Showing posts with label darknet. Show all posts
Showing posts with label darknet. Show all posts

Sunday, April 12, 2015

Doable Privacy Instructions for Android

This is intended to be an accessible guide to practicing hardening and security awareness for technical laypeople using the Android platform to communicate. While there will never be a set-it-and-forget-it solution, this guide attempts to be a starting point for people who want to learn more about a practical and accessible security procedure for their Android phone.

The Difference between End-User Security and Power-User Security

The Android operating system usually ships with security settings that are, from a certain set of assumptions, true. Unfortunately, many times those assumptions are based upon promises Google or your phone's various manufacturers cannot truly keep while providing all the functionality that the end-user desires from their device. While these assumptions can keep you safe in some circumstances, they also make you part of a large, appealing target and they do break down, often. So people who want to be relatively assured of the privacy of their communication on Android based Operating Systems should be in control of their devices in every way they possibly can.

Rule 0: If you don't need it, assume it's malware

The rest of this guide will focus on how to avoid allowing a malicious actor to take control of your phone, but the truth is that 99% of compromises are the result of somebody clicking on something fucking stupid and usually won't admit it. They install a malicious fucking "Scrabble" game or some dumb fucking shit and then they get mad at me when I remove it and do my best to clean up the damage it did. There's no point securing your device if you're going to download shit willy-nilly off Google's fucking Play Store.

Do not install apps unless you can trust them to not contain deliberately placed malicious code. Depending on who places the code, this is called either a "Trojan Horse" or a "Backdoor." Scenario A is that a malicious person creates an application which contains code which takes control of information on your device and uses it for malicious purposes. This can be anything from simple things like collecting personal data or geolocation data, or more complex things like injecting malicious code into the Android operating system. As a rule, IF YOU CAN DO WITHOUT AN APP, DON'T INSTALL IT. If you wish to avoid surveillance in a serious way, remove as much non-essential software as possible which may contain bugs which Trojan Horses You may say, "But it's just a little game? Can't I install that? It's harmless." That is exactly how Trojan Horses work. That is what the phrase "Trojan Horse" means. An innocuous looking object that conceals a hidden threat. Virus makers do not label their products. Don't fucking install it.* Scenario B involves a malicious person creating an application which bills itself as a secure application but secretly contains code that allows the app maker to remotely access it. That is called a Backdoor and that kind of vulnerability exists in most proprietary messaging systems, such as Skype and Facebook Messenger. This is of course game-over from a privacy perspective. Much of this guide will center on offering alternatives to messaging systems that contain backdoors or Trojan Horses, but the bottom line is that if you don't need an app, don't install it. At times, this will mean giving yourself potentially dangerous power over your phone that the Manufacturer does not want you to have. Having this power does not make you inherently insecure, it simply means that anyone who takes security seriously must be in control of his or her own security at all times.

*If you want to get games, you should do one of two things. First, and the preferable option, is to get another device which you use to run apps that can't be trusted alongside private communication information. This device will be your social/entertainment "Sandbox," separate from your private communications. I usually keep one Social/Entertainment Sandbox and the rest of my computers are hardened, fully-liberated GNU+Linux machines which refuse any insecure connections. The other option is to only install games from Free Software projects, preferably through the F-Droid app repository explained below. This is still a compromise and could these could still contain vulnerabilities, but due to the ever-present possibility of peer-review these would be unlikely to contain malware or backdoors.

Using Free Software: Doable Privacy Instructions for Android Part One

Much of the content on this blog will be syndicated from the blogs of my projects related to hacking on Android and manipulating the single-board computing hardware in Android phones. When I say hacking I mean it primarily in the original sense of the word hacking, which focuses on using computers to build new things that are useful or interesting, but also at times in the incorrect, but commonly used sense which concerns security testing and the relevant, interesting areas where they overlap today. I am particularly interested in Android-Based wireless Mobile Ad-Hoc Networks and Android ROM and Kernel customization. decentralization and how it can enable account-less, end-to-end encrypted communication which exists beyond the control of a third party, concepts which are realized in some form or another with i2p, cjdns, TOX, and Twisterd, and how this relates to how the network "routes around censorship."

My Projects

CyanogenMod on the Centura:

This project is my attempt to generate a working, current CyanogenMod-Like device tree which can be used to create Android ROM's for the Samsung Galaxy Centura mobile device based on the Qualcomm MSM7x27A board. I picked this board to make CyanogenMod easily accessible to people on phones they can afford to brick if something goes wrong. The Centura is a 30-50 dollar phone. I also fiddle a bit with ROM's for the ZTE force, a much more powerful budget phone.
Status: WIP with occasional useable releases.

ig88ROM

ig88ROM is my attempt at developing a custom ROM which can be built using a CyanogenMod device tree which includes a range of amusing pranks, useful tips, and dirty tricks presented with explanations for how they work and how they are performed in order to make how exploits work and how they can affect you more accessible. This is intended only for educational and professional purposes where legally allowed, whether I agree with the law or not. If you use it otherwise, I warned you, don't blame me if you get caught, I am telling you NOT to use it for illegal purposes.
Status: WIP with some usable components.

freeLAIR

freeLAIR is the 5th and final rewrite of the video game I frequently used to explore programming concepts I was interested in. It's a procedurally generated RPG inspired by the Rogue-likes, but which deviates by being multiplayer and played in real-time by nature. It will initally be for desktop GNU/Linux and eventually for Windows and OSX. freeLAIR may be the first multiplayer game to use the peer-to-peer Tox protocol for multiplayer communication.
Status: Beginning of the final rewrite, which won't take long believe it or not.

libtox++ TOX_Net2

libtox++ is a C++ wrapper for the Tox library which is not a one-to-one wrapper in order to make it easy to use modern C++(C++11, 14) features in C++ applications which make use of TOX. TOXNet2 is a library and partial TOX client implementation which aims to make incorporating TOX into your application for communication as easy as using the widely understood SDLNet Library.
Status: Definitely not ready yet. But soon.

Smaller Projects

Rotation Lock Plus Landscape

A fork of the Free and Open Source "Rotation Lock" app which adds landscape support. Status: Released.

CardCoin

A alternate coin which is intended to be used to track digital trading cards. Status: Barely started. Might take a while.

Projects I'm interested in/Think everyone should use

TOX

Tox is a free and open-source, peer-to-peer, encrypted instant messaging and video calling software. The stated goal of the project is to provide secure yet easily accessible communication for everyone. Users are assigned a public and private key, and they connect to each other directly in a fully distributed, peer-to-peer network. Users have the ability to message friends, join chat rooms with friends or strangers, and send each other files.

i2p/i2pd

I2P is an anonymous overlay network - a network within a network. It is intended to protect communication from dragnet surveillance and monitoring by third parties such as ISPs. I2P is used by many people who care about their privacy: activists, oppressed people, journalists and whistleblowers, as well as the average person. No network can be "perfectly anonymous". The continued goal of I2P is to make attacks more and more difficult to mount. Its anonymity will get stronger as the size of the network increases and with ongoing academic review.

cjdns

Cjdns is a networking protocol, a system of digital rules for message exchange between computers. The philosophy behind cjdns is that networks should be easy to set up, protocols should scale up smoothly and security should be ubiquitous. Cjdns implements an encrypted IPv6 network using public key cryptography for network address allocation and a distributed hash table for routing.

Twisterd

twister is the fully decentralized P2P microblogging platform leveraging from the free software implementations of Bitcoin and BitTorrent protocols.

Projects

 
Cmotc © | Partner: Toxigon ©
CMotC © 2015 - Designed by Templateism.com