741 karma · joined March 29, 2013
In order for an active adversary to perform a successful MITM attack against a TOFU scheme they would need to successfully determine when someone is seeing a fingerprint for the first time (or get lucky) and then successfully maintain their MITM position across every single network the device uses, forever. If they fail at either of those, the user will be warned.
I keep bringing up SSH because it's an example of a fingerprint verification system based on TOFU that works incredibly well at preventing MITM attacks. No one is having key signing parties with their servers, and yet connections remain secure.
In reality, TOFU is a form of key verification and it is highly effective against MITM attacks because there's no way for an adversary to reliably determine whether or not a user is seeing a fingerprint for the first time. If at any point the fingerprint changes, the users are warned.
Users can also easily check and compare fingerprints too. They are not mutually exclusive.
https://github.com/WhisperSystems/Signal-iOS/wiki/FAQ#can-i-...
https://developer.android.com/tools/publishing/app-signing.h...
I considered using Squid somewhere in Streisand, thinking that it might be a nice feature for mobile users in particular. However, one of my main goals with this project was to set up servers that didn't log any information under any circumstances about the sites that clients were visiting or their IP addresses. A caching proxy by definition is going to have to store some of the assets that users are requesting, so I abandoned the idea. Perhaps you are using it differently though?
I appreciate the feedback! By the way, your email does not appear to be in your profile.
It's worth pointing out that most of the services Streisand sets up have already been configured with countermeasures against passive scans. For example, Shadowsocks doesn't respond with any identifying information at all unless you have the proper symmetric key, and OpenVPN will drop all traffic immediately if the connecting client can't sign its requests properly for the HMAC firewall.
I meant that people can easily start more servers when a censorship event happens.
I intentionally made it really easy to override the default values that I chose for port numbers. It wouldn't be difficult to mix those up in the future, if necessary.
I did my very best to make sure that I was configuring things in a secure way. My approach to installing OpenVPN involves several additional steps that harden its security, like setting up an HMAC firewall and changing the default cipher from Blowfish to AES, for example. I take this seriously and I want to do it right. I'm looking forward to getting contributions from the community too.
I think that automation has the potential to significantly increase security because painful tasks that might be tempting to skip when someone is setting things up by hand can become painless. In an ideal world every task can be performed correctly and repeatedly.
I also did my best to fully document every single action that is taken. You can see what is happening at at all times throughout the process. Ansible's syntax is also very readable, so you can examine the steps before you run anything too. I am optimistic that things will only get better :)
The use case is to make it easier for people to set up servers that allow individuals who live in countries where the Internet is being blocked to circumvent these restrictions.
"Silence censorship" is meant to be sort of funny, but the idea is that censors have had it too easy for too long, and an automated and repeatable method of setting up an anti-censorship server can help change that.
"Automate the effect" is meant to reflect the fact that you can start as many of these servers as you want. If a country starts censoring the Internet, more servers will spring up in response.
I hope these explanations make sense. I will try to figure out a way to make the README more clear.
Edit: I'm still working through a few other Ansible 1.6.8 issues as well.
Edit 2: I think that I got them all.
For now, Streisand can execute on any standard Debian 7 server and configure it appropriately. It only needs an open SSH port and an account on the system with root permissions. AWS, DigitalOcean, Linode, and Rackspace are the options it supports for creating a brand new server from scratch as well.
Google does not have access to any metadata, other than the fact that you are a TextSecure user who has received a Push notification. GCM payloads are fully encrypted. Google cannot tell who a message was from, they cannot see which numbers were involved (users are free to register with a number that is different than the one assigned to the cell phone that is running TextSecure), they cannot tell whether or not it was part of a group conversation, and they cannot see its contents.
Apple also has root access to all iOS devices via their over-the-air update framework. Opaque basebands and graphics chips with closed source drivers are difficult to trust too. None of these scenarios mean that software which offers serious improvements over the status quo should be casually dismissed. TextSecure can (and does) provide significant protection from mass surveillance and targeted surveillance. Security nihilism is corrosive.