5 ms·
And it does not seem a very serious attempt either. The only way to make this deal is through a single listed protonmail address that if this gets any traction
by piracy1 6y ago
And it does not seem a very serious attempt either. The only way to make this deal is through a single listed protonmail address that if this gets any traction will be closed in all likelihood. Not like an onion site with a contact page or something.
- sudosysgen 6y agoNot really. The message is PGP signed. If the protonmail address is taken down, then another message will be put out with alternate means of contact that will have a correct PGP signature. If you read the message there is indeed an onion address as backup in case things get taken down. The PGP address is the important part. No matter what gets taken down, if they can get attention to another message with a valid PGP signature, then they can carry on easily. EDIT: This is actually how Cicada3301 of all people operated. The PGP key allowed them to post a message even on Pastebin or /x/ and they would still be contactable and effectively uncensorable, because their identity was persistent and their messages were replicated.
- brobdingnagians 6y agoI've always wondered how effective this sort of info security is. Could a state actor track down there sorts of operations, or can infosec be good enough to really leave no trace?
- sudosysgen 6y agoIt's not that hard to do this kind of thing without leaving any solid trace at all. A way to do it for example would be to use a stolen credit card to subscribe to a few VPN with hops on Tor in between and use that to set up a VPS that puts this up after a few weeks The devil is in the details, but if you're careful you can leave absolutely no trace.
- deleted 6y ago[deleted]
- bouncycastle 6y agoAlthough, the more they interact with the internet, the more clues they leave behind. Things like Tor can be deanonymized, and even Tor has a warning. Quote: "Generally it is impossible to have perfect anonymity, even with Tor." Source: https://support.torproject.org/faq/staying-anonymous/ https://support.torproject.org/faq/staying-anonymous/
- Proven 6y agoRight, I'm sure they don't know about this and continue to use Tor from the comfort of their homes.
- monsieurbanana 6y ago> Although, the more they interact with the internet, the more clues they leave behind Interacting with a tor browser would be amateurish at this point. Just connect to tor (not on a browser, tor directly), use a script to upload to some random pastebin, disconnect from tor.
- bouncycastle 6y agoI didn't mention anything about a browser. Note that, for example, your isp can see whenever you are using tor or a VPN. From there, they can inspect the packets to work out what pastebin you have visited. Eg. simply by measuring how many bytes you have uploaded and then finding the paste and comparing the length of the paste with the number of uploaded bytes. (Just a basic example, there are more advanced methods). See https://witestlab.poly.edu/blog/de-anonymizing-tor-traffic-with-website-fingerprinting/ https://witestlab.poly.edu/blog/de-anonymizing-tor-traffic-w...
- sudosysgen 6y agoYes. This is why you don't actually post anything on pastebin yourself. Rather, you SSH into a VPS (via multiple VPNs and Tor/I2P), then program the VPS to post your message to pastebin in a week. And of course, you're not doing this from your home, you're doing this from the parking lot of a Starbucks in a car with tinted windows and fake plates, using a device with a spoofed MAC address. There are many ways of pulling this off so that no one will ever be able to pin you down. You just need to pay attention to detail. You're of course using some sort of obfuscated bridge too, so that packet sizes become meaningless.
- technion 6y agoAs a side note, with so much attention on replacing PGP, I've long though the turning point would be when a group like this uses something else. It's just a highly visible thing and it's a group that a lot of people assume know what they are doing.
- KirillPanov 6y ago> with so much attention on replacing PGP There actually isn't much attention on replacing PGP with anything specific. What other completely decentralized alternatives exist with no single point of failure? libsodium? That's a good start but a long way from a complete alternative. Plenty of quasi-centralized encrypted chat "apps" keep pretending they offer what PGP offers. The clueful ignore these gesticulations.
- technion 6y agoFor the context right here minisign would be perfectly capable. The post on this thread is not encrypted, there's no "decentralized" relevancy. Minisign has smaller keys and forces modern technology with a far simpler format.
- xmodem 6y agoIndeed, for a side project I have, I have a problem I want to be able to solve of "encrypt a file with a passphrase in a way that's secure and can be decrypted with standard tools". PGP is the best option for this, but I'm resisting implementing it in the hope I can find something better.
- technion 6y agoYou may wish to look at age: https://github.com/FiloSottile/age https://github.com/FiloSottile/age
- xmodem 6y agoI've looked at 10 different tools like this, but this doesn't fall well enough into the definition i'm using of "standard tools," by which I mean something installable from apt/yum/ports on a wide variety of systems. The closest I've found is using openssl's aes modes, but that requires the IV to be stored out-of-band somehow which is a do-able but a hassle I was hoping to avoid.