Friday, April 24, 2015

And oh, by the way, here's why backdoors are a bad idea

Some editions of Microsoft Windows include a full-disk encryption scheme called BitLocker. In order to enable a Windows user to recover the encryption key required to unlock their hard drive if they lose it, that key is kept in escrow by Microsoft on their Azure cloud platform. there are obviously good reasons to do something like this. In order for an attacker to retrieve a copy of that key, he can browse a user's social network profiles to troll for information which he can use to impersonate the target to Microsoft support. They call Microsoft, use the information to impersonate the target, Microsoft will send them the key. It's that simple. A glorified crank call. It is known that the NSA can access information on the Azure cloud both surreptitiously and by court order.

There is an easy way to avoid this. Don't escrow keys in systems which can be viewed by the person administering the server. Instead, use double-blind ways of storing the data, which leave the only usable, unencrypted copy of the key with the account holder and never hold an unencrypted key on the server. This has been implemented in Tahoe-LAFS and is now being implemented in many consumer grade clouds(Yay!). This is called Zero-Knowledge encryption.

This is essentially a password-reset vulnerability used to privelege-escalate into an encrypted storage device. A similar password-reset vulnerability exists on Facebook, Amazon.com, Linkedin, Netflix, World-of-Warcraft, a ton of other sites and in all Two-Factor Authentication schemes that rely on text-messaging a transient key to an account holder.

Additionally, the recent iCloud breaches somewhat ignominously dubbed "The Fappening" utilized a well-known backdoor used by law-enforcement agents in the U.S.

And oh, by the way, here's why backdoors are a bad idea

Thursday, April 23, 2015

And if that weren't bad enough

There are vulnerabilities available in many operating, communication, and encryption systems which require greater or lesser degrees of sophistication to exploit. Some of these are deliberately placed by a developer, manufacturer, or other intermediary in the software/hardware supply chain and qualify as backdoors, but most are the result of honest mistakes, lack of funding, insufficient testing, or run-of-the-mill incompetence. This is where the NSA's so-called "Advanced Intercept Capabilities" come in, and we actually have much less to be worried about here. Advanced Capabilities are usually targeted techniques against specific computers which, rather than passive eavesdropping, exploit them to give up non-standard information, like the various side-channel attacks carried out on Tor.

The critical issue with Advanced Capabilities is two-fold, first, we must cease the NSA's sabotage operations carried out against products used by U.S. persons, and second, we must provide an effective bug-disclosure policy which does not allow computer vulnerabilities discovered in the course of signals intelligence gathering to remain exploitable by criminals and enemies of America.

And if that weren't bad enough

3 Basic System Management - App Store

  1. The Problem with the Play Store many people advocate the use of the Google Play Store for a few of it's advantages. The Google Play Store lets app developers sign their apps using their own cryptographic signatures, for one, which many app stores do not. It also sometimes receives updates before other app stores do. However, those pale in comparison with it's disadvantages. The first and foremost disadvantage is the seemingly total lack of meaningful auditing of the apps that are included in the Play Store. On a single search for a more-or-less benign term like "Chess Game" it is possible to find half a dozen instances of apps that ask for inappropriate or excessive permissions in order to track users. These anti-features are not explicitly listed and they are frequently deliberately surreptitious. There are other real problems with the Play Store and Google's services in general as well, including backdoors which allow Google to install and remove applications from your device without your consent or knowledge. If you installed a Free and Open-Source ROM for your device, you've already rid yourself of the Play Store and now you can move on to something better.
  2. The Safe Alternative: F-Droid is an app store which was created partly to deal with the problems surrounding Google Play by the Free Software Community. It is much more selective about the apps it will include, meaningfully auditing the code for malicious inclusions and anti-features. Anti-Features which don't disqualify an app from being included in F-Droid must be explicitly listed in the app's description in order to allow the user the oppourtunity to make a conscious decision to use that app or not. Using F-Droid means you are much less likely to receive a malicious app or update from your app store. Installing F-Droid will require you go into your phone's settings and enable installing apps from "Untrusted" sources.

How to Install F-Droid

*First, Enable Installation from "Untrusted" Sources. * Out-of-the-box, your device "Trusts" applications which Google Play Services "Trusts," which we've already seen means your phone trusts the vast majority of malicious apps already. In this step, we're going to enable you to install apps which aren't trusted by Google Play Services but which provide their own trust mechanism through F-Droid. Security-Conscious users should carefully judge apps they install on their own merit, and not upon the trust that Google places in them.

  1. Open your device's "Settings" app from the App Menu.
  2. Tap the "Applications" menu in the "Settings" app
  3. Tap "Enable Installation from Unknown Sources"
  4. When warned, click OK.

Next, Download and Install F-Droid from the Web Site

  1. Open the "Browser" app from the App Menu
  2. Navigate to https://www.f-droid.org
  3. Click the big blue button that says "Download F-Droid." It should only take a few seconds.
  4. In your Downloads menu click "f-droid.apk" and install the app.
  5. Open F-Droid from the App Menu to to access the app.
Appendix 3
  • Upkeep: The focus of F-Droid is to put control of the device's features into the hands of the person who owns and uses the device. To that end, it will inform the user of when an update is available, but it will not install that update automatically. When using F-Droid to obtain security software, as you should, you should make sure to review and install updated versions of the apps as they become available.
  • Notes: You should still avoid installing anything unnecessary, even though F-Droid provides reasonable assurance apps are not created with malicious intent, code is hard to create and vulnerabilities are easy to implement by accident in even the best of circumstances. Judgment will always be key to serious security.
  • Developers/Aspiring Developers: F-Droid is a responsive, vibrant community for people who want to publish Free and Open Source apps for Android. If you're a developer, I encourage you to consider informing F-Droid of your Free Software application and asking them to consider including it. Usually, the process is only a matter of a few days and making F-Droid better makes the world a safer place for Android users.

Choosing your App Store: Doable Privacy Instructions for Android Part Four

Wednesday, April 22, 2015

And it gets way worse...

In order to tolerate when those routers go down, those requests can be sent to many different routers, potentially. One router might be a backup in case the other router is experiencing heavy traffic, for instance. If an attacker has compromised one router, he can target messages by simply flooding the other router with fake traffic. That's just one of many, many ways. Some of them are even scarier.

Because of the voluntary nature of encryption use, anyone can do this, not just state actors like the US Government or the NSA.

It also means that you only need to compromise a fraction of the routers on the internet to compromise nearly all the traffic on the internet.

And it gets Way Worse

Tuesday, April 21, 2015

A General Overview of Eavesdropping

Communications traveling over the internet are routed through many intermediate computers, called routers, which direct messages as they are sent by the programs that send them. If the programs that send them send all or part of those messages in an unencrypted format or in an encryption format known to be breakable those routers can intercept and copy those messages as they are routed, if necessary decrypting them at their leisure.

But NOTHING is encrypted unless the program tells it to be

Also, the NSA isn't compromising home computers directly, it is monitoring them by compromising routers and stealing the messages they communicate.

A General Overview of Eavesdropping

Monday, April 20, 2015

Dispelling the key misconception about online tracking

Most people believe that online tracking is primarily contingent on the exploitation of vulnerable computers. While that does exist and is a serious concern, the reality of mass surveillance is much more banal and terrifying.

Think of it like Archimedes in the bath. The internet is like a bathtub, filled to the brim with water. As a function of getting into the bath, an equivalent volume of water is displaced, just as a function of connecting to the internet you disturb the activity of the surrounding network. For instance, in 1986, hacker and scientist Clifford Stoll was able to pinpoint the location of spy and mercenary Marc Hess in Germany by timing how long it took for Hess's computer to respond to a network diagnostic "Ping" request. This is one of the most basic, essential, and long-standing internet protocols and isn't going anywhere because something like Ping will always be required for computer networks to work. This kind of data will always be available to some degree or another. But the problem is that there is an immeasurable amount of superfluous water being displaced, figuratively speaking, just waiting for anyone to come along and calculate your volume.

Everything you do on the internet is easy to steal because nobody is doing anything right in the commercial space with regard to privacy.

Dispelling the Key Misconception about Online Tracking

Sunday, April 19, 2015

2 Basic System Management - Device Encryption

Goal: Make it prohibitively difficult for an attacker who can physically access your device to read, copy, or alter the data on your device.

This part is comparatively easy and self-explanatory. Android and related Operating Systems have the ability to encrypt the disk which contains the system, software, user data, and similar sensitive information. Encryption accomplishes 2 tasks.

  • First encryption hides the contents of the storage device by scrambling the information on it in accordance with a private key. When you enter your password, you unlock that private key, which tells the system how to de-scramble the information on the storage device. This keeps people from reading your files.

  • Second: partly as a consequence of the first step and partly as a result of design and review in the encryption field, encryption also guarantees that your data hasn't been altered by someone who manipulated your disk from within a running Operating System on another device, and keeps code from being injected in that manner.

Configuring Device Encryption

The best time to encrypt your phone is when it is 1: Fully Charged, 2: Plugged in to a Power Source, and 3: Mostly Unused. This will result in the fastest, most reliable encryption process.

Enable Password

  1. Open your device's "Settings" app from the App Menu.
  2. Tap the "Security" menu in the "Settings" App.
  3. Tap either "PIN" or "Password" to set the password to unlock your device.

When your device goes to sleep, the password will be required to unlock the device.

Enable Encryption

  1. Go back to the "Settings" App.
  2. Tap the "Security" menu.
  3. Tap "Encrypt Phone" or "Encrypt Tablet" depending on your device.

Now when your device goes to sleep, it relinquishes the encryption keys until you re-enter the password you set previously.

Appendix 2
  • Upkeep: This pretty much "Just Works" and shouldn't change much, and if it does, it's because something way bigger than you happened. You should remember that without the password, encryption is one-way and cannot be reversed. Don't forget your password.
  • Notes: Ideally, you would set two passwords, one to turn the device on, and one to unlock it from sleep mode. This is because each time you enter the password, there is a chance that someone or something is watching which might observe you entering it. A secondary password would keep such an observer from being able to use the screen-unlock password to attack a powered-down device. Since this is not supported in the operating system, keep your disk encrypted but use a second layer of encryption and passwords for sensitive information like the Instant Messengers and Encrypted Notepads we will discuss later.
Appendix 2a, Encryption Vocabulary

Codes and Ciphers

  • Code: A "Code" is a way of representing information for a specific purpose. There are codes which are intended to be readable, like Morse Code or computer programming languages, and there are codes that are intended to be unreadable, so-called "Secret Codes" which can be created in many ways. This article mainly deals in when and where you.
  • Encryption: "Encryption" is the use of mathematics to obscure the content of a message except to it's intended recipient. That intended recipient has in his or her possession a "key," a unique piece of knowledge that is required to unlock the contents of a message. As a side-effect of the key's uniqueness, it can also verify that a message came from the recipient. This process is what is referred to as a digital signature.
  • Key-Pair: Encryption programs generate what are called "Key-Pairs", which are composed of a public and private(sometimes called secret) key. When you generate a key-pair you distribute the public key to people who you want to communicate with. This allows them to encrypt messages and send them to you, and to verify your signature on a message and thus that the message came from you. A private key can be used to sign a message or decrypt a message which was encrypted by the sender with the corresponding public key.
  • Ciphertext: "Ciphertext" is the encrypted text of a message. When you use a public key to encrypt a message, the output is the ciphertext. The private key can then be used to decrypt the message.
  • Cipher: A "Cipher" is the description of the algorithm used to generate the public and private keys and to encrypt and decrypt messages using those keys.
  • Steganography: "Steganography" is the process of concealing the presence of a message from people entrusted to transport it. Concealing information in an image, for instance, is a means of using steganography.
  • Somewhat like Steganography, it is advisable to conceal the intended meaning of any potentially dangerous terms even in ciphertext in case a private key is compromised. This is no different from slang. You have an ounce of T-shirts you wanna roll up and smoke.

Addressing and Transport

  • Client: A "Client" is a program that you run on your computer to connect to a communications network. Your web browser, ChatSecure, TextSecure, RedPhone, and AnTox are all client programs for connecting to communications networks.
  • Server: A "Server" is a program that runs on another computer that you connect to with a client. Facebook mostly runs on a Server which is accessed through the client, which is the web interface in your web browser
  • Address: An "Address" is a piece of information that represents the destination of a message. It is also a type of "Metadata," which is information about a message not necessarily related to the content itself. Your address can, but does not have to, give away your location when you send or receive messages. That is what Tor is for, and some forms of peer-to-peer communication offer this type of protection as well.
  • Peer-To-Peer: "Peer-To-Peer" refers to methods which require no intervention on the part of a central authority or service provider, such as Facebook or Google. AnTox and Tor Hidden Services are peer-to-peer networks which can be used for communication without central authorities.
  • "End to End: Peer-to-peer encryption is also referred to as "End-To-End" encryption, and refers to encryption schemes where only the concerned parties are involved in the encryption and decryption process. This means that even if information is stolen in transit, it's meaning cannot be revealed by downgrading the strength of the encryption while the eavesdropping occurred.

Device Encryption: Doable Privacy Instructions for Android Part Three

 
Cmotc © | Partner: Toxigon ©
CMotC © 2015 - Designed by Templateism.com