I am under surveillance by Canadian agents, my computer has been backdoored
log.nadim.cc
log.nadim.cc
There are many actions you could take to mess with the investigation that might seem like fair game, but you should discuss each one with an attorney so you don't provide some arcane justification for them to arrest you (by hacking back, or even maybe "interfering with an investigation").
Once you get past that stage, the attorney can help you petition to stop the behavior or demand more information about it.
Legal advice is what you need now, not tech advice.
(Because the server is crushed, I'm only getting the basic gist - forgive me if you've already done this.)
nadim@nadim.cc
(That said, I can see another problem in cases such as this: what if some of the "volunteering lawyers" are set by the government?).
My IANAL guess is that they would still be bound by client/attorney privilege, and they'd be committing a crime if they violated that.
I should add that while the malware in question may indeed talking to CSIS servers, this could be the case the CSIS servers themselves are hacked -- more likely by an automated worm in service of spammers (and honestly this is what the 'PG' person sounds like to me -- a scammer/spammer) than any scary entity.
Regardless, this is a legal, not technical matter at this point. Get recommendations for a lawyer in your area (you could also try contacting the university staff for this -- they may well be required to help you find an attorney), talk to them. Avoid posting anything else to a public forum.
I heard that Canadian sysops are the ones that apologise when you hack them. ;-)
Not trying to be sarcastic, but I'm really curious what such an email could possibly achieve. If they tell you they haven't done anything, they're either lying or not - you wouldn't know. And really, what are the chances they would tell you that they have rooted your PC if they had?
http://en.wikipedia.org/wiki/Jacob_Appelbaum#Investigation_a...
It really shows how those in power are scared of the liberating powers of technology.
Although I think what the US government has done to Jake is quite clearly a disgusting abuse of power, let us not kid ourselves by somehow believing that the state has gone after him because he has publicly advocated for the use of strong crypto.
| his harassment at the border began right after
| giving a keynote at HOPE 2010 in place of Julian
| Assange
| the only US citizen identified in the media as
| a member of the Wikileaks team.
I'm thinking that these two pieces of information are part of it.Assange developed part of Truecrypt if I recall correctly.
But yes, there are a reason that crypto people get hunted in general ( not only wikileaks) and there are even a ground war going on in other fronts.
First, I will tell there are "groups", mind you, I only mean a collective of individuals and organisations, that many times are fighting amont themselves, also individually they may have different aims and purposes, but the "group" thing simplify the things.
Second, the subject is very ancient, so I will try to talk only about the last 100 years, because otherwise it will become a too complex thing to write about in a short post.
Also, I will not name the groups, because whatever name I use for each of them, have different meanings and charges to each person, resulting in a flamewar (and the reason people think I am crazy).
I will list the groups in order of theoretical and legal (not necessarily de facto) power.
Group A: This group is in power in several states, run some huge international organisations, and wants more power centralisation, individuals within it want more power to themselves.
The Group A is very much against cryptography technology leaking (the weapons of choice of Group E), Group A also tend to help Group C if they think it will be a blow to Group B or E, otherwise they currently use Group C as scapegoat and target to fool their subjects in giving them more power.
Group B is very much alike Group A, but with fundamentally different economic beliefs, Group B realised it cannot beat Group A directly, so they right now work by mostly promoting ideologies and morals that will undermine Group A centralisation of power and capacity to react, Group B also don't like Group E, and don't like crypto on Group E hands, but sometimes they might allow Group E to get that tech if it means improving their own to use against Group A.
Group C currently is like Group A and B, but based on religion, also Group C recently took over 4 countries, with great help of Group E and Group A, much to the regret of Group E that only now realised it was against their interests to this happen.
Group D only want to be left alone, but are frequently caught in the crossfire.
Group E are the opposite of Group A, they want more freedom, more decentralisation, and of course, more power to themselves too, but not in a hierarchy, and more splintered. Group E loves cryptography, and the reason OP is being hunted, is because he is helping Group E (on purpose or not).
I'm really hanging on for someone to provide some names or additional info so I can do my own research rather than taking stuff at face value :/
Group C probably has a name, but I don't know it.
All Groups, maybe with exception of B, are not much cohesive and are easier to say who belong in them.
So, I will say some organizations that BELONG to some groups (they are NOT the groups, they are PART of them, a small part by the way).
Group A: Has on it the UN, and several countries. Also has on it some esoteric organizations and religions.
Most people don't notice, but Thelemites (followers of Thelema) frequently align with Group A, so if you want some extra information, read about that.
Group B has on it the followers of Gramsci, Frankfurt School, several atheist evangelists, and part of their strategy was very much well explained by a guy named Yuri Alexandrovich Bezmenov, see if you find his interview.
Group C has on it Muslim Brotherhood, and Al Quaeda, "Al Quaeda" means "The Foundation", and Osama Bin Laden has read the foundation series by Isaac Asimov, so if you want to know what Group C is doing, read those books, and think about how you would apply them to present age...
Group D has people like the guy above that claimed to be part of F, also has countries that don't want to be dragged in all the A, B, C craziness, like some african countries, some asiatic countries, and so on.
Group E has among them the OP, Julian Assange, Punks (the ones from 70s), Cyberpunks, Cipherpunks, Anonymous, Libertarians, Far right groups, non-aligned christians (those that follow the bible and reject mainstream churches), a small amount of catholics, secularist arabs, conspiracy theorists, nutjobs, normal people that dislike their constitution torn apart, federalists, Catalan/Scotch/Chechen/Kurd/Touareg/Xeer/Somalilandi/Gaucho/etc... independence/autonomy movements, Occupy X/Y/Z, Indignados, Golden Dawn Party, the norwegian serial killer, lots of other random people.
Groups that I don't know their alignment: Shia countries (Syria, Iran, Iraq, Lebanon), seemly those are related to D, several people in E are helping them (and A and C are attacking them).
For those wondering where is Israel, Zionists and Roman Catholic Church. I will leave those out on purpose.
My believe was that the KGB had degenerated into some sort of mafia and russia was now playing the capitalist game (by their own rules of course). But then again i don't know much about those things.
I'd like to point out that we like cake and tea, and amuse ourselves with getting on with stuff, while groups A-E do their best to screw it up. If A-E could just naff off and let the rest of get on with it, we'd be in a much better place.
First, you will understand lots of things easier if you read at least the first book of the Isaac Asimov "Foundation" series.
Then, I've been researching this for a looooong time.
Also you will waddle through lots of crazy stuff, trying to find the gems.
I only started to find out, what information matters, and what don't, what is real and what is just nutjob ideas, after I met some particular people in real life.
Also there are deep religious issues on this, and some fringe stuff (for example: the ex-wife and some more people related to a known member of Group A claimed that he rose to power in his country using black magic).
But a good start, is research about what is Thelema (and its followers), who is Antonio Gramsci, what is Frankfurt School, what is Muslim Brotherhood, the islamic plans for gold standard, Colonel Gadaffi push for gold standard, Punks, Cyberpunks and Cypherpunks, Saddam Hussein push for oil be sold for Euro (instead of USD), Sunni vs Shia wars, pro-Assad christians.
These are the stuff I remember where real facts are easier to find.
Other things that I would mention here are too bizarre and hard to understand, and filled with misinformation.
Also if you decide to research this stuff, caution to who you talk, you might get dragged into the thing (and let me tell you, it is not pretty, I had two serious close calls recently).
Of course, like the OP, you might get dragged into it anyway.
It may sound cliche, but fiddling with that stuff, that I learned how serious the phrase "And when you gaze long into an abyss the abyss also gazes into you" is dead serious.
But let's say that I had a online friend, that I decided to help, and found out that this friend was a unwilling weapon of "Group A" that escaped, and was being searched for, and I got tangled into very hair raising stuff (including death threats toward me).
And I learned lots of stuff, that I wish I had not learned, the sort of stuff that make people say that "Ignorance is Bliss", but now that I learned, I must act upon it, there not much else to be done.
It was a hell of a adventure. The most scary shit I ever faced in my life, and made me get much more mature and responsible.
Also I almost lost my family in the process (they were very much against some actions that I did and became incredibly upset).
Happily they later understood everything that I did and now we are happy again.
http://www.amazon.com/Im-Namen-Staates-German-Edition/dp/349...
No chance of humoring us?
Watch some movies, catch your regular classes (or skip a couple if you can), read that fat sci-fi novel - fill in the blank. FI anyone you don't know calls you on the phone just tell them you're not interested, goodbye, and take a rest from the internet. After a week, chat to a lawyer and work on the fact that someone is harrassing you - might be an intelligence service, might be criminals, but make it your lawyer's problem. The best thing for you right now is to recharge your batteries and that putting some distance between yourself and the source of your stress. The best way to deal with your computer being hacked is to leave it switched off; not least because your lawyer might advise handing it over to a forensic analyst for an audit.
But primarily, take it easy and be good to yourself. Nothing obliges you to wear yourself out responding to the behavior of others if it is making you stressed or unhappy.
Speak to a lawyer and/or some journalists.
I want you to do this. Your current position may make it not so simple. But you must slow down and regain your composure.
Such situations are better dealt with people who love you.
Postpone any harsh decision until you have met with a loved one and have explained the items.
Remember that there is always a way to work things out. Dont lose hope. I want you to remember that things get better. They improve. You just need to slow down and reason a bit.
I'm not doubting your points. But I want you to go to a safe place where you can get some rest. Tomorrow you may be able to think about this with a better understanding. You are a smart person. You always figure out hard problems. You need to rest a bit before you can tackle it. Go and stay with a loved one. They will welcome you and listen to the items you are talking about.
I am orangethirty. Have been programming for a long time. I live in the Caribbean, and you can read more about me on my github (github.com/orangethirty). I'm only interested in your well being. We all want for you to regain your inner peace.
If you need anything, then let me know by posting here. If you feel comfortable emailing me, then do so.I am not pressuring you to do so. Do it if you feel like it.
I want you to remember that tomorrow is another day. Things improve. There is a way to solve every problem.
- orangethirty
Try to dump RAM image.
Image the drive, sign and optionally encrypt the contents, preferably file-by-file checksum and copy to multiple secure locations. Copy of checksums in additional secure location.
Get out of your house with your computer as soon as possible (as soon as you upload one or two images). Do not leave the computer, they will try to destroy or confiscate the evidence. Plan to store computer in secure location, preferably with 24/7 video monitoring and a heavy duty safe. Preserving the evidence is probably that important.
Try to be in the company of someone you trust so they can act as a witness and can protect you from physical intimidation or attack.
Assume phones are compromised including GPS on your mobile phone. Assume you are under physical surveillance. Assume your car is compromised.
Relatives and close friends will be known to operatives. May be a good idea to spend 1-2 nights in a motel with a friend without anyone's cell phone paying cash until you secure copies of your data and get advice on what to do next.
That should have been enough to make anyone suspicious.
“On January 31st, 2013, a person identifying as PG sent me an email saying that he would wish to meet to discuss a business opportunity with me.”
...was intended to refer to you, or if the initials PG are just a coincidence.
You are in the “initials club” after all (rms, jwz, esr, djb) and have even shortened the usual three letters to two.
http://bits.blogs.nytimes.com/2012/03/12/a-hacker-charms-and...
Fuckers. (sorry, I couldn't resist)
This story sounds...weird. I doubt it is quite as he suspects it is.
The NSA doesn't do field intelligence work, AFAIK, unlike CSIS.
>This story sounds...weird. I doubt it is quite as he suspects it is.
It's weird, but I'm not sure who else other than CSIS would have the motivation to hack an activists computer so it sends data to CSIS-affiliated servers.
[0] http://en.wikipedia.org/wiki/Canadian_Security_Intelligence_...
[1] http://en.wikipedia.org/wiki/Communications_Security_Establi...
I happen to know that upon applying you are directly told not to tell anyone you applied, or even that you were thinking of applying.
Trying to contact a small variety of servers of various disparate government agencies seems more like an attempt to generate false evidence that the victim is actually a dangerous hacker.
Or at least that's what Stephenson, Doctorow, and Gibson have trained me to think.
Are you suggesting the CSIS kill people? Who are going to be missed because they have said they are under surveilance? Or even abroad?
Magikarp is doing everything right so far. He doesn't need to cross a line by exposing CSIS servers to attack. And nobody else needs to play with CSIS servers either.
Protest and demonstration is one thing, but playing with law enforcement servers is like throwing bottles at police cars for the lulz and is just asking for the book to be thrown back at you.
Do you have evidence of any particularly good countries?
$ ls -l ~/.ssh
total 80
-rw-------+ 1 nadim staff 737 Aug 22 01:39 authorized_keys
-rw-------+ 1 nadim staff 35 Jan 5 21:32 config
-rw-------+ 1 nadim staff 3243 Aug 18 10:57 id_rsa
-rw-------+ 1 nadim staff 735 Aug 18 10:57 id_rsa.pub
-rw-------+ 1 nadim staff 3326 Feb 2 21:41 id_rsa_CSIS
-rw-------+ 1 nadim staff 749 Feb 2 21:41 id_rsa_CSIS.pub
-rw-------+ 1 nadim staff 3198 Feb 2 21:46 known_hosts
[1] I have no reason to think he does or does not posses this skill. I only mention it in the negative because it was not in his wikipedia bio.Please read on. If this is real, then I'm sorry and recommend you to consider all suggestions before deciding illogical.
DON'T COMMIT SUICIDE!
If you watched the movie "Enemy of the State", I'd become paranoid, but not afraid. Stay calm and act logical.
I've looked at cryptocat two days ago, what's special about it? I don't see any reason for the Government to observe you, except that you would be a good fit into their Cyberwar Team. And that you have the wrong connections in the internet. I mean your friends are all hackers. It makes you appear dangerous too. Anyway, the government observes everyone, but with different priority and detail. I think only you might know why they observe you. No need to share the info.
Just as in the Movie: I'd replace all clothes, shoes and hardware with new ones and move to a different place. Acquire encryption software from a trusted source or compile it myself on a newly obtained Netbook and encrypt the hardrive+swap with a password and keyfile. Hide the keyfile. Put your hardware and new phone into a cool faradaybag.com. Stay in public, but personally invincible. Leak everything that isn't harmful for you using delayed transmissions with ifttt.com. Always have multiple copies of important documents, just for the case it's necessary.
Oh and I'd get a weapon and buy a bulletproof jacket (not vest). Avoid any contact to officials should be priority. Use Tor and VPNs like spotflux, hide.io, ovpn.to etc. and inform close friends to guard you.
+Trust no one.
Yes, I agree on the weapon, every signal that can pull the trigger of an official's gun should be avoided. But I think not having a weapon maybe careless too, only he knows what's right in his situation. A stupid move when confronted with officials could cause him more harm than wearing a gun.
What he needs is legal & political help.
Btw. almost if not all of the fiction described in that movie has become a real threat. Not taking them into consideration is silly.
Now if he's in trouble simply because he works in the security field, this is a bit concerning. The lawyer advice is the sound one: fight legally the system and bring this to court if the attacker did anything illegal.
Of course you have to laugh hard at the mediocrity of the second part of the "attack": directly contacting servers which can be reverse-looked up. Doh!
But it still begs the question as to how his computer got owned in the first place.
Is it mediocrity, or is it intended in order to send a message?
"We are on to you", etc?
People seem to know the guy. I'm not sure this is "imaginary" at all.
Of course, he doesn't seem 'valuable' enough to spend a fresh 0-day on him alone as the government backdoors (Flame and friends) did with multiple 0-days included; but I'd guess that every large gov't has a standard rootkit and knows a few vulnerabilities not yet disclosed/patched - it's really not that hard/expensive to do, you can just spend a million and buy that stuff from private researchers.
Also, it would be interesting to see what one could find on a raw disk image clone (hidden files? rootkits?).
I am using Transmit for Mac OS X, by Panic Software, version 4.2.
i assume they had connection for sending commands that was separate because the sftp sounds like it was blocked but the uploading stopped apparently in response to external stimuli. seems kind of lame to have some kind of connection sending commands and then using transmit to upload files.
http://developer.apple.com/library/mac/documentation/Darwin/...
If you're still concerned your machine is affected, I'd recommend getting Little Snitch - which automatically blocks connections (both in-bound and out-bound) that are not pre-approved. In addition, when it auto-blocks it records the application that was making the connection attempt in the auto-block rule.
(Well, actually I'd suggest you dd a backup of the drive to analyze - then wipe and start anew.)
If they hired anyone of any worth, the person installed a timed launchd (or cron) controlled script to run rarely and at odd hours to upload content from your machine to those remote locations. This kind of setup a.) would use a command-line tool for the upload and b.) unless they knew you had Transmit it would be designed around executables already included in OS X or that they installed.
Unfortunately, if it has stopped, they've probably deleted the scripts and cleaned up the evidence. If you've got Time Machine running, however, you may have backed up some of their handiwork.
Set up a separate Linux (etc) machine with two ethernet ports as a firewall/router, running wireshark in addition to everything else. It can now log all packets in and out of your network, and save them for later analysis.
If nothing interesting happens in the time it takes you to get bored, copy just the files you really need across from your old HDD to a shiny new one.
The real -legal- solution is to turn the computer off, stop touching it, and get a lawyer specializing in computer crimes. Get the machine to them so they can make an image of the drive, complete with hashes of the filesystem, so that they can prove it hasn't been tampered with past that point.
Then let -them- do the investigation, with someone that has the documented skills a court would recognize.
Thank you for your response, though. I was just trying to be a little more practical.
I was more addressing the techical "How can I tell if my computer is haunted?" question than the original poster's legal issues, on which I am not at all qualified to speculate.
Anything wrong with that?
If you want to protect against the kind of attach he hypothesizes to have experienced, yes. Trying to catch root backdoor on your machine by running a firewall on that same machine won't be much help. He called it an "external firewall", so I imagine it was a separate machine that noticed the outgoing requests.
Might be crazy, but when I travel I setup a webcam in my office to upload to a vps and then ustream 24/7. Highest quality (don't care about bw since nobodies home.)
It would be interesting to hear if/when he didn't have direct control of his laptop while on travel.
In fact, that's why I published this blog post. To protect myself.
While yes, a desktop can be breached (as it apparently was in this case), there's more surveillance options you have with which to secure its surroundings. And agents would have to get a warrant anyway.
If you're worried about the prospect of them warantlessly breaking in...I guess that the more likely danger is that if they are willing to resort to that, they are also willing to stage a robbery in which someone punches you in the face and makes off with the laptop. Or hire someone to spike your drink during a date.
As somebody else said: take a deep breath, take over 9000 backups, and start reducing your attack surface without falling to complete paranoia.
As it's written this seems to be a very confused article to me. What exactly is the author's point in writing this? And what is his next step moving forward?
What operating system does he use, what software under that operating system (specifically the FTP client), does he have a secure firewall, etc. etc.
Can you tell me what your next steps in proceeding are, or would this violate the protection you're attempting to set up?
Helpful advice is more than welcome.
But you should try to script something quickly which will automate these actions for you. And you should also try to make a bot to investigate the "backdoor" more.
Aside from your evidence, is there anything that has happened in the past that would lead you to being a target for the NCIS?
1. If you suspect the machine was tampered with, do not use it again. There are a lot of places a backdoor could be hiding, even after you reinstall the OS.
2. If you do not do so already, use smartcards for crypto. Don't store keys on your machine. It is easier to carry a card around than a computer, and smartcards are harder to brute force.
If you're doing really security sensitive work don't run questionable software which you don't have the source code for.
I don't believe the people he alleges he spoke with are intelligence operatives. Whoever they are, they were almost surely messing with him (but could still be conventional employees of an intelligence agency.) Whether or not they're for real doesn't change my first paragraph though.
I'm not able to give any advice except this: As long as you're on this road, there is no one you can fully trust. No one at all. You haven't fully internalized this yet.
i would like to think that "CSIS" had better things to do.
Mainstream new story from a couple weeks ago in which activist orgs complained of CSIS harassment:
http://www.ctvnews.ca/activists-warn-against-csis-intimidati...
Give me a break.
Canada has a very open door immigration policy. Unfortunately that open door draws in people who actually don't like what Canada is about (which makes it weird that they would come here) and who conspire against, effectively, Canadian society. I welcome that law enforcement cares about this and does normal investigations.
Further from a corporate perspective it is well known that China, in particular, is going absolutely rampant with corporate espionage in the West. This is a major concern.
Or just call it some sort of "anti-activism" creed.
Sounds like what you're saying is that because CSIS does some legitimate things it means they don't also do less legitimate things, like harass/spy on activists.
So? I have the CIA appear in my blog logs and have for years. People work there, and some of them like blogs. Is that, apparently, "harassment"?
Cryptocat developer Nadim Kobeissi was detained and questioned at the U.S. border by the DHS in June 2012 about its censorship resistance.
I'd totally support this.
Illegally monitoring a citizen has to about as bad as it gets in my books. Especially someone who has never done anything illegal and only received attention by building tools to help free speech/privacy.
This Nadim fellow is a suspicious guy doing suspicious things who travels to terrorist hot-spots and to the USA, which is also suspicious. And I bet that CSIS is reading every word on HN right now. After all, where do you think that CSIS finds the hackers to set up the kind of hacks that Nadim has described? Same goes for CIA, NSA, FBI, DHS.
Just because something is legal doesn't mean its not excessive. Just because the government does something, doesn't make it right.
From the description of what happened I'd guess probably at the local high school, by asking if anyone likes Bond movies.
Well, on that off chance, let me be the one to say to our CSIS guys and gals: for fsck sake, don't do something like this. We could all use some better role models, and the number of comments and votes on this thread reflect how monumentally-offensive the suggestion is.
Nadim is a smart guy working in computer science. What would the reaction be if he were Dr. Kobeissi and a computer science professor?
1) Because you are an anti-surveillance activist.
2) Because they want to eventually backdoor Crytocat in order to spy on the users.
3) Because the FBI asked CSIS to spy on you, and the FBI has their own motives.
In any case: Please take the time to actually understand the difference between XMPP and OTR. You have repeatedly and very confidently shown a fundamental misunderstanding of their function and implementation in this thread.
Hypothetically, what is the benefit of airing out of all this information ?
Media attention. That seems to be all this kid has done is wave things at the media that the media themselves don't understand. Cryptocat is a javascript implementation of XMPP with OTR enabled. Snore... Hop on Google chat and click "Off the record" and you've done the same thing cryptocat does. Unlike google chat you have to load up yet another Chrome browser extension that will no doubt eat more memory.
The "anapnea" thing he was involved in looks like a joke as well. "Encrypted tunneling network"? You mean a VPS you give people SSH access to? Mind blowing.
Nothing to see here folks. Move along.
Right, and cryptocat doesn't, 'cuz they said so on their website!
Inform yourself, ignoramus.
He is quite literally doing the same thing as I could do in setting us open fire on a box and inviting everyone to conne t and turn on their client side OTR. Just because it's a chrome extension and written in JavaScript somehow changes that? No.
No, it doesn't. That's not what "virtually" means. It's guaranteed, barring some unexpected advance against one of the cryptographic algorithms used. In cryptography you use words like "essentially" or "infeasible", not "completely" and "impossible," because at the end of the day you are just hiding behind hard math problems.
The whole point of OTR is that you don't have to trust the third party, and you obviously do not understand that. They are just a transport. The analogy you are making could just as well be applied to any ISP inbetween you and the person you are talking to. They are a transport. Don't trust the client? Use another. Or are you seriously suggesting writing your own? Then you're starting down a very long path: http://cm.bell-labs.com/who/ken/trust.html
You also keep comparing it to Google's "no log" feature, but they have absolutely nothing in common. The "specs are not different"; they are completely different things.
It's disappointing that you're so stubborn, arrogant, insulting to the author, and wrong at the same time. OTR is a brilliant and fascinating protocol, particularly because it gives people who communicate deniability, which PGP, for example, doesn't. Cryptocat is helping popularize it, and that's good.
This is a point which a lot of people seem to overlook. Sometimes, non-repudiation is desirable. Sometimes it is not.
You realize it is impossible to talk to somebody over the Internet, or in real life except in person, without relying on a third party, right? You choose who to trust, and OTR, the protocol, makes it so you only have to worry about the software used, not about the communications channel and anyone listening in on it.
> The specs are not different. They are completely different things.
Do you not have any reading comprehension? That's literally what I said. I haven't said anything against OTR at all. I fully support the use of XMPP and OTR for communications. You can attack me all you'd like, it doesn't change anything I said.
This is literally what you said.
> You can attack me all you'd like
I don't think I'm attacking you, but after being this insulting to Nadim Kobeissi, in this thread and on Twitter, you don't get to play hurt.
I hope Nadim does a full write-up, including these, soon.
In the meantime, all the best and keep your (thankfully already) level head.
using defective crypto products is much riskier than not using any crypto at all and exercising caution. cryptocat has always seemed a poorly disguised honeypot to me.
Cryptocat has been fairly well reviewed by a number of fairly smart people. While flaws have certainly been found, they've mostly been addressed, AFAIK.
"Snake oil" has been a popular term to throw around ever since the original PGP user's guide, but simply labeling something "snake oil" without any actual proof is a dangerous thing to do (especially when it's an open source product, and you should be able to point to any defects specifically).
Edit: I realize the term 'snake oil' predates PGP, I was referring to the crypto community's penchant for it.
I am trying to protect myself and my open source project, which, by the way, has been audited countless times and has progressed greatly towards security. If you have a problem with me, then call me up and discuss it instead of stressing me out even more when I just discovered that the government is building a case against me.
If you don't like my work, file a bug report. Check out our documentation. Review our OTR implementation. Submit a pull request. Hack some code. Just don't say hurtful and untrue things like that in public. You can do better.
This is the Hushmail attack, and it seems like Cryptocat is vulnerable to it.
I swear upon my father's grave I will never do something so dishonest and evil towards everyone who has supported Cryptocat, the most meaningful thing I have made with my life.
1. I'm not a lawyer, but I'd be surprised if this were legal.
Some people are fanatics who will never believe. Perhaps there wasn't enough hacking in terminals with falling green letters or he doesn't think crypto software can possibly be easy for non-security professionals.
Again, you are doing the right thing. I'm only sorry the only thing I can give you is my support.
That being said, I think it's a cool project and it seems to be pissing off all the right people, so keep it up. And I'm not a lawyer but I don't think that the gov't has a case against you (or am I missing something). In fact, it would appear that this might be warrantless wiretapping so you might have a case against them, but I'm not sure if that is something you want to pursue.
this is so spot on. secure comms have no place in a web browser, which is a complex beast with a large set of underlying dependencies. webkit vulnerabilities leading to comms being blown is a crappy architecture.
people who care about comms use a standalone client and a separate server. if you care about the integrity of the server, you run some disk crypto, DDR3 memory, secure it physically, etc.
That is not the case. DDR3 memory will not help you.
CPU registers are the safest place against this attack (hence stuff like TRESOR where AES keys are held in CPU registers), but are by necessity limited (especially on x86; SPARC was better, and some of the new extensions to x86 help (SSE, etc.)
Most of this has been mitigated to some extent by periodic inversion of sensitive strings in main memory (keys, usually) -- this has been implemented in ~all crypto libraries.
SRAM's huge advantage is you can clear it faster than DRAM, but that doesn't help if you can somehow prevent the clearing from happening.
Especially if you're bit-flipping sensitive stuff, there's probably a good hope for protection from recovery at normal temperature after what, 30-60 seconds? So reset is an issue, but "keep sensitive things in RAM vs. on disk" is still a reasonable security precaution.
you are clearly very talented with marketing yourself and the project, so cryptocat getting lots of media coverage led to an essentially crowdsourced design for cryptocat 2, very similar to mega. sure enough, this design has held up relatively well and gotten through audits without too many serious issues. as someone who cares a lot about secure comms, i have seen and continue to see no reason to use cryptocat.
i find it particularly ridiculous that a supposed proponent of free speech suggest i am not entitled to my (negative) opinion of your project. i see no point in filing bug reports for software i will never use. i believe in people doing their own homework, it is not my job to improve your project.
if i assume that your govt troubles are indeed legitimate, there are a couple things that seem inconsistent to me:
- you seem very concerned about the negative ramifications of angering your local govt, and all this is linked to (1) your dev work and (2) your prominence in the media. if you are so truly concerned about govt action against you, why are you publicizing the harrassment you have experienced? it only serves to promote your dev work and elevate your media presence, which i would expect to further aggravate your local govt.
- the govt likely knows that actions like this, properly publicized, only lead to an increase in the reach and use of your product, in direct contradiction to your suggestion that they don't want to have your product circulate. it seems that "cui bono" in the context of your story is that you and your project directly benefit by getting lots of publicity.
i found it a bit difficult to fish out details on the ciphers and modes you use with cryptocat 2, which doesn't exactly inspire confidence. i am not a fan of using a stream cipher (AES-CTR) to protect non-streaming comms due to the nonce re-use issues your audit found. ssh using AES-CTR makes sense to me, an IM protocol, not so much.
What aspect seems "fantastic" to you? Have you yourself been involved in activism?
The whole thing sounds like a bad b-movie or someone playing a practical joke, rather than a genuine attempt.
Then again, who knows, idiots manage to get hired everywhere.
Do you mean trailing people and surveillance?
I have to wonder what you'd see
If you used style as ID.
Styles change from time to time
But style stays from line to line.
Names can change and faces too
But writing tells you who is who.[0]
Many say they are a crowd
But fewer do once lost their shroud.
Traps and snares one will find
Many more if kept their wits about their mind
Still plenty that you see
Hide their face behind IP.
Just a thought.[0]: http://33bits.org/2012/02/20/is-writing-style-sufficient-to-...
[1]: EDIT: It seems to me that it is very possible that not all accounts here, though not necessarily in this thread, correspond to a single individual.
With the help of the HN api, you could probably fingerprint a lot of users.
None of that would show up in any logs or files, and it would get around any password protection and encryption on the actual computer, the only evidence would be from monitoring router traffic. A usb bug would be something that would transmit via wifi, but it would need to be connected directly to your computer to work.
Also check inside the computer for anything unusual.
https://blog.crypto.cat/wp-content/uploads/2013/02/Port_sn_0...
The main crypto.cat page loads fine over HTTPS (certificate has sha1 thumbprint d1aa1c1037202e359f224e407d7f84a0e8a94dd7 which i see is advertised on the erroring blog.crypto.cat page).
Why has the certificate changed? Why did the CA signing the SSL certificate change? Is there any forwarding message signed by the original certificate?
I do have a question about the story though. Why would an intelligence agency want to "acquire" Cryptocat? What would that mean anyway? Purchasing it for internal use is surely not necessary. They can just use it or any one of a number of in-house products they surely already have access to. Purchasing it to take it out of circulation is a possibility. But is this actually feasible? It's Open Source. Purchasing it to stop the developer working on it is a possibility. But wouldn't others step up? Buying a controlling stake in it is a possibility. But I don't see why an intelligence agency would make an offer of cash to someone not known to be susceptible to that kind of manipulation. I actually just don't see them doing this full stop. They surely know Nadim is motivated by idealism, not cash. So I can't think of a reason to "acquire" Cryptocat that actually stacks up. To work out what is going on here, you have to put yourself into the mindset of the individuals and organisations involved. And that is not easy if you simply have their media persona to go by.
Like the rest of the population, these organisations tend to be filled with people of many different persuasions, from geeks and activists and hackers through ultra-authoritarians and rogue elements. It's impossible to know which group is responsible for this, or what their motivations might be. It might have even been an unauthorised operation! And it may just as easily have been someone spoofing CSIS, e.g. some hacker group angry at CSIS for some past grievance. If so, I bet it is baking CSIS's noodle just as much as Nadim's!
At any rate, one should never infer a conspiracy where simple administrative or bureaucratic incompetence is a perfectly valid explanation.
The key here is your desktop and how did they access it.
"Alleged CSIS Liaison Officer met me for coffee yesterday. Told me that Cryptocat is national security threat to Canada. That is all."
Pretty sure you would never be able to trace back a CSIS or CSE ip.
I guess they read HN too.
The fact that you don't know about them means ... the plan is working.
excepting missions involving ice hockey, which bring forth a lust which can only be quenched by blood.
In this case, it's plausible enough suspicion, let's give him the benefit of the doubt, eh?
Although, I did have a palestinian friend swear that the Tim Horton's on Guy was a hotbead for the Jordanian security service.