4 ms·
This really depends on who you are and from what you are hiding: 1) Communication between non-targeted (unimportant) individuals hiding information from: 1.1)
by koehr 9y ago
This really depends on who you are and from what you are hiding:
1) Communication between non-targeted (unimportant) individuals hiding information from:
1.1) other individuals or non-governmental institutions
1.2) governments or GOs
2) Communication with targeted (important) individuals hiding information from:
2.1) other individuals or non-governmental institutions that target you
2.2) governments or GOs
The first one is the easier one as expected:
1.1) Individuals want to secretly share information without someone else notice. "Someone else" can be another person, family, friends, a teacher, collegues or their boss.
Important here is, that the person to hide the information from doesn't target you. This makes it VERY easy because the person doesn't necessarily expect any secrets to be exchanged.
Simple chat apps do here. Telegram and others support self destroying messages.
1.2) Individuals want to secretly share information without being (potentially) tracked by the government. They are part of the grey mass of "normal citizens".
As long as you or your partner are not actively watched by a government, things can still be relatively easy. Standard apps (eg WhatsApp, Telegram) might be even enough. Mass surveillance might be a problem though (in China, Iran or the US for example) so to be on the save side, better use non-standard software that is decentralised and uses hard encryption and something like Off-The-Record messaging. Good and mature candidates would be of course XMPP (aka Jabber) with OMEMO or the newer Matrix protocol.
2.2) Individuals want to hide information from someone who knows or suspects that they do it:
As soon as you or your communication partner is targeted, things get a lot harder. Now not only the information itself needs to be encrypted (good old rubber hose decryption works against the best encryption methods). Other individuals usually don't have sophisticated surveillance methods, so it should still be relatively easy. Important is, that meta-information (who communcated with whom at what time, etc) needs to be secret, too. As soon as the one who suspects you to secretly share information knows that you did, they will ask questions. Better they don't have anything at hand to do so.
Plausable denyability is the keyword. Off-the-record messaging provides this but is of no use if you keep the chat logs or be seen. Even the contact in your phone could be suspicious enough. Better use a dedicated system or memorise the contact information and only use it without saving it. Never ever communicate while the watching person could see it.
2.2) Governments or governmental organisations watch you:
Now this is the hard part. Hiding from a government that watches you and/or your communication is REALLY HARD. Don't be fooled by advertised end-to-end encryption and public law-suits of companies trying to defend their users privacy.
You have no idea what GOs are capable of which is why you need to implement measurements even against unknown attack vectors.
The best you can do is to hide your communication traces by following at least the following rules:
* Never use something that leaves a trace of personal information. Use pre-registered sim-cards or internet cafes in different cities. Always use public proxies, TOR, everything.
* Use asynchronous communication: Leave an encrypted blob somewhere in the void of the internet without any receiver. The receiver needs to be potentially everyone but of course nobody except the receiver can be able to read the message.
* Use disposable keys. Hide signatures but never forget to use them! A cryptographic secure signature is the only way for the receiver to be sure that it is really your message and nothing intercepted or faked. But the signature needs to be hidden inside the unreadable crypto-blob.
Phew… that was a long one. But I hope it gives you and the interested reader some insights.
Some links to kick-off the research:
https://en.wikipedia.org/wiki/Off-the-Record_Messaging https://en.wikipedia.org/wiki/Off-the-Record_Messaging
https://en.wikipedia.org/wiki/OMEMO https://en.wikipedia.org/wiki/OMEMO
https://staltz.com/an-off-grid-social-network.html https://staltz.com/an-off-grid-social-network.html
https://en.wikipedia.org/wiki/Matrix_(communication_protocol) https://en.wikipedia.org/wiki/Matrix_(communication_protocol...
https://en.wikipedia.org/wiki/Public-key_cryptography https://en.wikipedia.org/wiki/Public-key_cryptography