How Bin Laden Sent and Received Email
news.yahoo.com
news.yahoo.com
Even that isn't so spectacular though, considering this is someone dedicated enough to his cause to successfully plan and execute terrorist acts as a career.
1) Bin Laden sent e-mail. 2) He sent it via a very simple if slow method. 3) The US has these e-mails including the receiving address.
Why would they publish this tipping off their targets? Why does the official require anonymity?
A nasty thought does occur which is that this makes an excellent reason for governments to insist that ISPs and email providers hold all emails indefinitely for future investigations.
It was a slow, toilsome process. And it was so meticulous that even veteran intelligence officials have marveled at bin Laden's ability to maintain it for so long.
Really? Really? It's still more efficient than traditional post, and I'm guessing there wouldn't be this level of hullabaloo if that had been the mode of communication.
For how long did he really used email? The answer is probably anything from zero years to five. Like you said, looks to me that the system he was using was a faster and more efficient system than the classic pen and paper he used all his life.
(From what I remember, they were merely writing messages and saving them as drafts. Then others would log on and read the drafts. No emails were sent.)
Interesting though how much he relied on couriers.
For personal reasons, I do not browse the web from my computer. (I
also have not net connection much of the time.) To look at page I
send mail to a demon which runs wget and mails the page back to me.
It is very efficient use of my time, but it is slow in real time.
http://article.gmane.org/gmane.os.openbsd.misc/134979Also elsewhere he says that he rarely has an active internet connection, so presumably the demon runs and mailserver flushes during the window that his internet is on.
AFAIK, going wayyy back, this strategy was first talked about by Sophsec at an infosec conference in 2006. They made a library called libomg that would log into social networks and webmail to communicate with infected bots and they had various strategies for doing so. The most hilarious was the myspace module which automatically set up networks of teen girls who chatted in uh teen-speak, which were actually hidden commands for the other bots to log in and retrieve. It was awesome.
The most hilarious was the myspace module which
automatically set up networks of teen girls
who chatted in uh teen-speak
Makes sense - teen-speak barely means anything and it's frustrating as hell to read, so normal people usually turn away before starting to see suspicious patterns.Much easier to just create an account to send just one email and then delete the account (after it is sent), or just never use it again.
That being said, I probably wouldn't use encryption anyway. I wouldn't do anything that might cause my correspondence to receive any further scrutiny whatsoever.
For all of HTTPS's faults, it's so transparent that you don't even think of it as encrypted communication. If PKI apps and MUAs didn't suck so much, we'd probably all treat email the same way.
This is why a criminal tries to act and behave just like you, a non-criminal, so they mix in with the crowd and get attention off them so they can engage in what they do best, jumping jacks and monkey bars. ;)
I dramatically adjusted down the amount of reasoning I thought the 'average' person is capable of over the months that I tried to explain / convince him. It's very well possible that I wasn't able to explain because I don't fundamentally understand myself; but even all the 'circumstantial' evidence couldn't convince him. And that was from a person who, statistically and objectively speaking, is at least above the median in intelligence and thinking power.
India and China, who don't care about personal privacy as much as the US, gloat about doing this all the time, often to US companies' data. The US gov't does have the right to wiretap and snoop under the Patriot Act, but it does not have to have the luxury to share with the American public because Americans value privacy highly.
The person sitting next to you in these cafes can barely read, the PCs are what was mainstream here in 1999. They are connected with 56k modems. I am not sure why you're struggling with getting out of your shoes.
Watch this champ: http://www.youtube.com/watch?v=kUEGHdQO7WA
Do you have any basis for this belief?
“Do you have any basis for this belief?" Want me do YOUR research for you? You claimed the solution is HTTPS (or encryption in general), I said no, and you want me to prove the objection?
Anyway, aside from the fact that I was born and raised in Pak and lived there till I finished high school at the age of 17, I know what they do online and know the culture intimately, and understand how vast the tastes and interests are when income and education levels are so varied. The ISPs there are regulated, sites often blocked, and govt openly and proudly snoops (like I have said many times before).
Now before you tell me to look this up for you, do your own research, please amigo! You might be a great "mechanic" but you’re trying to drive a Ferrari in a rally, and arguing "Why not, its the greatest car!" Context is everything. This is getting tiring, boring and old, you take yours, I take mine, and off we go. :-)
Also, get a passport and travel a bit, you'll notice how invisible some things are to you in your environment, and how much you take them for granted. How many facts of life are not facts but assumptions.
It's also a little grating to have you lecture me on my assumptions, whilst simultaneously making unfounded assumptions about me.
Anyway, they did not overlook the oldest security technique in computer history (encryption/cryptography) without reason - and you gotta give those fuckers credit, those mountain goats gave the most powerful military in the world a run for its money for a decade.
That said, you're right that they're extremely good at hiding via more conventional means.
No it doesn't, that's the whole point.
The universe contains about 2²⁶⁵ elementary particles and has existed for about 2¹⁰⁸ femtoseconds. So it probably cannot have done more than about 2³⁷³ classical computations. You can easily use triple-AES-256 to get an effective 512-bit key, dwarfing the possible computations the universe can have carried out for the foreseeable future.
The world GDP is about US$58 trillion per year, which is about 2³⁶ dollars per year. A computer that can test keys currently costs at least 2⁻⁸ dollars, although probably more, and cannot test more than about 2³⁵ keys per second, although probably less. There are about 2²⁵ seconds in a year, so that's 2⁵⁰ keys per year per processor, or 2⁹⁴ keys per year per previous year's worth of production.
So, suppose the entire world economy were devoted to producing computrons to crack a single crypto key. In N years, you can have tried ½N² · 2⁹⁴ = N² · 2⁹³ keys.
To try 2¹²⁸ keys, you need N² ≈ 2³⁵, so N ≈ 2¹⁷, a bit over a hundred millennia. (If you are willing to accept some chance of failure, say a 99.9% chance of failure, then you can skimp a bit and only try 2¹¹⁸ keys, N² ≈ 2²⁵, N ≈ 2¹², only four millennia.)
If bin Laden used AES-256 instead, you need to try 2²⁵⁶ keys to be sure of succeeding, so you need N² = 2²⁵⁶ / 2⁹³ = 2¹⁶³, so N ≈ 2⁸⁰ ≈ 10²⁴ years, which is 10¹⁴ times the current age of the universe. By comparison, the galaxies of the Local Group are expected to merge into a single supergalaxy in only 10¹² years while other galaxies are too far away to be detectable, star formation is expected to end in only 10¹⁴ years, all planetary systems are expected to have decayed in only 10¹⁵ years, and the supergalaxy is expected to have fallen apart in only 10²⁰ years. We're talking about a timescale ten thousand times longer than that. (http://en.wikipedia.org/wiki/Future_of_an_expanding_universe)
So the mere computing power of the TLAs is unlikely to yield results by brute force. Their ingenuity, however, could find a better way than brute force.
Large amounts of money can and do buy the time of legions of sharp mathematicians who devote their lives to devising and cracking new cryptosystems. There are good reasons to suspect that this no longer gives the US government the kind of advantage that it used to enjoy, but hard evidence of that is also hard to come by.
There's also the possibility of using large amounts of money to trick someone into using weak encryption, a policy which was very successful with Crypto AG.
Better to send scattered, seemingly innocuous plaintext messages, if the insidious information is coded well enough to look like normal conversation.
If you encrypt all your email, they just have to log every piece of encrypted mail they see and wait until they find the key to open all of them. If you do it the smart way, they have to hunt for each individual message, and you win the "security arms race".
I presume using rendition and rubber-hose cryptanalysis?
Of course, you'd have to use a non-networked computer for this, in case Truecrypt phones home...
[i am disappointed the article doesn't even mention that kind of detail; never mind describing how they avoid traffic patterns (presumably they have protocols for changing email addresses, times and subjects)]
This is excellent observation, especially as so much of the justification for limiting, restricting, or circumventing encryption on the part of intelligence agencies has been that "terrorists" would employ it to communicate.
It's probably better for attempting to elude the NSA, as well. Get lost in the mix, as opposed to having big large red flags in your messages.
(Lots of people have died because of inadequate training in these areas. Eastern Flight 401 is a good example: http://en.wikipedia.org/wiki/Eastern_Air_Lines_Flight_401. The crew was so busy debugging a faulty light bulb that they forgot to fly the plane. It crashed into a swamp.)
(This, BTW, is why I am generally against anti-piracy enforcement actions and warantless wiretapping. When you force normal people to use strong cryptography and VPN providers or mesh networks, the terrorists are much harder to pick out. They just look like kids downloading movies.)
Without some other security steps, like VPNs or proxies, the US would have certainly been able to trace the country of origin of these communications.
Cryptography doesn't do you any good if there are guys with a car battery asking you very pointed questions, like "where did you get this encrypted disk"?
With MicroSD in your mouth, they wont even get the idea to question you.
apparently he had a number of trusted couriers, and judging from what I have read on tracking these couriers down[1], it wouldn't surprise me if he had multiple levels of courier for his email
[1] apparently the couriers were so good at counter-surveillance that even when the CIA had tracked one of the brothers down to Pakistan, it took them two years to link them to the compound, since they both took exhaustive counter-intelligence measures to make sure they were not tracked. amazing story