EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage.
EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.
EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage.
EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.
http://www.wired.com/threatlevel/2010/06/leak/ http://www.wired.com/threatlevel/2010/06/conscience/
I've read more about your involvement in the Lamo-Manning conversation, and I've changed my mind. Lamo turned in Manning. But you knew Lamo was planning to deceive Manning to make him confess more leaks in a second chat:
http://www.salon.com/2010/06/18/wikileaks_3/
I can't edit nor delete my original comment since the edit link has expired.
As an important actor in the Lamo-Manning story, I would like to ask you some questions.
- Do you think Adrian Lamo acted ethically?
- What's your opinion on whistle-blowers and their role in democracy?
Thanks.
Cute. I'm sure he read Dilbert a few times too.
It takes quite an astonishing level of arrogance to suggest that being an "Ars Technica reader" was an important part of his identity, as that article did. Internet nerd makes a few comments on tech website, huge shock there.
It was tongue-in-cheek.
Anybody with any sense knows you're a plant, not a hacker, and your hacking charges were laid there by the US Attorney to give you cover to turn on real hackers. Wired has been part of the compromised media from the day they published anything written by you.
Lamo's role in the Manning case drew the ire of Glenn Greenwald, of Salon Magazine. An ardent supporter of WikiLeaks, Greenwald has been a passionate critic of Lamo, suggesting that Lamo lied to Manning by turning him in, and also lied after the fact to cover up the circumstances of Manning's confessions. Greenwald places the incident in the context of what he calls "the Obama administration's unprecedented war on whistle-blowers". Greenwald's critique of Wired Magazine has drawn a response from that magazine which suggests that Greenwald is writing disingenuously: "At his most reasonable, Greenwald impugns our motives, attacks the character of our staff and carefully selects his facts and sources to misrepresent the truth and generate outrage in his readership." In an article about the Bradley Manning case, Greenwald mentions Wired reporter Kevin Poulsen's 1994 felony conviction for computer hacking, suggesting that "over the years, Poulsen has served more or less as Lamo's personal media voice."
Greenwald is skeptical of an earlier story written by Poulsen about Lamo's institutionalization on psychiatric grounds, writing: "Lamo claimed he was diagnosed with Asperger's Syndrome, a somewhat fashionable autism diagnosis which many stars in the computer world have also claimed." In his response, Poulsen accused Greenwald of "name-calling, bizarre conspiracy theories and ad hominem attacks".
Not sure about the second part, but the fact that Lamo lied to Manning isn't controversial. He's talked about it in a few interviews.
This one was a little odd: http://www.guardian.co.uk/world/2013/jan/03/adrian-lamo-brad...
However, I'd trust Declan McCullagh more than any other journalist I know. He also writes for Wired. He's not uncritical of the PRISM story, but I'd trust him to be fair, and he wouldn't himself become part of the story.
liberationtech seems good; p2p-hackers was ok for a while. the old cryptography list was ok in a couple of the incarnations. cypherpunks before the great decline is still my gold standard, though. (remops has been ok at times; some of the digital gold lists were also interesting).
I posted something to that effect in the article's comments. It was moderated and comments are now closed (at least for me).
"Commenting has been disabled for this article"
Encryption is good at keeping the contents secret, but not the source of traffic.
He doesn't need to use anonymity systems now; he just needs to use a service which doesn't report IP address to the other end. A simple VPN or whatever would be fine.
If I were seriously on the run, I'd be using a system with days of latency (variable over 1-5 days), which blended in with a widespread current system. Essentially Len Sassaman's old mixmaster remailer system, which interfaces with the world over SMTP. The problem is there aren't enough mixmaster nodes to be really enough now, so you'd want to use a fairly anonymous sender too, and the old "USENET message pool" style systems don't work now that "USENET" basically means "http access to one of a few big providers", too.
Kind of a step back from where we were in 1999, which is bullshit :(
Bitmessage has deniability, but if the receiver end is compromised or untrustworthy, then the deniability is gone, and the timing attack might be possible.
Combining Bitmessage and I2P would be solution, I think, but I don't know of any Bitmessage nodes on I2P.
Bitmessage is only plausibly deniable, meaning a traffic analysis is likely to narrow down the list of senders to a few, which is good enough in a manhunt.
Maybe Bitmessage helps receiving messages anonymously, but the timing attack might still be possible when sending messages. I2P can mitigate the problem, but I don't think Bitmessage has any nodes in I2P.
I would say that, if you don't trust Poulsen, don't talk to him.
For me, I just have always assumed that electronic communications are easier to compromise than old traditional ones. In the end, you connect to an ISP and packets can be inspected. OK, you might have encryption, but there have been too many schemes cracked or broken. So, why ever think that electronic comms can ever be secure? In the extreme, if the spooks get your encrypted data and they really believe that the data contains the "ticking bomb", they'll just torture you until you give up the key. So, you're still stuffed. Why give them even that much?
More over, the one big issue I have to electronic communications, is that it is very hard to know if you are under surveillance. The old methods give you a better chance to discover that you are being watched. It is also easier to hide the fact that you are communicating at all.
The clincher for me was that a while ago an "amusing" story appeared in a British news paper. Essentially it "exposed" MI6 spies in Moscow using actual drop boxes to pass along information. Now, if MI6 are still using pre-WWII methods, that has to tell you something, right? They don't trust the electronic methods.
So, if secure communications really mattered to me, life or death type mattered, then I'd be looking at things like one time pads, drop boxes, people, etc. Of course a lot of it depends on what you are trying to communicate, how many people are involved, and frankly how much money you have to use.
One thing I do know, electronics would be something I would work very hard to avoid.
Lastly, if I were going to whistle blow to a journalist on this scale, the first thing I would establish would be several methods of communication. Times, places, codes, etc. I suspect that, given the nature of this exposure, that will have been done, and none of it will be electronic.
You can broadcast your message to the world, like number stations do. To anyone without the OTP, it's quite literally impossible to decrypt.
But remember my bit about knowing if you are being watched. Electronic, I have no idea, unless, IIRC, we get quantum about it. Old skool, chances are better. I, or a friend can observe my drop box or exchange, and so on.
Im not saying there are no good electronic methods, I am saying that ultimately I'd be more comfortable not using them. Remember too, I am talking ultimate paranoia, life and death.
In the end of course the weakest link of all is the humans operating any system. I mean, the whole PRISM thing was blown by a human.
The other thing in my mind is that these days spooks expect and are geared up for electronic comms, not so human comms. Budgets slashed, less "watchers", and men on the ground. Going olde skool is a sort of curved ball.
Also, I know paper. I can verify hiding places. I can watch people move. I am not good enough to review, completely and confidently, code and encryption software. I would have to trust programmers I dont know, in a climate where we believe the likes of GCHQ, NSA, etc have back doors and cracks. We are given to understand that these people are all over electronic comms. As far as I know, they have not penetrated writing paper and hiding holes. They are not invisible either. Maybe you and others are good enough to verify all the software, encryption and networking software and hardware sufficiently enough to trust your life to it. I know I'm not.
In short, if my life is on the line, I would go with what I know best. I know paper better than deeply complex mathematics and programming.
Besides, given the revelations, why even bother to risk it? Even before all this, I would laugh my nuts off at terrorists who were caught and convicted using electronic evidence. I thought them idiots for even touching a computer to arrange terrorism. I assume that now, they wont be so stupid. It was nice and easy for the authorities to plunder their computers and and electronic trail. Now their job just got harder.
http://online.wsj.com/article/SB1000142412788732467720457818...
That might be another reason that TOR isn't safe. You don't ever know who any of the other servers belong to ... and the staff at the Exit Node can (and has) read anything. I wouldn't bet my life on software 'originally sponsored by the U.S. Naval Research Laboratory'.
From what I understand an awful lot of them are run by the US government.
What about that it isn't safe because of who is running many of the exit nodes?
This is a pretty interesting "where do I start?" paper if you want to know more but don't have much background on the subject: