Trying to Keep Your E-Mails Secret When the C.I.A. Chief Couldn’t
nytimes.com
nytimes.com
Yes, you can access existing Gmail accounts over Tor. But in my experience, it is damn hard to create them over the anonymizing network. Google wants a mobile phone number, which of course defeats the point. On the other hand, Hotmail had no such requirement last time I attempted this…
Can't you just pick up a pre-paid sim card in a corner shop? You get a "burner" phone as a bonus.
Anyway, for some uses your own tor hidden service is fine, it's quite easy to run if you're familiar with Tor and services. You can also use something better and more secure for communication than HTTPS and Tor, like SSH and BBS like interface. It reduces risk that people accessing your service with systems which aren't properly prepared to be secure won't store anything at all on disk. (Yes, it still could be possible to swap or hibernate some data if users are real failures.)
Yet another option which I like is RetroShare, it's secure and keeps data private, but it doesn't inheritly hide connections between nodes, for that part you'll need another anonymization layer.
For simplicity, I prefer to use self hosted message system with SSL and notifications can be sent with link or without link to users when required based on message content / subject / privacy level required etc. If users do have registered account, then they also might need to give their login credentials if required. My server also provides TOTP authentication as 2FA solution, for a few geeks who use it, including my self.
Because of the nature of easily-copiable bits, the only real way to be secure in communications is encryption with something like GPG. But public/private keys are a completely unfathomable idea to regular people. Hell, they're even confusing to techies. Even if the concepts are understood, implementing and using them is cumbersome and error-prone to say the least.
That's why I think the most important thing to be working on, from a social-importance perspective, is a way to make GPG-style encryption friendly, usable, and easily-grokked. The problem of good-enough encryption has been mostly solved, I think--we just have to get people to use it!
I would suggest using Jitsi, an open source alternative to Skype, that encrypts both chats and calls/videocalls, when talking to another Jitsi user. The best part is you can still use your Google Talk/Facebook chat/XMPP/other logins. But it encrypts the conversations happening between them.
As for e-mail either one of these (Except Hushmail which I've also heard has been compromised):
http://www.makeuseof.com/tag/3-secure-encrypted-email-provid...
Or just write e-mails in a text file, encrypt it locally, and then send it to someone. It will be hard to anonymize who's sending it, though, unless maybe you create some new e-mail accounts using Tor, and then always using them through Tor.
Go off the record[1] in your client instead and enjoy all the important protections, which include: encryption, authentication, perfect forward secrecy and deniability of the kind that you can keep denying everything even when presented with a word for word printout of the conversation.
Why even give Google a chance to fail you? Sure, it can still be known whom you're contacting and when but otherwise, you're covered.
[1] http://webapps.stackexchange.com/questions/16931/how-does-th...
Actually, there are well known and well tested ways to do it. You would probably enjoy learning about remailers and nymservers.
http://en.wikipedia.org/wiki/Anonymous_remailer
http://en.wikipedia.org/wiki/Pseudonymous_remailer
It's a lot of work, and it's easy to make security compromising mistakes, but it is a very interesting topic to learn.
However keeping your mail secrets from your girlfriend and/or your boss is relatively easy. Secure passwords, two factors authentication, ciphered communications to the servers, S/MIME...
It takes just one mistake — forgetting to use Tor, leaving your encryption keys where someone can find them, connecting to an airport Wi-Fi just once — to ruin you.
No, you're not. Sure there are additional risks but making broad statements isn't helpful when we're talking about connecting to a service with SSL.
> connect your MAC address to the Gmail address
How? Again, it's possible but Gmail works over SSL. That connection would have to be compromised to make any connection to your MAC and then they'd have to make a connection from your MAC to your personal identity.
Apart from that: If I buy hardware from e.g. Apple or Dell, do they keep a database that connects the MAC to my identity? I don't know.
As for the MAC database, it doesn't really matter. It would be easier to correlate the MAC address with security camera footage, for example. (I worked on a project for a local network security firm doing exactly that--don't worry, I wasn't doing the security end of things.)
apt-get install macchanger
macchanger --random eth0
(And there are multiple utilities for Windows too).Of course, you have to know you need to change the MAC, but that's something the article could've mentioned.
you want a safer way to communicate. use the telephone, non-voip. the content of your conversation is temporary, there is no record. if someone is not listening in to your conversation right now, no evidence in terms of content stays behind. if it would have been petraeus, all we would know that he had a lot of phone calls with his biographer....
You assume. There's no technical reason for this to be true, however. Telephone conversations are digitized and could easily be saved by the millions. I once worked at a military base where they saved every minute of every telephone conversation, and back then storage was a hell of a lot more expensive.
Voice recognition software has been around for ages, and mainstream consumer products (DragonSpeak, etc) have become surprisingly good. Sure, they could have used prepaid mobile phones or voice scramblers, but then again they also could have just accessed their secret email account(s) just from public access points.
(It leads to http://www.nytimes.com/2012/11/18/magazine/the-2-d-thanksgiv... , not a bad cookery piece but alas, only headlined "The 2-D Thanksgiving".)
P.S. On topic, it occurs to me that email was not needed. For the purpose of revising a draft, any web file access would suffice: Pastebin, Dropbox, Bitbucket, whatever. Even better, an encrypted service like Wuala or Silveroak.