13 ms·
Encrypt your Google chats and make the NSA sad
- sweis 13y agoAs far as I can tell, this is using CBC mode without any authentication: https://raw.github.com/mdp/gibberish-aes/master/dist/gibberish-aes-1.0.0.js https://raw.github.com/mdp/gibberish-aes/master/dist/gibberi... If that's the case, then this implementation is vulnerable to a variety of attacks.
- chubot 13y agoOh cool, I am on stage 3 of the Matasano challenge which covers this. I am learning something useful. :)
- salade_verte 13y agoThanks, can you suggest me a better AES implementation ?
- mcpherrinm 13y agoIf you're asking that question, and really aim to write crypto safe from the NSA, then I think you have a lot more learning to do. Just naming off a different mode isn't going to cut it. The Matasano crypto challenges seem to be popular lately. That would be a decent place to start.
- salade_verte 13y agoI'm happy with AES and I don't want to write my own crypto. I was asking for a better AES javascript library, because I found a couple of different js AES libraries, but, as you said, I don't know anything about cryptography, and I wanted to know if some are better than others. thanks
- tlrobinson 13y agoYou don't need a better AES implementation (well, you probably do, but that's just the start). You need higher level primitives. There a thousand ways to use AES, and most of them are insecure, including your implementation.
- bdamm 13y agoYour implementation is vulnerable to MITM attacks. That will be the case no matter which AES mode you choose. You are on the tip of the greatest problem with modern cryptography, which is that there is no real way for widespread confidentiality to be created without trusting a third party such as a CA. But once you trust a CA, then you become vulnerable to the backdoors available through the CA community (not just one CA.) Personally, I'm hoping for a bitcoin-like protocol (such as namecoin) to create a peer-to-peer trust network for distributing public keys. PKI is only useful when the root are truly trusted and tightly controlled (or even supervised with highly transparent audit programs). The current generation of Internet CAs don't even come close - they are not trusted by anyone except themselves, and they sure are willing to take your money if it'll make you feel better!
- jafaku 13y agoDoes bitmessage have anything to do with this?
- salade_verte 13y agoThanks, where will the man in the middle be ?
- mpyne 13y agoWait, you're trying to beat NSA by writing your own crypto? This is worse than useless :), all you'll do is flag that communication for further research (which the NSA will then break within a couple of hours if need be), at least with plain text you'll stay in the noise of the masses.
- salade_verte 13y agoI don't want to beat the NSA, I was just asking for a better javascript AES script. I have nothing to hide, that's why I would be very happy to get out of the noise of the masses and make the NSA waste a couple of hours :)
- mpyne 13y agoDon't get me wrong; I use crypto too (GPG), but NSA is not the ones I'm worried about. ;)
- anologwintermut 13y agoIt's worse that that. It uses a questionable javascript crypt library (written by a former twitter dev, not a cryptographer) and a fixed IV derived from the password which is re-used for each message. This is oh I read the wikipedia article on AES level cryptography deployed against people who would have written the Wikipedia entry if not for that fact that what they know is probably not public. Better idea: Just make a plugin that uses OTR[0]. Don't try to roll your own crypto, especially when you are up against people who know what they are doing. [0] http://www.cypherpunks.ca/otr/ http://www.cypherpunks.ca/otr/
- ryan-c 13y agoThere are 64 bits of randomness (however, they come from Math.random which is not so good...). The encrypted text produced by this has a distinct signature - all message will contain "U2FsdG". Here's how we break this if you're Google/can force Google to do stuff: 1) Detect messages containing that OpenSSL 'magic number' 2) If detected, push something like this: // Should check to see if GibberishAES exists to avoid errors if it doesn't... // Grab target function as a string var keycode = '' + GibberishAES.openSSLKey; // Inject something evil keycode = keycode.replace('key = result.slice(0, 4 * Nk);','key = result.slice(0, 4 * Nk); for (var pos = 1; pos < 4 * Nk; pos++) { result[pos] = 0; };'); keycode = 'EvilGibberish = {}; EvilGibberish.openSSLKey = ' + keycode; // Execute the modified code to generate the new object eval(keycode); // Replace the 'good' keygen routine with the 'evil' one GibberishAES.openSSLKey = EvilGibberish.openSSLKey; This will zero all but the first 32 bits of the AES key, allowing easy brute forcing. Note that this is based on something I wrote for a CTF, and I haven't tested it specifically against GibberishAES, but the technique works.
- mdp 13y agoIt's definitely a questionable javascript library, I wrote it back in 2008 after reading the wikipedia article :) It was designed to interop with OpenSSL's default command line AES crypto, which has some weak points, mostly around the IV selection. That being said, the biggest weakness will always be that it's running in the browser and open to injection attacks. But while I think there's definitely better crypto chat solutions out there, it's nice to see people taking an interest in the subject. And let's not kid ourselves, the vast majority of NSA data collection is probably less about sophisticated encryption attacks, and more about the clever application of political/police powers.
- deleted 13y ago[deleted]
- rogerbraun 13y agoI like this, but the easiest way to do this without pretty much any configuration is to log in to Google Talk with a Jabber client that has OTR support, such as Adium or Pidgin.
- gohrt 13y agoGoogle Talk is being replaced by Hangouts, it might not be practical to keep your existing Google Talk client long-tem.
- sspiff 13y agoWhile this is a nice effort, why use Google Talk at all for chatting if you're going to do all this effort (per user configuration etc) if you could just use an XMPP client with OTR[1] support, or use an XMPP server you can trust? [1] https://en.wikipedia.org/wiki/Off-the-Record_Messaging https://en.wikipedia.org/wiki/Off-the-Record_Messaging
- patrickaljord 13y agoBecause then you'd be talking to yourself as nobody uses XMPP with OTR.
- sspiff 13y agoNobody is using this solution either, and setting it up is harder than setting up OTR (provided your conversation partner is already using an app for XMPP). I can explain my girlfriend and brother how to enable and configure OTR. I would have a hard time getting them to execute the instructions for this addon.
- stock_toaster 13y agoI use it. So ... nobody+1 I guess?
- drdaeman 13y agoAt least Adium, Gajim, Kopete and qutIM have built-in OTR support. So, I guess, it's a bit more than nobody.
- patrickaljord 13y agoYeah I remember using OTR on kopete when I was in college. I had one instance opened on my laptop and the other on my PC. It was pretty cool and easy to set up. What wasn't easy was finding anyone I knew to talk to with beside the few other linux nerds at school.
- dgesang 13y ago
- switch33 13y agoSomewhat relevant(IRC for gmail): https://github.com/progrium/irc-for-gmail https://github.com/progrium/irc-for-gmail Also, it sucks that this AES plugin for gmail uses greasemonkey. There are a bunch of exploits abusing greasemonkey really.
- mtgx 13y agoStill waiting for Google to implement OTR and ZRTP in Hangouts by default...especially now after all this.
- simgidacav 13y agoHave a good time waiting, sir. In the meanwhile you might be interested in the following fact: 1. Google is removing XMPP as protocol http://www.zdnet.com/google-moves-away-from-the-xmpp-open-messaging-standard-7000015918/ http://www.zdnet.com/google-moves-away-from-the-xmpp-open-me... 2. On the other hand, however, duckduck is giving us some alternatives https://duck.co/topic/duckduckgo-s-new-public-xmpp-jabber-service-on-dukgo-com https://duck.co/topic/duckduckgo-s-new-public-xmpp-jabber-se...
- jafaku 13y agoForget about DuckDuckGo, it's based in the US. Better use Startpage.com, which is based in the Netherlands.
- joe24pack 13y agoAnd you don't think the EU isn't already doing pretty much the same thing?
- simgidacav 13y agoIt's not the fact that US=bad, EU=good. The fact is that you can use free software programs over xmpp which support OTR cryptography.
- EliRivers 13y agoI thought Google were being fingered as complicit? I wouldn't trust them, even if they totally super-secret pinky promise they're not handing everything over, honest!
- peter487 13y agoProbably not gonna happened, but it would solve so many problems with public key crypto. Key distribution? No problem, tie your public key to your gmail account. Need to communicate with someone? Just send them your public key. Goole would verify that key X belongs to mail Y, another problem solved. Mix it together with some javascript library (source code available by design) and you have almost perfect and simple to use public key crypto for masses. Oh well time to wake up….
- freshhawk 13y agoThis would definitely be the level of security that falls under this statement from Snowden: Q: Is it possible to put security in place to protect against state surveillance? A: "You are not even aware of what is possible. The extent of their capabilities is horrifying. We can plant bugs in machines. Once you go on the network, I can identify your machine. You will never be safe whatever protections you put in place." (from http://www.guardian.co.uk/world/2013/jun/09/nsa-whistleblower-edward-snowden-why http://www.guardian.co.uk/world/2013/jun/09/nsa-whistleblowe...)
- rubikscube 13y agoThis talk about "bugs" in machines makes one wonder if that is related to why Intel was one of the companies mentioned in a recent article. Intel stands apart from the rest of the companies. Google, Apple, Facebook don't specialize in hardware.
- youngerdryas 13y agoApple obviously does specialize in hardware and if you use iMessage it is already encrypted.
- cowkingdeluxe 13y agoWhy did he not give even a small technical overview on what they are capable of? He should've been able to given he has a lot of technical expertise and it would've helped his evidence a lot. Did they figure out how to tap complicated SSL? Is it hardware based? He gave no hints but could have easily. Instead it's this blanket statement that's supposed to imply that all encryption is pointless.
- steveklabnik 13y agoGlenn Greenwald said on Twitter that he was given the technical details and isn't releasing them.
- gnaritas 13y ago
- dlss 13y ago"A" for effort, but I won't be happy until something like this also obscures who you are talking to.
- Groxx 13y agoBe happy: https://github.com/prof7bit/TorChat https://github.com/prof7bit/TorChat (description: https://github.com/prof7bit/TorChat/wiki https://github.com/prof7bit/TorChat/wiki )
- dlss 13y agoWow -- that does make me happy. Thanks for the link! (Also: Pascal?! I guess I can't complain -- I'm just glad this exists :)
- marcog1 13y agoI've been using encryption with Adium for a long time, but the problem I have is switching between clients (laptop and mobile) results in me seeing gibberish on the mobile side. I have yet to find a mobile client that supports encryption.
- dpeck 13y agoFor android, but: https://guardianproject.info/apps/gibber/ https://guardianproject.info/apps/gibber/
- thisisparker 13y agoFor Android, see the Guardian Project's work, especially Gibberbot: https://guardianproject.info/apps/gibber/ https://guardianproject.info/apps/gibber/ For iOS, you could try ChatSecure: http://chrisballinger.info/apps/chatsecure/ http://chrisballinger.info/apps/chatsecure/ If you want to use the same key on both clients (which carries some additional risks if, say, your phone gets stolen, given that key is stored in plaintext) you may find the Guardian Project's documentation of different OTR key file formats useful: https://github.com/guardianproject/otrfileconverter https://github.com/guardianproject/otrfileconverter
- rexreed 13y agoXMPP on a Raspberry Pi box with minimal raspbian and OTR. Gives you some control and a minimally-hackable box. Some interesting related reading on the XMPP with Raspberry Pi: [1] http://russelldavis.org/2013/01/18/setting-up-prosody-on-the-raspberry-pi-for-house-apartment-secret-club-house-wide-chatroom/ http://russelldavis.org/2013/01/18/setting-up-prosody-on-the... [2] http://oskarhane.com/make-your-raspberry-pis-and-other-servers-a-botnet-controlled-via-xmpp/ http://oskarhane.com/make-your-raspberry-pis-and-other-serve...
- cupcake-unicorn 13y agoWhy doesn't Google up the security in its own apps? The government may "force" them to provide access, but can it "force" them to remove safeguards like encrypting email/chats/etc? Even if they just gave us the option to check a box, and it wasn't on by default. The problem I'm seeing with all these solutions is that they're very specific to two users, they both need to have everything set up. Well, great, the NSA will see one less conversation when they peek through your stuff. I'd like to have ALL my messages encrypted.
- nano111 13y agocan't force them not to encrypt emails but it can force them to give out the keys
- nano111 13y agofor some reason, it won't let me delete my duplicate comments that were created because of errors on postings...
- nano111 13y agocan't force them not to encrypt emails but it can force them to give out the keys
- nano111 13y agocan't force them not to encrypt emails but it can force them to give out the keys
- nano111 13y agocan't force them not to encrypt emails but it can force them to give out the keys
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- deleted 13y ago
- deleted 13y ago[deleted]
- rythie 13y agoI'm sure they are more interested in who you talk to than what about most of the time. I would assume they want to track people close to persons of interest they know about.
- akkartik 13y agotptacek doesn't seem to have found this thread yet, but he's said many, many times here that doing crypto in js is a bad idea: http://rdist.root.org/2010/11/29/final-post-on-javascript-crypto http://rdist.root.org/2010/11/29/final-post-on-javascript-cr...
- Hyrum_Graff 13y agoDelete your Google account and make the NSA sad.
- godgod 13y agoDoing that today.
- leot 13y agoGoogle, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public key is colored "green" (for "secure") and the from address is colored "green" if it's been appropriately signed. With (and, I'd argue, only with) a webmail client can PGP be rapidly deployed and almost completely transparent. But, this would make "intercepts" far more difficult, now, wouldn't it ...
- adventured 13y agoThis will only work for average email users if you can pull it off without ever using any of the industry language, or requiring anybody to ever actually do anything with a key. Find other descriptive language to use, and make it require zero extra effort, and you've got a winner.
- leot 13y agoWe learn all the time how to do complicated things on the internet. Facebook isn't instantly trivial to use (though it seems that way now that we know how to use it). Neither is Google+. The whole problem with PGP is that it's not worth learning to use because it depends necessarily on network effects. If Gmail deployed it, the network effects problem would immediately disappear. At first it would only work within the online webclient, obviously, and enabling it would have big consequences for how/whether client-based access (IMAP and POP) worked.
- 6d0debc071 13y agoMost people aren't going to get themselves into webs of trust - and certificate authorities and webmail servers and the like can be compromised. The only thing you can vest any significant trust in, with NSLs and so on flying around, is what's on your computer. And, if you want to be really sure, what's on a computer with no radio protected by an airgap into which you never insert removable media....
- tlrobinson 13y agoI would prefer to see a plugin that implements OTR instead of this half baked solution. https://en.wikipedia.org/wiki/Off-the-Record_Messaging https://en.wikipedia.org/wiki/Off-the-Record_Messaging
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- acanby 13y agoI might be missing something here, but where is the passphrase negotiated? Apart from calling or talking to the other person, the only way to define this common key that I can see would be electronically. Isn't this a bit of a problem?
- bbit 13y agoIt's going to turn out this guy is a "spy" for China or a plant by the Obama regime to make America look bad or both.
- jaytaylor 13y agoIs it possible to use gAES with Google Chrome?
- tn13 13y agoI think a better solution to say hello to NSA would be by sending a letter to your local senator (and other representatives) that you are not going to vote for them in future unless they raise their voice in the concerned house.
- Tloewald 13y agoI think just attach files full of random noise to emails.