5 ms·
Facebook encrypted messaging! What's next, military intelligence? How about a vegan big-mac? Maybe a quality automobile by GM? I think steganography is an exce
by nobody271 8y ago
Facebook encrypted messaging! What's next, military intelligence? How about a vegan big-mac? Maybe a quality automobile by GM?
I think steganography is an excellent way to deliver encrypted messaging to consumers. It has so many inherent features that I'm surprised it isn't already widely used. Let's see:
- easy to recognize but hard to detect
- can pass through any channel that accepts images
- massive storage capacity (10MB+ depending on how you roll)
- encryption easily baked in!
- many additional use cases (store your kids ssc or passwords, store encrypted notes, anonymous communication by just posting an image online somewhere).
Everyone should know Facebook encryption is about as good as free (or maybe most) VPN encryption. But with steganography all you need is an open source application that you can trust or a popular codec.
If anyone is interested I have a stalled steganography project that I'm waiting to get back to (once I finish a ASP.NET Core book) https://github.com/smchughinfo/steganographyjr https://github.com/smchughinfo/steganographyjr. I'm making it as easy to use as possible (UWP, iOS, Android, a website, Web API, Nuget, and possibly a native app for Debian if I get the time) Most of that work, though, you get for free with .NET Standard + Xamarin but it's still a lot of work.
- ams6110 8y agoWhy not just post ASCII armored gpg messages on pastebin?
- nobody271 8y agoI suppose you could and I am certainly no expert so it might even be better that way. A couple cons to that are that it looks cryptic so it's a little easier to detect, that you have to share the URL somehow (as opposed to hanging out in usersub on imgur), it's usually more difficult to deal with large amounts of raw text than an image, and if you use PGP instead of AES->base64 (or something like that) you would have to know the recievers key. I guess that last bit depends on the use case. I'm not saying either approach is better. Maybe one is better, I don't really know.
- giancarlostoro 8y agoIf you're going to go that route using Pidgin with OTR would make more sense.
- code_duck 8y agoSteganographic communication as a substitute for encrypted text is a baffling misinterpretation of the reason for encryption in a chat program. The use cases and potential userbase barely overlap at all. I don’t want my conversations with my mother to be public. But we are not going to communicate in secret messages hidden in images as if we are espionage agents, and most assuredly 98% of the public will not, either. Not to mention that steganography has a security by obscurity aspect - the more you raise knowledge that textual messages may be concealed in images, and present a common mechanism for doing so, the less effective it is for escaping scrutiny. Also, I’d note for your points that stegonography has no ‘storage capacity’. That’s a characteristic of the underlying medium. It is not a standalone communication system - if I’m sending secret spy image messages to my tow truck company instead of normal text messages, the storage is foremost limited by the text message system.
- nobody271 8y agoSure, for a chat conversation you would want something faster than steganography. But if you will notice I did not propose a solution for encrypted chat. I proposed a solution for making encryption easier to use, yes? I hope that debaffles you a little. Steganography alone is just security through obscurity? I guess I'm not sure which algorithm you are thinking of but regardless it's very easy to encrypt your data before writing it to the image so in any case, that is a non-problem. The same goes with your sentence about the use of steganography detection. Maybe it's possible for some algorithms, I don't know, but I have very strong doubts about that and again, it's encrypted. The amount of data you can write to an image using a steganographic algorithm could be rightly called its "storage capacity", yes? Or do you believe that for each image there is an exact maximum storage capacity regardless of the way you encode data to it?
- code_duck 8y ago“I think steganography is an excellent way to deliver encrypted messaging to consumers.” is in your prior post. If you are not using stegonagraphy for the obscurity aspect, why use it at all? Why not just encrypted plaintext that can be decrypted? Stegonagraphy is intended to conceal that a message is being sent at all, other than the apparent message of an image. If my recipient and I are both using Cool Stegonagraphy Messaging App, or you are marketing CSMA to the general public, that removes that crucial feature. As far as storage capacity, I mean is not a concept that stegonagraphy envelops. The amount of data you could include would be limited by the lower level transmission systems - whatever software and hardware you are using to actually transmit, device, store and view images such as image format and your phone storage.
- cannonedhamster 8y agoBurger King has a veggie Big Mac. https://www.bk.com/menu-item/veggie-burger https://www.bk.com/menu-item/veggie-burger Steganography has a bad connotation because it's heavily used in the pedophilia realm which would limit it's uptake, somewhat like torrents. Perfectly valid and useful tech that gets used by a few but not by most. I think Telegram, even with it's flaws, is the closest I've come to an easy to use encrypted messaging app that I can get my mother to use and like.
- nobody271 8y agoI don't think anyone cares if pedophiles use it. They only care if it will work for them. Heck, if it keeps pedophiles safe that's a pretty good endorsement. I think the primary road block for most people is not seeing a use case combined with the technology not being readily available (excluding a few apps that aren't compatible with each other).
- FuckOffNeemo 8y agoI think you're grossly under selling the emotional response the larger public user base would have to being associated with paedophilia. Albeit, even if it's tangibly associated via an app. Unfortunately that's the nature of the beast. You and I, in addition to our peers would probably see it as an endorsement (as you coffecfly stated). But we're not Joe Bloggs. The feeling of disgust is so easily manipulated amongst the greater public.
- lsc 8y agoas a teenager, I was a vegitarian. I remember once I was the new guy at a computer repair place, so it was my job to go across the street and get everyone's burgers. This was, of course, the late '90s, and burger king did not have a vegiburger Anyhow, I go up to the counter and rattle off everyone's order from my list. I'm making conversation with the person at the checkout, and mention I'm a vegitarian (I think sometimes it's a little like crossfit, in that regard) Anyhow, this person mentioned that burger king had vegiburgers, and they could make me one. Excited to have something other than just french fries, I accepted. So I get back to the office and hand out the burgers. I go to dig into mine, and it's just a bun with way too much mayonase and some lettuce. It was so disappointing. I'm not a vegitarian anymore, but I do still enjoy vegiburgers, so I will have to go try this out.
- pilsetnieks 8y ago> can pass through any channel that accepts images No. Any online service worth its salt is going to reencode images to serve proper sizes and maybe do other processing. Along the way stuff like EXIF data and other worthless (for displaying the image) chuff will get stripped from the image. Alternatively, if you mean not somehow embedding in the file but encoding in the actual pixels of the image, that data will get lost as well when the image is resized and resampled. To survive most image manipulations, the data will have to be quite crude and you'll have low bandwidth with this kind of encryption. An exception would be some photographer oriented services like Flickr that allow you to download the original file but those are a minority.
- nobody271 8y ago> No. Yes. Any algorithm designed to be resilient to common processing steps will pass this test with flying colors. Also, EXIF data is not used in steganography, by definition.
- yellow_postit 8y agoThat’s a moving target with no guarantees to stay true. Steganography in the use cases you’ve described adds complexity and additional portability challenges over a plain encrypted file.
- pilsetnieks 8y agoHence why I mentioned that if you encode the data in the actual image (the part that's guaranteed to survive processing,) you cannot do it with very fine elements, like subtly shifting the colors of individual pixels or the like, because an average Facebook JPEG algorithm, for example, will just destroy that. You need to use data points that could survive heavy JPEG artifacting, and that means very few data points per image, and low bandwidth.