There’s a PGP signature, but as far as I’ve head the attackers didn’t leave behind any other messages to prove it was signed with the same key.
There’s a PGP signature, but as far as I’ve head the attackers didn’t leave behind any other messages to prove it was signed with the same key.
The message is PGP signed. If the protonmail address is taken down, then another message will be put out with alternate means of contact that will have a correct PGP signature.
If you read the message there is indeed an onion address as backup in case things get taken down.
The PGP address is the important part. No matter what gets taken down, if they can get attention to another message with a valid PGP signature, then they can carry on easily.
EDIT: This is actually how Cicada3301 of all people operated. The PGP key allowed them to post a message even on Pastebin or /x/ and they would still be contactable and effectively uncensorable, because their identity was persistent and their messages were replicated.
A way to do it for example would be to use a stolen credit card to subscribe to a few VPN with hops on Tor in between and use that to set up a VPS that puts this up after a few weeks
The devil is in the details, but if you're careful you can leave absolutely no trace.
Source: https://support.torproject.org/faq/staying-anonymous/
Interacting with a tor browser would be amateurish at this point. Just connect to tor (not on a browser, tor directly), use a script to upload to some random pastebin, disconnect from tor.
Note that, for example, your isp can see whenever you are using tor or a VPN. From there, they can inspect the packets to work out what pastebin you have visited. Eg. simply by measuring how many bytes you have uploaded and then finding the paste and comparing the length of the paste with the number of uploaded bytes. (Just a basic example, there are more advanced methods). See https://witestlab.poly.edu/blog/de-anonymizing-tor-traffic-w...
This is why you don't actually post anything on pastebin yourself.
Rather, you SSH into a VPS (via multiple VPNs and Tor/I2P), then program the VPS to post your message to pastebin in a week.
And of course, you're not doing this from your home, you're doing this from the parking lot of a Starbucks in a car with tinted windows and fake plates, using a device with a spoofed MAC address.
There are many ways of pulling this off so that no one will ever be able to pin you down. You just need to pay attention to detail.
You're of course using some sort of obfuscated bridge too, so that packet sizes become meaningless.
Some examples where it could go wrong: what if the VPS was a honeypot? What if the VPN logged everything? What if Tor or other piece of software they are using has a 0-day? The more complexity, the more chance for a bug or mistake... and so on...
That said, a VPN logging everything, or Tor being compromised, or the VPS being a honeypot wouldn't be enough to compromise you, you'd need all of them to be true simultaneously.
Randomized MAC connecting to a MacDonalds free WiFi, cameras capture a masked guy in a hoodie or black Cutlass with unreadable plates. Now what?
Plenty of ways to be untraceable unless there is a spook at every hotspot, instantly notified of undesirable activity.
There actually isn't much attention on replacing PGP with anything specific.
What other completely decentralized alternatives exist with no single point of failure? libsodium? That's a good start but a long way from a complete alternative.
Plenty of quasi-centralized encrypted chat "apps" keep pretending they offer what PGP offers. The clueful ignore these gesticulations.
The closest I've found is using openssl's aes modes, but that requires the IV to be stored out-of-band somehow which is a do-able but a hassle I was hoping to avoid.
You can't verify a signature without a public key.
If you want to have a go at it yourself, run gpg -vv and paste the entire message, it will give you the public key.
You can change part of the message or the encoded fingerprint (which is a bit longer than the portion you pasted), and it will still report it the same way.
However, you will not be able to mathematically verify that this message and another one was signed by the same key.
If you look carefully at what GPG is telling you, probably see a line like this, unless you have the key in keyring:
gpg: Can't check signature: No public key