have at it.
Anyway this made me want to read Cryptonomicon for the 5th time and gift it to some younguns.
The original story was in a 200 ish page library book I rented in 2004 or so, and I imagine the publishing of that book was in the early to mid 90s based on the tech and artwork involved :) It was at Half Hollow Hills public library, which has since been demolished!
That sound fishy, was there any metadata to confirm it has been decrypted? That's the thing with encryption, it's just math, it won't "fail" anything if you got the wrong key, you'll just get random data back.
For example, PGP, PKZip, OpenSSL, and age all do this with encrypted files. I'm not sure I can think of a user-oriented encryption application that doesn't. Disk encryption also definitely does (although in TrueCrypt volumes the header is encrypted and not recognizable as such, so TrueCrypt is an exception, probably deliberately).
Crypto primitives in programming languages don't, and NaCl crypto secretboxes don't (they just start with the nonce!), so I guess if you were calling the NaCl secretbox encryptor by hand to encrypt your files, they wouldn't have any header.
Be sure to put he proper headers on the data so it self identifies as an encrypted file.
I really like the idea of a hacked hard drive or phone which generates a never-ending series of files containing terabytes of random data. I bet any given boarder crossing will only have the ability to scan two devices at a time, so bring a couple and you can probably shut down everything as they scramble to figure out what to do when their local storage fills up.
I realise that this is not the exact argument that i was originally making, but technical people are unlikely to rethink technical solutions without them understanding the technical barriers that limit a "solution's" effectiveness.
Most hard drives (and presumably SSDs) contain embedded microcontrollers to handle translation between the various protocol levels (USB, SATA, etc) and the raw data on the platters/FLASH cells, often running i/o drivers on top of some microcontroller-specific RTOS.
So ... surely the ideal technique would be to write a driver for the RTOS that generates a stream of data on the fly that looks like an ExFAT filesystem full of directories and email folder hierarchies containing Lorem Ipsum text? That way, it keeps feeding an unending supply of junk back to the imaging hardware (which probably isn't anything as high level/simple as "plug into a PC, mount it, and copy everything"). Yet if they open up the case and look inside, they'll see a genuine hard drive with genuine platters.
If I had to do this, I would indeed make a faked Nimbus 100TB SSD drive, but it would also be super slow and glitchy. Spit out the proper meta data, then slow random noise presented as glitchy virtual sectors. Done deal. They've surely imaged glitchy drives before. They aren't rare.
How many drives can they image at a time, and how long does it take? How many drives can they not image because yours is taking so long? That's what I would attack.
I'm wondering if it's not gonna be another 'good' reason to keep anyone they want to mess with for days. Oh sorry we can't read m2 disks we have to call the guy from the place that has the only converter. We'll keep you warm in the mean time. You didn't have a flight connection or a lawyer you wanted to call, right?
Based on prior stories I've read - trolling pissed off people with any form of Authority could end up very very badly for anyone doing this.
Aside from them just out and out confiscating any electronic device they like, they could detain you for a long period of time, they could put you on no-Fly lists (and then good luck ever flying into/within the US again), they could put you on extended screening lists (and so, every time you fly then on - again, kiss goodbye every electronic device you posess every time you travel, again). If you're a foreign national, or even if you look vaguely foreign, you might find yourself deported/denied entry/locked up for a while during the deportation process.
That's before they even get motivated enough to be malicious - I'm sure if they wanted, they could gin up enough of a case of "obstruction" or "wasting police time" if they can find any evidence (or even anything that looks like it could be hint of intention, like posting on HN), which even if it never goes to trial can still make your life a living hell, cost you your job, and a huge amount of money defending.
Or maybe they're just people who want to protect the country they live in? You can't just view everyone who disagrees with you politically as a drooling idiot.
That being said, you are of course correct.
1. Try to educate and reform the lawmakers. 2. Create a situation to bring out the absurd.
2 is often easier than 1 for the common man and has been used in many past revolutions.
Civil disobedience requires breaking the law. With that comes the possibility of being legally prosecuted. Civil disobedience requires accepting that. And in fact, a large part of the effectiveness of civil disobedience comes from the fact that people accept the risk of arrest.
But do we know of any situations where it's actually worked? My impression is that judges for some reason fight hard against its use by defendants.
I don't know of any recent examples.
(Note: this doesn't mean you should go on record with such a defense without an attorney present, just saying why it shouldn't legally be regarded as malicious without a lot of other evidence.)
For example, if I put a zip bomb on all my emails regardless of the border security but just as a general security measure, would that make me culpable if it wasn't targeted?
All hypothetical of course, because there's other hurdles to that as well like being flagged as spam in every day use.
They don't have to prove it, in the sense that you prove a mathematical proof.
They just need to agree you had that intent.
Depends very much on what is being cut, in what context, and why. Cutting chicken fillets in a kitchen to cook dinner? No. Cutting a human on the street whilst screaming 'die you bitch' probably yes.
Its not about the tool, its about how you use it.
Remember, piping /dev/zero to a compression routine for a few seconds, out of curiosity or testing a shell script or whatever, could create a file that might throw a wrench into poorly-built works.
And if you have the zip bomb on the USB drive with the intention to damage a law enforcement system, things change.
Just like you are allowed to have a gun, but you can't walk into a random place carrying a gun.
I'm sure that the diligent border patrol protecting us would find it eventually.
In theory, you'd be fighting the system.
In practicality, you'd probably end up in some black site, disappeared.
I recommend against doing stuff like this.
'never'? Rising costs is a common factor in numerous cancelled projects, at least in the UK defence market that I'm familiar with.