Smuggling Snowden Secrets
firstlook.org
firstlook.org
So, not only can't Johny encrypt (http://www.gaudior.net/alma/johnny.pdf), but neither can security experts when their lives may depend on it. Proving once more that not only do we need better security tools, but - above all - more usable security tools.
I am also not a crypto expert, but as I understand it: Micah could have also encrypted the email with the key given to him by the 'anonymous mailer', included the hash of that key as part of his message and then signed the whole message with his own key. Since Snowden trusted Micah's key, he could verify the email signature and then check that the included hash matched his own key. A MITM attacker could intercept Snowden's first email and change the key, but then Micah would have hashed the fake key and included that in his email, which the MITM couldn't alter without breaking the signature, then Snowden would have seen the wrong hash on the reply email and know of the presence of the attacker.
An anonymous person contacts you - how do you get their key from a public authority? There is no impersonation attack possible in this case.
Someone claiming to be Edward Snowden contacts you today (now that he is longer anonymous) - in this case yes, the author just including their key would not necessarily be secure.
Snowden solved it by requesting the public tweet of Lauras's key fingerprint which was enough. Having the match of the fingerprint is enough. It's much smaller than the whole key. For example, if Laura's key is 4096 bits to print it you'd need around 700 letters. But to verify some 4096 bits you have to actually be Laura's key, it's enough that the fingerprint of, for example, 160 bits match: the math magic involved in creating the fingerprint should guarantee you that nobody can create another key and have the same fingerprint.
In the article, the fingerprint used 4 bits per letter, and there were 40 letters, so it was just 160 bits that Snowden used to verify the key.
There is! Most journalists have a Twitter account or at least some verifiable online identity, so that's exactly what https://keybase.io/ is for.
I do think it's a mistake for them to allow uploading your private key. They really shouldn't be encouraging private key promiscuity like that. Otherwise, I really like the service and hope it catches on.
There is an option to upload an encrypted version of your private key, but you can simply choose not to.
> Russia really didn't want him, but they sure didn't exactly push back considering whatever Snowden had on his person (or remotely access to) and surely has been taken and shared with the Chinese as well.
To be frank, if security (at the NSA) was/is as lax as Snowden claims, then none of the information is probably news to Russia or China. That said, I was under the impression that Russia and China aren't exactly bed-fellows, yet you claim that 'surely' the information has been shared. I don't think that's a foregone conclusion (assuming that there is any new information to share).
> I'm simply trying to provide the deep (on occasion conflicting) loyalties that underlie many security professionals in this country that are married to the ultimate goal of protecting interests domestic and abroad of the United States.
The problem is that protecting US interests isn't some cut-and-dry thing. The CIA trained and funded Osama bin Laden to 'protect US interests' (in repelling the USSR from Afghanistan). How did that work out? The US went into Iraq because "WMDs" existed that Saddam Hussein was going to launch against our allies. How did that work out? The US intelligence community has been pushing for revolution in the Middle East... now we have a bunch of countries in turmoil, and ISIS running rampant. How did that work out?
I remember top US officials claiming that the Iraqis would "welcome us as liberators" as if everyone would just abandon Saddam and start cheering "USA! USA!" as soon as troops cross the border.
I question the qualifications of the people making these decisions.
> They are the best and brightest, and the leadership generally above them are FROM the ranks of trusted/vetted/experienced individuals.
I'm not really sure what this has to do with anything. How does this relate to Snowden? How does this related to NSA whistleblowers? How does this relate to treason even?
Uh, didn't it compromise security by making it possible for someone else to MITM the rest of the emails Snowden received? They see the public key request before he does, send out their key instead, suppress his real response from being sent to them, decrypt mails to him and re-encrypt with his real key so he doesn't notice. AFAICT it indeed didn't compromise his identity, but the privacy and authenticity of the rest of the conversation.
Granted, like a lot of MITM scenarios, using crypto at all drastically raises the bar from permitting passive eavesdropping, to requiring a lot of access and agility to eavesdrop. At least, this is my personal, semi-informed conclusion lately -- I don't know what the experts say.
Yes. The solution is to make him repeat his original message as well, which couldn't have been intercepted because it was encrypted with our own key.
The only solution is to use another channel to authenticate the other's key, be it GPG's web of trust, or any other imperfect way (phone call, physically meeting, ...)
First, Agree on a reply latency -- say, 1 day. Then, instead of simply replying to a message, you have an irritating four-step process:
1. Wait until one day after you received the message.
2. Send a digest of the message and your public key.
3. Wait another day.
4. Send the message itself.
All that sending would be using PGP.The receiver must make sure that the delays for receiving the digest and the reply body are what the expect. This method requires a MITM to either anticipate what the message is or introduce an extra day of latency, which the receiving would notice.
Which might be entirely possible, as Micah has done work for the EFF.
As Einstein said: "Things should be made as simple as possible, but not simpler". By making PGP simpler, you're effectively killing it by adding more and more attack vectors.
https://wiki.debian.org/Keysigning
And add a few instructions like "now email your private key to ..." and people would just go through the motions and do it.
Still though, adding to the traffic out there would probably help - at least a little bit - privacy efforts.
Ann ispects units, then hands them on to Bob who performs a final inspection. Ann is falling behind so she gives the units a quick short less thorough inspection. She knows that Bob will catch the problem. Bob gets a sudden extra load of units, so he too gives them a less rigorous inspection. Bob knows that Ann has previously inspected them. It happens surprisingly often although not quite in that form.
There's a whole bunch of research shwoing what a group of people do when estimating numbers - they tend to clump around whatthe first person says.
I suspect three people checking and ID would be subject to both of these problems.
I might have an old version, but my apk is 1595338 bytes and has SHA256 274f77b0d3da9280c1e728cc53c9348d9454e7f255dcf37e6df925040b8d3c3b.
2nd time Greenwald - use your partner to carry the solid state devices. Lead to the 'drug war sweep' at the airport. Yes, your clothes are removed to 'distract you' and to make sure that you are not 'hiding' any USB drives.
3.) There are few 'excellent journalists' left. That's why WE concentrated all of them on da verge as a single point of failure.
4.)Salient fact: there are only 2 techies that know gpg in the org and the journalists dont care to learn or dont know what is important?
5.)three factor authentication == security. 1 factorr eencyrpted key rates low.
6.)xkcd comic badone has hammer on your head and u will give password. a/pple bio-metrics fooled again by latex clone. no 3 is how u play. game: chess 'sing fortissimo' n-q6 (if I play a rank 1600 move, it means REVOKE credentials, a 1900 move means pass)
7.)thought experiment - the radio operator is parachuted into enemy territory. Captured and turned? or maybe...
8.)increas eing the noise to the signal for the metadata is more important.of the h-l or letter h munus 1 which looks like letter l - -pg for 3 letter acronym - is basic. so, twitter source is too low entropy. steagan image or TWO simple texxt on public website forum means plenty oof of downloaders.
summary 1.)who are the top 3 in the world? 2.)single point of faliure on one email website? 3.)meta-info ENCRYPTED MESSAGE HIDING plus tor, etc trust attack or even simple denial of service attack leaving only the 'bad ones' to be used.
8.)joke crypto. old Russian proverb. we pretend to work and they pretend to play us ... oops pay us..
yoops slay us? So mister red wald start up the joke contest and have plenty of playing the part of the green herring or is it purple herring - fuscia maybe? - i dunno. THIS WIL INNCREASE THE NOISE TO SIGNAL ratio where bad tyoists yuuppsie TYPISTS are then on the tracking list.
Using number theory and the many old people who love to play games and trade joiokes it is now time to look at spam and emails
Crazy to think that NSA wouldn't be monitoring journalists to catch their sources.
Deleted comment
He can say whatever he likes, in whatever way he wants and so can you. Isn't the Internet awesome?
I think the guy was trying to say that this was a war and that the informationin the article shouldn't have been shared, not just that but there was no real substance to what was shared and that the whole article was basically bragging.
Didn't really comment on the substance of what he was saying, other than to say that he was free to say what ever he liked.