HNHacker News
TopNewBestAskShowJobs

jlund

741 karma · joined March 29, 2013

Joshua Lund
submissionscomments
jlund··on Let Math Save Our Democracy
I wanted this article to be about encryption.
jlund··on Signal 2.0 released with private messaging support
Yeah, I don't think we actually disagree. Key verification is important, which is why it's a feature in Signal.

In order for an active adversary to perform a successful MITM attack against a TOFU scheme they would need to successfully determine when someone is seeing a fingerprint for the first time (or get lucky) and then successfully maintain their MITM position across every single network the device uses, forever. If they fail at either of those, the user will be warned.

I keep bringing up SSH because it's an example of a fingerprint verification system based on TOFU that works incredibly well at preventing MITM attacks. No one is having key signing parties with their servers, and yet connections remain secure.

jlund··on Signal 2.0 released with private messaging support
That's like saying that SSH isn't more secure than Telnet unless you personally drive to the data center and verify the fingerprints of every single server by hand.

In reality, TOFU is a form of key verification and it is highly effective against MITM attacks because there's no way for an adversary to reliably determine whether or not a user is seeing a fingerprint for the first time. If at any point the fingerprint changes, the users are warned.

Users can also easily check and compare fingerprints too. They are not mutually exclusive.

jlund··on Signal 2.0 released with private messaging support
You can install Signal on a WiFi-only iPad and use any phone number to register. This will also be the case for the upcoming desktop client.
jlund··on Signal 2.0 released with private messaging support
TOFU has proven to be quite resilient against MITM attacks. Do you think it's a stretch to say that SSH is secure?
jlund··on Signal 2.0 released with private messaging support
MMS messages are sent and received by your cellular carrier.
jlund··on Signal 2.0 released with private messaging support
Signal ties into your phone's existing address book. You can add someone new using the iOS Contacts application.
jlund··on Signal 2.0 released with private messaging support
Keys are trusted on first use, similar to SSH. The app also provides an interface you can use to verify fingerprints:

https://github.com/WhisperSystems/Signal-iOS/wiki/FAQ#can-i-...

jlund··on China Cracks Down on VPN Services After Censorship System ‘Upgrade’
The DigitalOcean provisioning issue was recently fixed, and creating new droplets is working properly. Making the mirroring segment more resilient to failures is high on my list of priorities. Thanks for the positive feedback!
jlund··on Silent Circle's warrant canary is out of date
That's correct. Android will warn you if the signatures don't match too. Even if we're in the full-on conspiracy theory territory of Google disabling that core security feature, impersonating a third-party developer, and dropping a binary onto a single user's phone, they still couldn't fake the signature.
jlund··on Silent Circle's warrant canary is out of date
Except for the fact that Google does not have the signing keys that are used for the TextSecure binaries. They cannot silently distribute a binary that has been tampered with. This distributed trust system is one of Android's strengths:

https://developer.android.com/tools/publishing/app-signing.h...

jlund··on Show HN: Streisand – Silence censorship, automate the effect
It works great on micro instances. That's actually the default option for new EC2 instances that it creates.
jlund··on Show HN: Streisand – Silence censorship, automate the effect
I honestly hadn't even heard of AAA in the context of RADIUS before reading about it on Wikipedia just now. I only tangentially know about RADIUS from seeing it in various WiFi control panels over the years.

I considered using Squid somewhere in Streisand, thinking that it might be a nice feature for mobile users in particular. However, one of my main goals with this project was to set up servers that didn't log any information under any circumstances about the sites that clients were visiting or their IP addresses. A caching proxy by definition is going to have to store some of the assets that users are requesting, so I abandoned the idea. Perhaps you are using it differently though?

I appreciate the feedback! By the way, your email does not appear to be in your profile.

jlund··on Show HN: Streisand – Silence censorship, automate the effect
Thank you. I'm using Ansible's vars_prompt functionality to ask for these values. I'm not sure if there is a way to skip a prompt if the information is already available. I don't think there is right now, but Ansible is adding new features fast and I will keep this in mind.
jlund··on Show HN: Streisand – Silence censorship, automate the effect
I haven't ever done anything with port knocking before, but it's a neat idea that could also be entertaining.

It's worth pointing out that most of the services Streisand sets up have already been configured with countermeasures against passive scans. For example, Shadowsocks doesn't respond with any identifying information at all unless you have the proper symmetric key, and OpenVPN will drop all traffic immediately if the connecting client can't sign its requests properly for the HMAC firewall.

jlund··on Show HN: Streisand – Silence censorship, automate the effect
That would be extremely cool. Maybe someday!

I meant that people can easily start more servers when a censorship event happens.

jlund··on Show HN: Streisand – Silence censorship, automate the effect
You are very welcome! Please let me know if you have any feedback or suggestions after you give it a shot. It sounds like you might be in a country where deep packet inspection is happening, and you are exactly the type of person I am hoping to help.
jlund··on Show HN: Streisand – Silence censorship, automate the effect
Yes. OpenVPN (wrapped in stunnel), OpenSSH, Shadowsocks, and Tor (with the obfs3 and ScrambleSuit pluggable transports) are all effective against the Great Firewall. Streisand sets up and configures all of them.
jlund··on Show HN: Streisand – Silence censorship, automate the effect
No problem. I totally understand.

I intentionally made it really easy to override the default values that I chose for port numbers. It wouldn't be difficult to mix those up in the future, if necessary.

I did my very best to make sure that I was configuring things in a secure way. My approach to installing OpenVPN involves several additional steps that harden its security, like setting up an HMAC firewall and changing the default cipher from Blowfish to AES, for example. I take this seriously and I want to do it right. I'm looking forward to getting contributions from the community too.

I think that automation has the potential to significantly increase security because painful tasks that might be tempting to skip when someone is setting things up by hand can become painless. In an ideal world every task can be performed correctly and repeatedly.

I also did my best to fully document every single action that is taken. You can see what is happening at at all times throughout the process. Ansible's syntax is also very readable, so you can examine the steps before you run anything too. I am optimistic that things will only get better :)

jlund··on Show HN: Streisand – Silence censorship, automate the effect
Thanks! Bandwidth usage would probably become a limiting factor before CPU. It also depends on which mix of services was being used. The services are all lightweight enough that I don't think you'd have any issue with lots and lots of concurrent users, even on a Micro.
jlund··on Show HN: Streisand – Silence censorship, automate the effect
Very cool! I'll try to find some time to test the other providers, and assuming everything looks good then I can add a link to this in the README.
jlund··on Show HN: Streisand – Silence censorship, automate the effect
Ha! This is going to be stuck in my head all day now.
jlund··on Show HN: Streisand – Silence censorship, automate the effect
It sets up a new server running L2TP/IPsec, OpenSSH, OpenVPN, Shadowsocks, Stunnel, and a Tor bridge. It also generates custom configuration instructions for all of these services. At the end of the run you are given an HTML file with instructions that can be shared with friends, family members, or fellow activists that will help them connect to the new server.

The use case is to make it easier for people to set up servers that allow individuals who live in countries where the Internet is being blocked to circumvent these restrictions.

"Silence censorship" is meant to be sort of funny, but the idea is that censors have had it too easy for too long, and an automated and repeatable method of setting up an anti-censorship server can help change that.

"Automate the effect" is meant to reflect the fact that you can start as many of these servers as you want. If a country starts censoring the Internet, more servers will spring up in response.

I hope these explanations make sense. I will try to figure out a way to make the README more clear.

jlund··on Show HN: Streisand – Silence censorship, automate the effect
Thanks for the feedback! I'm excited to see how people use this and what new features might be helpful for them. I will be sure to incorporate that information into the README.
jlund··on Show HN: Streisand – Silence censorship, automate the effect
I just pushed a fix for this. If you pull, you should be good to go. The bug was introduced in the new version of Ansible that came out two days ago. I didn't catch it because I hadn't updated quite yet. Sorry about that!

Edit: I'm still working through a few other Ansible 1.6.8 issues as well.

Edit 2: I think that I got them all.

jlund··on Show HN: Streisand – Silence censorship, automate the effect
I will add this to the README. Thanks!
jlund··on Show HN: Streisand – Silence censorship, automate the effect
That's a great idea. Ansible doesn't natively support those providers through an official API yet, but I don't think it would be difficult to do. I will look into it!

For now, Streisand can execute on any standard Debian 7 server and configure it appropriately. It only needs an open SSH port and an account on the system with root permissions. AWS, DigitalOcean, Linode, and Rackspace are the options it supports for creating a brand new server from scratch as well.

jlund··on Show HN: Streisand – Silence censorship, automate the effect
I am happy to answer questions about this, if anyone has any. Or if anyone finds any bugs or has other feedback, that would also be great.
jlund··on TextSecure's Private Group Messaging
The server side is currently relaying messages for the in-progress iOS and Chromium clients. That's functionality that exists today, even though the clients are still under development. The TextSecure server is an elegant and important part of TextSecure's infrastructure. I stand by my assertion that it's an oversimplification to say that TextSecure == Google's Servers.

Google does not have access to any metadata, other than the fact that you are a TextSecure user who has received a Push notification. GCM payloads are fully encrypted. Google cannot tell who a message was from, they cannot see which numbers were involved (users are free to register with a number that is different than the one assigned to the cell phone that is running TextSecure), they cannot tell whether or not it was part of a group conversation, and they cannot see its contents.

jlund··on TextSecure's Private Group Messaging
Full disclosure: I wrote that Support Center article. The comment I was replying to made it sound as though TextSecure's infrastructure is almost entirely Google-based. It is not, and that's what I meant when I said "This isn't entirely true." The server is open source and it already includes preliminary support for WebSockets and Apple's APN push messaging network. Google's GCM is merely one component, and alternatives are being worked on.

Apple also has root access to all iOS devices via their over-the-air update framework. Opaque basebands and graphics chips with closed source drivers are difficult to trust too. None of these scenarios mean that software which offers serious improvements over the status quo should be casually dismissed. TextSecure can (and does) provide significant protection from mass surveillance and targeted surveillance. Security nihilism is corrosive.

← PreviousPage 2 of 3Next →