Confirmed: All Wikileaks Cables to be Released in next 24 hours
wikileaks.org
wikileaks.org
Also, what was Assange thinking? 'Oh I'll just give these people the material, we can trust them?' And the notion that journalists, many of whom are as technologically illiterate as they come, would store these files on a computer not connected to any network is so naive it's not even funny anymore.
That's what people were saying about the Afghanistan and Iraq log leaks.
There are a million dead, at least, many of them with holes made by US (and allied) munitions, and you're quibbling about a few who could be threatened, in what has actually been by far the largest and safest (innocents/dictators hurt) release of classified documents EVER.
This is serious stuff, stuff worth having posted everywhere, spammed to everyone, SMSing to every phone in the world, etc, on the chance that one copy would get through and let one journalist write one good expose. That it's been managed so as to have a groundbreakingly huge ratio of exposes written to actual data leaked is a stunning testimony to their delicate and thoughtful handling of the media organizations. What we see in North America and the EU is just a shadow of the literally world-wide (and now, hopefully, world-wise) fallout from these leaks.
Irresponsible ego tripping and deluded transparency advocates indeed.
You can read the Guardian's rebuttal here:
http://www.guardian.co.uk/world/2011/sep/01/unredacted-us-em...
Guardian's quote:
"Our book about WikiLeaks was published last February. It contained a password, but no details of the location of the files, and we were told it was a temporary password which would expire and be deleted in a matter of hours.
"It was a meaningless piece of information to anyone except the person(s) who created the database.
"No concerns were expressed when the book was published and if anyone at WikiLeaks had thought this compromised security they have had seven months to remove the files. That they didn't do so clearly shows the problem was not caused by the Guardian's book."
"According to Der Spiegel: At the end of 2010, Domscheit-Berg [former worker at Wikileaks and founder of rival, OpenLeaks] finally returned to WikiLeaks a collection of various files that he had taken with him, including the encrypted cables. Shortly afterwards, WikiLeaks supporters released a copy of this data collection onto the Internet as a kind of public archive of the documents that WikiLeaks had previously published. The supporters clearly did not realize, however, that the data contained the original cables, as the file was not only encrypted but concealed in a hidden subdirectory."
So The Guardian deliberately leaked the password and Wikileaks accidentally leaked the file. Personally, I think both sound like pretty stupid things to do ...
That's a pretty bullshit excuse. Wasn't the insurance file on PirateBay? How exactly should they have removed that once it was out there?
Presumably (hopefully?) the insurance file uses a different password. I was also under the (perhaps wrong) impression that no-one actually knows what's in the insurance file.
It's quite odd. Certainly Assange is quite technically savvy -- he's a reformed (genuine) hacker -- after all. So I just can't imagine him re-using passwords. Similarly, I would have thought that he'd be enough of a control freak to, you know, check this stuff out himself.
Does it mean that he does not black-hat hack anymore? Or that he does not "hack"?
How do we know he does not "hack"? maybe he doesn't do it publicly but he still "hacks" to his OSX/Linux box.
So a reformed hacker in my books is someone who no longer illegally hacks into property that is not theirs.
In "Hacker News" existed a decade+ ago then it would have been filled with black-hats.
There are some interesting considerations involved in what this means for distributing highly sensitive data to non-technical people. They apparently have no comprehension that a PGP-encrypted file is not like a web service where you can just go in and change the password in a jiffy -- as long as that file exists, the same password will work on it, forever. The rebuttal quoted indicates that WL said it was a "temporary" password, so it seems that via a misinterpretation at the Guardian, its editors expected the password to stop working on that file in a matter of hours.
It would be really interesting to see PGP files that were time-sensitive, and used passwords that only worked within X time. Does anyone know if something like that has been done?
What would have been a more secure way to distribute the archive? Only bundle 1000 cables at a time, each file with a unique password? Require journalists to view the files on premises at WL so that there was no loss of control on the data? Bundle everything up in a black-box .exe that self-destructed in x time (though, unless implemented carefully, this would still reveal private data once a competent person got a hold of it)? Why weren't these files asymmetrically encrypted anyway? Surely it is not very likely that the private key of a user would be published in a book or that a user would upload his private key to bittorrent. Lots of interesting possibilities here...
You'd need some sort of physical real-time clock combined with the memory storing the material, which wipes it after a given time. Maybe even a physical medium which degrades over time[3] could work, but that could be foiled by controlling the environmental conditions (inert gas atmosphere to avoid oxidation, cold temps to slow electron migration, etc).
There's a couple of interesting physical-security related links in a comment of mine from the other week: http://news.ycombinator.com/item?id=2932492
My personal approach would be something like providing an incredibly locked-down laptop/netbook (https://grepular.com/Protecting_a_Laptop_from_Simple_and_Sop... would be a good start), but with additional physical security improvements (battery/big caps wired directly to HDD and RAM via a set of tamper switches[1], disabling all IO ports in software and filling them with epoxy / disconnecting internally) You could then wire in an RTC to the same system, as well as perhaps using a GPS receiver to verify the time (Yes, you could jam/spoof GPS signals if you knew to expect them, but that's still raising the bar).
One final approach would be to have some other trusted party/system which remains in your control, and have some challenge/response auth which you can disable/destroy after a fixed time.
To conclude, I can't see any way to build time-limited encryption without some external trusted authority or some trusted physical infrastructure.
[1] Not just physical switches, but as many things as you can come up with: Light sensors, pressure sensors (especially if you can gas-seal the enclosure and keep it at elevated/vacuum pressures), temperature to avoid cooling attacks, resistive/optic-fibre security meshes. Another amusing idea would be to use a GPS receiver to ensure that data can only be viewed from a given physical location[2].
[2] This gets used in _Distress_ by Greg Egan, although I'd thought about it myself long before reading the book.
Edit:
[3] I just remembered about Flexplay (https://secure.wikimedia.org/wikipedia/en/wiki/Flexplay), which was a DVD scheme based on oxidation to time-limit their use as one-shot rentals.
The key is to have lots of problems nested together, which must be solved in series.
Computers scale a lot better than people, so something which required a human to try to solve a puzzle to get a key, then use that key to decrypt the next puzzle, and so on, probably has better characteristics.
A trusted third party or tamper-resistant hardware is far more practical.
Alternatively, this dongle could contain the necessary private key to decrypt the file instead of the data itself, or another component required to unlock the data a la RSA SecurID.
I would be greatly interested to see relatively secure self-destructing USB sticks.
The first guy was right, it's impossible. Certain very narrow bits of it could be accomplished, but not any real-world goals anyone could have.
The Guardian was operating under a grievous misunderstanding about the nature of the encrypted data, but from my vantage point I don't see that they operated out of intentional malice. If you are distributing data to compliant parties and just want to ensure a tidy cleanup to prevent mishandling or theft, something like this definitely could be useful.
I'm not a cryptographer, but it seems to me like something of this nature is impossible without maintaining control of the decryption process. You could add a timestamp to the file, but the workaround would be to change your computer's clock or rewrite the decryption software. You would have to include a cryptographically-signed timestamp from a trusted time server in the en/decryption process. Once that signed timestamp is obtained, though, it could be distributed along with the password and a modified application that uses the stored timestamp instead of a live one from the server.
My knowledge comes from reading about failed DRM schemes and the comments of tptacek and cpercival, so I can only point out things that wouldn't work, not what will.
You could also make decryption dependent upon a network connection (e.g. Adobe DRM, et al.), but with "the opposition" potentially in control of the network and/or able to compromise you physical security, and with the decrypted results readily copy-able (they always are, one way or another), this is probably more trouble than it's worth.
P.S. I didn't mean actually Adobe DRM; rather, just citing them as an example instance of such a thing (though, truth be told, I've never looked at how they do theirs, in detail).
There clearly is a need for a competent whistleblower website. Wikileaks has shown itself to be incapable of filling that role. Egos shouldn’t be more important than leaks.
Pretty disgusting how this entire press release amounts to political posturing and taking credit for the Arab Spring, with, what, one sentence about how terrible it is that names are now being released unredacted?
You can argue that Wikileaks isn't the one ultimately responsible for this, that it's the Guardian or the US government or whatever, but in their response they seem almost totally unconcerned with protecting individuals, and overwhelmingly concerned with getting credit for political revolutions.
Remember though, that the USA shared more information with the worst of these dictators, till close to the end, than the leaked cables reveal in total. This whole FUD about Wikileaks killing whistleblowers is just a smokescreen. Our government still routinely drone-bombs more innocents weekly than have ever been suggested to be in danger, let alone dead, because of anything WikiLeaks has ever done.
2) From the whistle-blowers perspective all documents have been released. Sure if Wikileaks hung onto them it would have a greater impact.
That's a reasonable assumption. Why wasn't it single-use? Aren't people's lives presumably at stake here? How many lives do you need to risk before it becomes worth it to re-encrypt a data set? Why, after disclosing the encryption key to a journalist, did Assange retain the (now tainted) file?
Wasn't the whole idea behind Wikileaks supposed to be that it was run by people with the greatest possible opsec/tradecraft crediblity? How does it make sense for that group to literally delegate all their security to a news publishing organization?
And having done that, by their own admission, how does pointing the finger at The Guardian's lack of opsec capability exonerate Wikileaks?
DDB has stolen their data; Assange has been dealt some serious allegations; and the Guardian has made an understandable technical mistake.
It's quite irrational to conflate that with the Wikileaks brand. Most of this was out of their control.
By Der Spiegel's recounting, it hardly matters what Domscheit-Berg's intentions were, because the files were unknowingly swept up in Wikileaks BitTorrent disaster recovery process. At that point, it became simply a matter of time before the contents of the data set became public, with or without Domscheit-Berg's promotion.
The personality conflicts here between Domscheit-Berg and Assange and Rusbridger and Leigh are probably a red herring. The evidence we have now strongly suggests that Wikileaks was not a careful steward of the data they had; that Wikileaks own convenience trumped tradecraft and security.
That's fine and human and normal for most types of data. But most of the time, we're not dealing with the names of informants and whistleblowers in the world's most repressive countries.
If they want to be a respected whistleblower website they have to show that they are competent. I’m sorry, but I just cannot see how Wikileaks has done that during the last few weeks and months. Based on that I personally wouldn’t trust them with anything. I wouldn’t be surprised if many other people (who, unlike me, actually have something important to leak) think the same way.
(I don’t even want to say anything about DDB.)
But I guess saying something critical about Wikileaks (even if you support the idea of a place for anyone to safely leak stuff) isn’t very popular around these parts. Ah, well.
http://webcache.googleusercontent.com/search?q=cache:NFOMuKV...
x.gpg 09-Jun-2010 00:32 390M
y-docs.gpg 09-Jun-2010 00:55 8.0M
y.gpg 09-Jun-2010 00:55 84M
z.gpg 09-Jun-2010 00:56 352M
[1] http://whois.domaintools.com/193.198.207.6http://cryptome.org/xyz/z.gpg.torrent
I jumped on there for research purposes, and there were 34 peers.
Amusingly it's been available in the google books preview all this time.
A truth spoken in public has a different impact form a truth spoken behind doors.
Its sad that the netizen class is going to give wikileaks credit for everything good that happens from now on. What self-congratulatory armchair revolutionary nonsense.
It also means that they do cherry pick because they have to prioritize what leaks they will check and release first.
They've got 250,000 cables. A small team is going to take a long time to check 250,000 cables.
No doubt they do keyword searches of the cables to find the juicy ones and release those first, but, what you gonna do... release the boring, mundane stuff first? No one would pay attention to you.
It was a calculated decision to greatly increase information sharing between government agencies (including the military) to allow for better cooperation.
My suggestion to anyone with secrets that valuable is to assume they get leaked and have a plan for that.
I'm curious if Wikileaks saw this coming, but I suspect they were naive enough to believe they could maintain control.
The donation list became public? 'Oh ho ho, how ironic!' One of the supporters splits and writes a book about it? 'isn't this refreshingly ironic?' The cable database goes public? 'how very ironic!' And so on.
I'm about as sick of it as I am of articles about a random bit of Wikipedia vandalism.
I do not see wikileaks as any more trustworthy or "better" or "more ethical" than the authorities they are acting against - yes, AGAINST, read Assange's book, he has an agenda and it might not be as altruistic and do-good as most people like to believe.
Um.. let's see... last I checked, Wikileaks hadn't tortured any prisoners, invaded any countries, or murdered countless civilians. So, yeah, I'd count them as just a tad more ethical than the scumbags they're releasing dirt on.
But what makes you think Assange and his gang would make better decisions given they were in the exact same situation? Power corrupts and wikileaks certainly demonstrated on several occasions just how incredibly powerful they are or can be.
I am from Europe so this might be a bit different "over there" but what I was trying to say was: I do not trust WikiLeaks and Assange or question them more or less than I trust and question my government and I certainly do not see Assange's understanding of and longing for anarchy (see his book) as an appropriate replacement of our current governments. Do you?