An encrypted message to Edward Snowden
wired.com
wired.com
EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage.
EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.
For me, I just have always assumed that electronic communications are easier to compromise than old traditional ones. In the end, you connect to an ISP and packets can be inspected. OK, you might have encryption, but there have been too many schemes cracked or broken. So, why ever think that electronic comms can ever be secure? In the extreme, if the spooks get your encrypted data and they really believe that the data contains the "ticking bomb", they'll just torture you until you give up the key. So, you're still stuffed. Why give them even that much?
More over, the one big issue I have to electronic communications, is that it is very hard to know if you are under surveillance. The old methods give you a better chance to discover that you are being watched. It is also easier to hide the fact that you are communicating at all.
The clincher for me was that a while ago an "amusing" story appeared in a British news paper. Essentially it "exposed" MI6 spies in Moscow using actual drop boxes to pass along information. Now, if MI6 are still using pre-WWII methods, that has to tell you something, right? They don't trust the electronic methods.
So, if secure communications really mattered to me, life or death type mattered, then I'd be looking at things like one time pads, drop boxes, people, etc. Of course a lot of it depends on what you are trying to communicate, how many people are involved, and frankly how much money you have to use.
One thing I do know, electronics would be something I would work very hard to avoid.
Lastly, if I were going to whistle blow to a journalist on this scale, the first thing I would establish would be several methods of communication. Times, places, codes, etc. I suspect that, given the nature of this exposure, that will have been done, and none of it will be electronic.
You can broadcast your message to the world, like number stations do. To anyone without the OTP, it's quite literally impossible to decrypt.
But remember my bit about knowing if you are being watched. Electronic, I have no idea, unless, IIRC, we get quantum about it. Old skool, chances are better. I, or a friend can observe my drop box or exchange, and so on.
Im not saying there are no good electronic methods, I am saying that ultimately I'd be more comfortable not using them. Remember too, I am talking ultimate paranoia, life and death.
In the end of course the weakest link of all is the humans operating any system. I mean, the whole PRISM thing was blown by a human.
The other thing in my mind is that these days spooks expect and are geared up for electronic comms, not so human comms. Budgets slashed, less "watchers", and men on the ground. Going olde skool is a sort of curved ball.
Also, I know paper. I can verify hiding places. I can watch people move. I am not good enough to review, completely and confidently, code and encryption software. I would have to trust programmers I dont know, in a climate where we believe the likes of GCHQ, NSA, etc have back doors and cracks. We are given to understand that these people are all over electronic comms. As far as I know, they have not penetrated writing paper and hiding holes. They are not invisible either. Maybe you and others are good enough to verify all the software, encryption and networking software and hardware sufficiently enough to trust your life to it. I know I'm not.
In short, if my life is on the line, I would go with what I know best. I know paper better than deeply complex mathematics and programming.
Besides, given the revelations, why even bother to risk it? Even before all this, I would laugh my nuts off at terrorists who were caught and convicted using electronic evidence. I thought them idiots for even touching a computer to arrange terrorism. I assume that now, they wont be so stupid. It was nice and easy for the authorities to plunder their computers and and electronic trail. Now their job just got harder.
Maybe Bitmessage helps receiving messages anonymously, but the timing attack might still be possible when sending messages. I2P can mitigate the problem, but I don't think Bitmessage has any nodes in I2P.
I would say that, if you don't trust Poulsen, don't talk to him.
Lamo's role in the Manning case drew the ire of Glenn Greenwald, of Salon Magazine. An ardent supporter of WikiLeaks, Greenwald has been a passionate critic of Lamo, suggesting that Lamo lied to Manning by turning him in, and also lied after the fact to cover up the circumstances of Manning's confessions. Greenwald places the incident in the context of what he calls "the Obama administration's unprecedented war on whistle-blowers". Greenwald's critique of Wired Magazine has drawn a response from that magazine which suggests that Greenwald is writing disingenuously: "At his most reasonable, Greenwald impugns our motives, attacks the character of our staff and carefully selects his facts and sources to misrepresent the truth and generate outrage in his readership." In an article about the Bradley Manning case, Greenwald mentions Wired reporter Kevin Poulsen's 1994 felony conviction for computer hacking, suggesting that "over the years, Poulsen has served more or less as Lamo's personal media voice."
Greenwald is skeptical of an earlier story written by Poulsen about Lamo's institutionalization on psychiatric grounds, writing: "Lamo claimed he was diagnosed with Asperger's Syndrome, a somewhat fashionable autism diagnosis which many stars in the computer world have also claimed." In his response, Poulsen accused Greenwald of "name-calling, bizarre conspiracy theories and ad hominem attacks".
Not sure about the second part, but the fact that Lamo lied to Manning isn't controversial. He's talked about it in a few interviews.
This one was a little odd: http://www.guardian.co.uk/world/2013/jan/03/adrian-lamo-brad...
Encryption is good at keeping the contents secret, but not the source of traffic.
Bitmessage has deniability, but if the receiver end is compromised or untrustworthy, then the deniability is gone, and the timing attack might be possible.
Combining Bitmessage and I2P would be solution, I think, but I don't know of any Bitmessage nodes on I2P.
Bitmessage is only plausibly deniable, meaning a traffic analysis is likely to narrow down the list of senders to a few, which is good enough in a manhunt.
He doesn't need to use anonymity systems now; he just needs to use a service which doesn't report IP address to the other end. A simple VPN or whatever would be fine.
If I were seriously on the run, I'd be using a system with days of latency (variable over 1-5 days), which blended in with a widespread current system. Essentially Len Sassaman's old mixmaster remailer system, which interfaces with the world over SMTP. The problem is there aren't enough mixmaster nodes to be really enough now, so you'd want to use a fairly anonymous sender too, and the old "USENET message pool" style systems don't work now that "USENET" basically means "http access to one of a few big providers", too.
Kind of a step back from where we were in 1999, which is bullshit :(
What about that it isn't safe because of who is running many of the exit nodes?
This is a pretty interesting "where do I start?" paper if you want to know more but don't have much background on the subject:
I posted something to that effect in the article's comments. It was moderated and comments are now closed (at least for me).
"Commenting has been disabled for this article"
http://www.wired.com/threatlevel/2010/06/leak/ http://www.wired.com/threatlevel/2010/06/conscience/
Cute. I'm sure he read Dilbert a few times too.
It takes quite an astonishing level of arrogance to suggest that being an "Ars Technica reader" was an important part of his identity, as that article did. Internet nerd makes a few comments on tech website, huge shock there.
It was tongue-in-cheek.
Anybody with any sense knows you're a plant, not a hacker, and your hacking charges were laid there by the US Attorney to give you cover to turn on real hackers. Wired has been part of the compromised media from the day they published anything written by you.
I've read more about your involvement in the Lamo-Manning conversation, and I've changed my mind. Lamo turned in Manning. But you knew Lamo was planning to deceive Manning to make him confess more leaks in a second chat:
http://www.salon.com/2010/06/18/wikileaks_3/
I can't edit nor delete my original comment since the edit link has expired.
As an important actor in the Lamo-Manning story, I would like to ask you some questions.
- Do you think Adrian Lamo acted ethically?
- What's your opinion on whistle-blowers and their role in democracy?
Thanks.
However, I'd trust Declan McCullagh more than any other journalist I know. He also writes for Wired. He's not uncritical of the PRISM story, but I'd trust him to be fair, and he wouldn't himself become part of the story.
liberationtech seems good; p2p-hackers was ok for a while. the old cryptography list was ok in a couple of the incarnations. cypherpunks before the great decline is still my gold standard, though. (remops has been ok at times; some of the digital gold lists were also interesting).
http://online.wsj.com/article/SB1000142412788732467720457818...
That might be another reason that TOR isn't safe. You don't ever know who any of the other servers belong to ... and the staff at the Exit Node can (and has) read anything. I wouldn't bet my life on software 'originally sponsored by the U.S. Naval Research Laboratory'.
From what I understand an awful lot of them are run by the US government.
gpg: armor: BEGIN PGP MESSAGE
gpg: armor header: Version: GnuPG/MacGPG2 v2.0.19 (Darwin)
gpg: armor header: Comment: GPGTools - http://gpgtools.org
:pubkey enc packet: version 3, algo 1, keyid 5B50940B79DEBE35
data: [4096 bits]
gpg: public key is 79DEBE35
:encrypted data packet:
length: unknown
mdc_method: 2
gpg: encrypted with RSA key, ID 79DEBE35
gpg: decryption failed: secret key not available
Of course, they could have used --hidden-encrypt-to, but I think it's more likely a publicity stunt.Oh, and if you do find a key claiming to be for Edward Snowden online, verify that it's actually him, ideally through the web of trust, and that it isn't just a key that was created after the news was leaked. I'd be wary of any keys on keyservers claiming to be him that have been uploaded after he went public with this.
Oh wait. That plan only works for federal agencies and secret courts. Never mind.
Having said, that, according to PGP Dump
Old: Public-Key Encrypted Session Key Packet(tag 1)(524 bytes)
New version(3)
Key ID - 0x5B50940B79DEBE35
Pub alg - RSA Encrypt or Sign(pub 1)
RSA m^e mod n(4096 bits) - ...
-> m = sym alg(1 byte) + checksum(2 bytes) +
PKCS-1 block type 02
New: Symmetrically Encrypted and MDC Packet(tag 18)(4096
bytes) partial start
Ver 1
Encrypted data [sym alg is specified in pub-key
encrypted session key]
(plain text + MDC SHA1(20 bytes))
New: (1024 bytes) partial continue
New: (18 bytes) partial end
It looks like we can merely see that the message is destined to 0x5B50940B79DEBE35. We won't be able to tell who's signer until it is decrypted. $ gpg --recv-key '0x5B50940B79DEBE35'
gpg: requesting key 79DEBE35 from hkp server subkeys.pgp.net
gpg: key 2BE0BC29: public key "Verax (Informed Democracy Front)" imported
gpg: Total number processed: 1
gpg: imported: 1 (RSA: 1)
Claims to have been created May 20, 2013, though it's only self-signed: $ gpg --list-sigs 2BE0BC29
pub 4096R/2BE0BC29 2013-05-20
uid Verax (Informed Democracy Front)
sig 3 2BE0BC29 2013-05-20 Verax (Informed Democracy Front)
sub 4096R/79DEBE35 2013-05-20
sig 2BE0BC29 2013-05-20 Verax (Informed Democracy Front) # gpg --list-packets /tmp/snowden.asc
:pubkey enc packet: version 3, algo 1, keyid 5B50940B79DEBE35
data: [4096 bits]
:encrypted data packet:
length: unknown
mdc_method: 2
gpg: encrypted with 4096-bit RSA key, ID 79DEBE35, created 2013-05-20
"Verax (Informed Democracy Front)"
(79DEBE35 can be found on the subkeys.pgp.net keyserver)"A public and private key each have a specific role when encrypting and decrypting documents. A public key may be thought of as an open safe. When a correspondent encrypts a document using a public key, that document is put in the safe, the safe shut, and the combination lock spun several times. The corresponding private key is the combination that can reopen the safe and retrieve the document. In other words, only the person who holds the private key can recover a document encrypted using the associated public key."
I'm not a crypto type but I believe what you want is a password-based key derivation function such as scrypt, the output of which you can then use as the symmetric key to encrypt/decrypt the private key. (This might even be what GPG/SSH does for you; I'm not at all sure)
Most people using software only solutions won't ever have their keys stolen, but that's because nobody tried to steal them. The compromise of a client os is inevitable if targeted by a competent actor, given enough time.
Smartcards and HSM's may not be infallible, but their rate of compromise appears to be negligable at best and an extremely rare capability for an offensive team to have access to.
Smartcards are surprisingly cheap and easy to work with, and due to their simplicity and long history are quite secure. The only real attack on them involves physical access and causes obvious physical damage that'd be impossible to miss.
http://shop.kernelconcepts.de/index.php?cPath=1_26&sort=2a&l...
https://www.opensc-project.org/opensc/wiki/OverView
this would probably be the place to start, at least to figure out which type of card you'd want. The main choices are a) support pgp and ssh b) support x.509 certificate based signing c) support time or use type tokens (like smartphone 2 factor apps) or d) some non standardized system running custom code on a tiny jvm inside the card.
a) would be what you'd want in the context of this conversation, but b) is much more supported and has a wider set of use cases.
In most cases it amounts to making sure you buy the right card & reader, plugging it in, and compiling the opensc and related packages
It seems quite unlikely the masses would have access to a trusted platform of any kind, especially considering that any secure platforms for communication that have existed, like Skype, have been opened up. Even good old GSM (AS/1 was it called?) voice-talk encryption was designed with a backdoor in mind at the urging of NATO.
Even assuming it's a compromised platform it's still a hell of a lot more likely to keep your key material safe as compared to having it sit on disk or in addressable address space. One presumes backdoors like that are used sparingly as they become considerably less valuable once publicly exposed.
I recommend disconnecting your monitor and only receiving output by having it blinked out at you through your capslock light on your keyboard. Bonus points if you can get your hands on some TEMPEST hardened hardware, and/or tamper-resistant hardware.
Anything less will leave you vulnerable to the black helicopters!
Note: I'm joking obviously, but this is something to take seriously.
Edit: obviously the 24V must come from a battery which is charged only at specific intervals -- otherwise they can interpret your messages by watching mains voltage variation.
Bonus: Anyone surveilling you via audio bugs will need new ears.
As long as you have a flexible hardware platform that lets you crank up some of the voltage regulator outputs, gpios that can be attached to a long trace/external wire as a makeshift antenna and have a decently fast cpu clock you have all the ingredients for a crude but usable software defined radio. maybe not super fast if you can't repurpose a hardware phy or radio interface, but more than enough bandwidth to exfil a secret key or 10 for maybe a couple dozen meters.
Tools to do sdr utilizing only general purpose processors and no radio specific gear are already available here and there as research implementations, and code that uses gpus/audio dacs/ and re-purposed phys to make a radio interface with a different spec or broadcast frequency is already in production use (wifi phy using a dvb radio interface -> tv whitespace communicator).
Using an approach like that to exfil or bridge an air gap is just too tempting for it to not happen. Honestly, I'd be willing to bet there's already an example of that somewhere out there in the wild today.
Examples of genuine vulnerabilities that would make you look paranoid just by defending against:
* Make educated guesses about passwords from a microphone recording of the keypresses. Both the intervals between keypresses indicate the region of the keyboard being touched, and the sound of each key differs slightly. Given a statistically significant sample of typing, you could deduce which keys are which based on the frequency of their use. http://www.securityfocus.com/news/11318
* Read a screen through a reflection, even from far away http://www.schneier.com/blog/archives/2008/05/spying_on_comp...
It's times like these, I'm grateful for limited terms of office, and a politically divided country.
"If you want to be extra safe, check that there's a big block of jumbled characters at the bottom."
:)
$ gpg -vvv -d letter-to-snowden.txt
gpg: using character set `utf-8'
gpg: WARNING: using insecure memory!
gpg: please see http://www.gnupg.org/documentation/faqs.html for more information
gpg: armor: BEGIN PGP MESSAGE
gpg: armor header: Version: GnuPG/MacGPG2 v2.0.19 (Darwin)
gpg: armor header: Comment: GPGTools - http://gpgtools.org
:pubkey enc packet: version 3, algo 1, keyid 5B50940B79DEBE35
data: [4096 bits]
gpg: public key is 79DEBE35
:encrypted data packet:
length: unknown
mdc_method: 2
gpg: encrypted with RSA key, ID 79DEBE35
gpg: decryption failed: secret key not availableVerax was the name used by Snowden to communicate with Laura Poitras (and perhaps others as well), but the story didn't break until June 5 and his identity wasn't revealed until days later.
So why is Wired encrypting a message with a key using that name that was generated before the name was publicly known in association with Snowden?
EDIT: Disregard the above—the "encrypted with" key is the recipient's key, not the sender/signer. 79DEBE35 may well be Snowden's key (but that's not proven either).
I can't tell what key the message is encrypted for. They may have used --hidden-recipient
The NSA is known[1] to be able to take advantage of weaknesses found (or planted) in crypto algorithms, however, not in PGP[2] and other strong ones.
1. http://en.wikipedia.org/wiki/Cryptography#NSA_involvement
2. http://www.philzimmermann.com/EN/faq/faq.html (3rd question)
Is that possible? To epxloit a decryptor software while it is decrypting something.
I couldn't find anything running a couple of programs on it, but then again I don't have the contents of the attached message.
For a back-of-the-envelope cost estimate, I'm going to assume that there have been no major theoretical breakthroughs in the last couple of years, and that the machines they used were roughly equivalent to an EC2 "medium" instance. That puts the cost of breaking a 768-bit key, using spot instances for cost-efficiency, at about US$200k.
That sounds small, but encryption/decryption are still reasonably efficient with larger keys, while factorization becomes vastly harder. Breaking a 2048-bit key would take something like 200 quadrillion dollars worth of CPU time. A 4096-bit key, like the one used for this message, would be vastly more secure than that.
Remember, the NSA's mandate is twofold: They are a signals intelligence agency, but they are also charged with protecting government communications, much of which occur with commercially-available cryptography.
RSA does make people nervous for some valid reasons, and that's why there's a gradual transition to ECC underway, but there's little reason to expect a practical attack on RSA at 2048+ bits in the near term.
Absent an operational error on the part of Wired or Snowden, I seriously doubt the NSA will be decrypting that message in Snowden's lifetime, and almost certainly not before changes in the political climate.
That's a lot of doublings of the difficulty to brute force a key. 2^3328 increase in difficulty.
$ gpg --keyserver pgp.mit.edu --recv-keys 79DEBE35
$ gpg --encrypt --sign --armor --recipient 79DEBE35
and post it publicly; perhaps on Pastebin.[1]: http://www.washingtonpost.com/world/national-security/code-n...
*assuming you believe the key is authentic
Edit: Also, it's not very hard to generate a different key with signature 79DEBE35, and put it on the key servers. gpg's displaying of such short abbreviations for keys is one the worst parts of its UI.
How do you know this?
It's still "my" key even though you're signing or rather encrypting a message with it.
We don't know who that key belongs to for sure, of course, but it could be Snowden's.
EDIT: While what I said was technically true, in that it is encrypted with the 79DEBE35 key, that's not Wired's key, it's the recipient's key.
Yup: http://www.asheesh.org/note/debian/short-key-ids-are-bad-new...
Also, there's no other way to get the message to Snowden unless you give it publicity. If he browses the Internet for news, he will find there's a message from Wired for him.