Resilient Anonymous Communication for Everyone (RACE)
darpa.mil
darpa.mil
1. One of the underlying cryptographic principles is multi-party / secure-party communication (https://en.wikipedia.org/wiki/Secure_multi-party_computation). e.g., three people want to share their salaries to each other, but don't want the information to be traceable to back to the source.
2. Another is Steganography, hiding text in, say, an image, or audio.
3. You want to prevent the problems with Signal, Tor, Bitcoin, etc. This means, no "50%" problem like Bitcoin, no monitoring of exit nodes like Tor, no centralized distribution issue like Signal.
Imagine:
Alice "sends" a message to Bob by creating an account on Reddit and posts a cat meme which has the hidden text (steganography).
Bob knows how to find the text in that cat meme, and responds by posting something on Twitter, which Alice can read and decrypt.
All this is deniable (I didn't get anything from Alice!), available (e.g., Twitter goes down), and secure.
The approach has limitations: your bandwidth is very low, and your latency is also pretty poor. Worse yet, you have to first establish a complicated protocol between you and your counterparty. In general, I think, it's not cracking your byzantine protocol that would ruin you, but a couple of small opsec mistakes (see Dread Pirate Roberts and the end of Silk Road), and these mistakes may be not even done by you but by your counterparty. Spear-phising, exploiting the local system that runs the communication and has some sensitive material in plain text, game over.
The problem with highly secure and clandestine communication (or any other activity) is that it makes your whole life complicated enough, puts enough extra strain on you, that you become noticeable by that alone. Maybe not immediately, but the probability of a small mistake that could put you on a watch-just-in-case list of a willing state-level actor is always nonzero. This does not mean that the situation is hopeless, but rather means that you have a time limit before your cat-posting scheme, still unbroken, becomes irrelevant, given enough interest from The Man against whom you conspire.
The problem with highly secure and clandestine communication.... it makes your whole life complicated enough, puts enough extra strain on you, that you become noticeable by that alone.... always nonzero.... a time limit before your cat-posting scheme, still unbroken, becomes irrelevant, given enough interest from The Man against whom you conspire.
Hide in the noise, embrace counter-culture, call it while you're up.Oh, and they have everything forever, so you can't ever make a mistake against future adversaries, within your risk-window.
and if you think the Latina Beaches will serve you as they did those delusional fantasies, they watch those, too.
The beaches, that is.
You can still fantasize about it, though.
If those before you tell you to beware of dragons, do not sneer at their skeletons.
If the peer selection protocol is something like a dht, or a random-k network like bitcoin, it doesn't leak anything.
but in practice nothing works better than all-to-all messages via epidemic routing. https://www.miasma.space/anon-dhts/
(1) The defensive side wants the ability to de-anonymize and decrypt everything on demand so they can catch threats to the US.
(2) The offensive side wants to promote anonymous encrypted communications so they can encourage pro-democratic dissent in authoritarian regimes.
It that respect, (2) is just a mouthpiece for (1), provided there’s a back door or vulnerability that only (1) knows about.
Do you have any examples from existing tools, e.g. Tor, for which that's true? Tor's been around a long time-- surely something would have surfaced at this point, but I haven't really paid attention to it.
https://en.m.wikipedia.org/wiki/Tor_(network)#Exit_node_eave...
I'm not in the field, but it seems like it would be way more useful for law enforcement working against criminals naive enough to think tor would be a one-stop op-sec solution (e.g. ANOM) than for nation-state-level counterintelligence.
you must have noise to hide a signalSaying it another way, don’t attack platforms, tools and channels, attack protocols since they are used across platforms, tools and channels
To this end, some examples:
Attack on
1) encryption - RSA backdoor
https://blog.cloudflare.com/how-the-nsa-may-have-put-a-backd...
2) hardware - Processor Backdoor
https://forums.whonix.org/t/expert-claims-nsa-has-backdoors-...
(this link is specifically great for this subject as it lists more than 10 different attack / compromise programs that are being run - with quite a few of them being protocol attacks - in the comments section )
3) networking - network gear firmware backdoor
https://www.cisa.gov/news-events/cybersecurity-advisories/aa...
pretty sure this is hearsay from a message board, but I can't for the life of me recall where or when I heard this.
Moreover, it is not DARPA doing the development. They fund other entities to do it.
Wait. Can you clarify this? I know that NIST's standards were compromised by the NSA or at least there is evidence of it. However, this is not necessarily the same as being morally compromised. The story I've read is that the NIST was taken for a ride by the NSA but weren't in bed with them. Is the narrative I have incorrect?
The IBM operating system? Or do you just mean they run on VMs?
Basically a small VM on a crowded server for tasks like running a Wordpress site. So I was confused about why that was emphasized.
But it looks like it's expanded to cover things like GCP and EC2 which makes more sense.
As we create, so we destroy for tactical reasons. Telegram's founder was just arrested for "failure to moderate". PGP was regarded as "munitions export". Tor is apparently wide open to the NSA through traffic analysis.
Even as a small portion of our government wants freedom of communication, most of it is strongly opposed.
I'm no expert on his current activities, but this isn't a situation without Known Context.
Even Politico and the WSJ can confirm...
https://www.politico.eu/article/telegram-ceo-arrest-pavel-du...
https://www.wsj.com/world/russia/russia-military-telegram-fo...
It is forbidden for military to military communication, but openly used a lot for information from authorities to the public.
A reason why russia use it is because they don't have anything better.
Ukraine on the other hand had fairly advanced systems well before recent Western military aid started arriving.
An app that's not e2e encrypted by default, doesn't support e2e encrypted group chats, and is annoying to enable e2e encrypted messaging in.
https://blog.cryptographyengineering.com/2024/08/25/telegram...
Would you be willing to clarify what you mean by that?
To start with, are you saying that Tor is wide open to traffic analysis
(1) by anyone,
(2) by powerful attackers such as the NSA, or
(3) by the NSA specifically?
There is no DPI on Tor networks. Traffic analysis for de-anonymization for Tor works by knowing all the variables in the system and solving it, not by looking at any content of the packets themselves.
The last time something like that was possible at all in Tor it broke it entirely and destroyed the anonymization. The bug involved a vulnerability in the way Tor handled the traffic confirmation attack on Onion Services. This attack allowed malicious relays to embed uniquely identifiable information into Tor cells (the packets used in the Tor network).
Western nations will probably have access to them in most cases, at least for traffic originating and ending in one of them
And you get the "packet information" out of the exit nodes...
With timing you keep track of the volume and... timing, which (often) allows you to correlate the entering and exiting traffic...
Could you point me to any notable incidents or events that has lead to this recurring sentiment?
- lack of a top level protocol description? Check.
- quirky codeworded modules instead of useful feature abstractions? Check.
- promoted by an intelligence agency? Check.
I'd be really interested in novel solutions to this general problem, but how is this one not dumber than Urbit?
Some constructive criticism: it's better to just admit when you made a false statement than to double down on being wrong.
if you're doing cleared work you have obligations and spooks are spooks. Not only is it government, but it is part of DoD. DARPA isn't creating anti-state anarchist communications platforms in spite of the rest of law enforcement and the IC, and if they are, you'd be insane to trust them with your black market or terrorist operation, which is the only meaningful use case for measuring the integrity of an encrypted anonymous platform like the one being proposed.
the extremist example use case means that authorities are forced to use some legal method other than mass or passive interception to exploit it for evidence or to disrupt a plot. pretty sure DARPA isn't arming enemies like that, and if they are, they can provide something security pros can reason about instead of something for naive developers to play with.
I'm simply stating a fact about DARPA and how their mission and operations fit within the US government.
Look, if you want to characterize DARPA research as IC work, go ahead. You clearly don't work in the space.
I'll reiterate that their product isn't going to work in any space if they don't learn how to write a security protocol and include it as the extraodinary evidence required for something like a secure anonymous communications. the way they can show good faith is by providing something objective. I even look forward to walking this comment thread back when they do.
sure, sequence diagrams, which are great to have and necessary, but there are no assertions about how security is done.
I assume you were originally responding to the proof of concept in the Github link? I mean, sure, maybe your criticisms are valid, but (to borrow a term from DARPA) they are non-responsive. If OP wanted to share that Github link and make it the focus of discussion, they would have done so. If you wanted to discuss that Github link, you should have been more clear that you were responding to something peripheral to the actual thing under discussion, which is the program, not the PoC.
In general, my response wasn't just to inform you, but because this is a common point of confusion when people share or discuss DARPA programs here. They are explicitly not prescribing a particular solution, even if sometimes a prior seedling effort or PoC is released alongside the solicitation. So don't take my response so personally; it was not only meant for you.
an ungovernable, decentralized, general trust-less computation protocol/escrow/rep using zkp+ and hormophic encryption was not able to be realized before the alfabit bois got a chance to mole into the development pipeline and backdoor the inevitable Merchanti Ultimatum; anything less would be a massive national security threat globally.