Lulzlabs AirChat: Free Communications For Everyone.
github.com
github.com
Here's the relevant regulation in the UK license: "11(2) The Licensee shall only address Messages to other Amateurs or to the stations of those Amateurs and shall not encrypt these Messages for the purpose of rendering the Message unintelligible to other radio spectrum users."
The idea, in the AirChat proposal, that institutions like the FCC, OFCOM, etc. are 'evil' because they regulate spectrum is ridiculous. The only reason we can communicate successfully on radio is because someone is regulating who gets to use what and how. The AirChat proposal mentions using the Yaesu FT-897D for test transmissions. That's a ham radio operating in the specific bands licensed for hams to use. So, these guys are (a) breaking the law (which they don't care about) and (b) messing things up for other radio users.
There was a practical reason to prevent coded transmissions during the cold war -- by doing so, it allowed cross-border communications which countries otherwise would have banned. Bilateral communications between individuals made war less likely and peace more possible. It wasn't to keep the radio spectrum safe from commercial use (since commercial users didn't use crypto, either, at the time).
There are other whole classes of amateur radio use which are precluded or seriously hindered by lack of encryption -- disaster work which communicates PII in a medical context, certain police or security backup use.
I'd like to see encryption permitted on certain bands; some where the keys are required to be exchanged in the clear (for protocol development), and some where people can use real keys but still tag the communications with their callsign and be aware of and responsive to any interference.
ISM is inadequate due to frequency bands; if the proposal is to open up dramatically larger parts of the spectrum to ISM-type use, then I could be fine with that too.
That would make sense if it was clearly on the band plan.
I don't understand this. Roads are a common resource but (so far) we're not forced to ride only in buses. Also, one can have a conversation in a 'cryptic' language, or is that prohibited as well ? :)
I fail to understand your analogy about buses and cars.
Amateur radio is about amateurs learning about, improving and using radio. It is not about private conversations. If you allow encryption on the amateur bands then you are de facto excluding others. Part of the joy of amateur radio is picking a transmission out of the air, listening to it or 'decoding' (not in the cryptographic sense) the transmission scheme used.
I would suggest that Lulzlabs people look at not using an amateur radio band. There are unlicensed bands that they could use for this purpose. e.g. http://en.wikipedia.org/wiki/ISM_band
If encrypted comms were allowed on open bands, commercial users would probably use the free spectrum and it would be difficult/impossible to get them not to.
This just seems silly and insecure. Noone in their right mind would use this for any kind of serious secure communication. Personally I'd wait for someone to remove all the extraneous stuff, make a real protocol definition and make this modular (for example, split the web-interface from the server).
Great idea though, and a nice proof-of-concept, I'd give them that. There might be a real need for something like this when governments shut down or block internet connectivity.
It totally flies in the face of open collaboration however.
The video is quite interesting, it shows the proof of concept.
I agree about the source code though, they have tried too hard being "lulz" at the expense of readability.
This project is very, very interesting. Unfortunately it requires some investment in the radio equipment, but I can see in a few months some Arduino bundles with this code and the radio antenna...
eval{$penis = $cgi->param('postfield')};
eval{$penispenis = $cgi->param('postfield')};In fact you even acknowledge this in the last paragraph. This sounds like a cheap stab at Perl.
Clearly, the author is better at home breaking software than making it. And it's fine. He or she also has certain amount of artistic leeway in expression, but not excuse from secure programming.
Plus this thing is meant to evade governments; you can't expect something this hideous to be audited, and used, and for others to trust their lives with.
1) "over-regulated by evil organizations like the FCC and similars shits around the world" yet using technology that is only available for use because of the FCC. If the FCC didn't set aside radio frequency bands for non-commercial use, this project would be infeasible because the radio bands would be in use already. The FCC and its ilk is the only real reason that ham operators can operate - the frequencies have been set aside for licensed amateur use.
2) "transmissions are anonymous" but only in data - radio location is as old a location technology as radio itself. Many GA aircraft still use radio beacons as fallback when GPS and VOR signals go down. It's simple, anybody can do it, and unless you're on the move, you will be found.
3) "We don't give a fucking shit about prohibitions over the use of encryption. fuck you NSA." And yet it's probably not the NSA who will care the most, but the FCC (ironically the group with the specialized equipment vans capable of finding you). Worse, if too much non-licensed, encrypted communication happens over radio (especially the frequencies reserved for ham radio), it's possible that the FCC will revoke the non-commercial use of the airspace, which would cause a whole host of other problems. That frequency space (which includes a number of harmonic frequencies throughout the radio spectrum from ULF to UHF) is ridiculously valuable, because it's a finite and highly contested resource.
I applaud the concept and idea, and cringe over the consequences and ignorance thereof.
At that moment I didn't realise how awesome it was, but in retrospect it was pure self-organised anarchy, without any commercial or governmental interference.
Regarding this AirChat, it is sad that they, as it appears to me, did not make usage of the expertise from the amateur radio community. Still, I believe that it has potential.
Be careful kids, you're playing with fire.
"Basically the script encrypts a randomly generated ephemeral key using RSA but then ignores it and uses the above hardcoded key for symmetric encryption."
[1] http://www.daemon.de/blog/2014/04/25/351/code-review-lulzlab...
"We ended up with a simple protocol packet: the Lulzpacket. This simple packet contains information to verify there was no corruption during the transmission and a random code to pseudo-identify the packet. We define the addresses of nodes in the net by their ability to decrypt a given packet. Addresses are derived from the hashes of asymmetric encryption keys, Every radio node defines its own address by the pair of keys it has generated for itself and the addresses change if users choose to regenerate their keys. Each node only cares for what is being received. No hardware identification, no transmitter plain identification. only packets matter. transmissions are anonymous. whenever an address is needed to reply to a packet, it is encrypted inside the packet. Packets targeting specific addresses are encrypted and they must be decrypted by the private key only the target possesses. Anyone trying to spoof an address will not be able to decrypt the packet."
[1]:https://github.com/lulzlabs/AirChat/blob/master/Airchat-Rele...
Big part of this would need to be software stack that would replace DNS (centralized, single source of truth) with something distributed (every P2P mesh can have it's own 'domains' - let's just assume there is no way to coordinate globally except each subnet having different random prefix).
Combine with encrypted tunnels over the old compromised internet to link the cities together.
Fck ISPs, fck mobile operators and their builtin surveillance. Impossible to turn off, government-proof, apocalypse-proof...
This is probably not super useful for anyone who wants to deploy practical infrastructure with audio transceivers. See tools like dsptunnel for IP-over-audio solutions.
>ofc, man. thou we require your girlfriend to deliver tits or gtfo. (sorry but it's needed to help us on the datamining of frequencies usage and transmission mode performance raw data through our Hadoop cluster of ARM servers, all those pix will be used for the datalink test.. err...derp)
This is sexist filth.
The code, the readme, and all the other bits are in standard "lulzsec" tone. There is no dissemblance to feign respect for your sensibilities, they don't care. At least they're honest.
I'd be very interested in an SDR application which strove for undetectable communications, either super high chirp rate FHSS or UWB.
In practice, you're probably best off by masquerading as another communications technology and hiding your traffic within that, rather than trying to use long-haul broadcast RF to hide your location. A common technique if you do need to radiate a lot of RF and don't want to be DF'd is to remote the transmitter from yourself over some other protocol -- a separate point to point radio link, or stored communications, or an IP/PSTN/etc. link. This is how a lot of pirate radios, military radios and radars, etc. work -- the emitter is at risk, but as long as you can break the link between emitter and controller, that's not the end of the world.
http://en.wikipedia.org/wiki/Self-Organized_Time_Division_Mu...
It assigns time slots to users without the involvement of a central station.
On the bright side maybe this will help encryption become legal for ham radio.
I'm not one to really care about what other people think, but on the other hand, there's no reason to portray yourself in a negative light needlessly. It'll just alienate people from your goals for no reason.