4 ms·
Concrete steps that I have made to gain control over my data: - hosting my DNS server ( bind ) along with my domain - Made my own RSS reader and blog with ope
by zer0gravity 13y ago
Concrete steps that I have made to gain control over my data:
- hosting my DNS server ( bind ) along with my domain
- Made my own RSS reader and blog with openid authentication (server/client)
- Installed ftp server ( vsftpd )
- Installed my own mailserver (nice tutorial here: https://help.ubuntu.com/community/MailServer https://help.ubuntu.com/community/MailServer)
Planning to:
- install my own xmpp server
I want to create an integrated, user centered platform, that will provide ( mail, blogging, storage, ftp, feed reader, an openid identity & social networking ) and make it really easy for somebody to install it on a raspberry pi + some external storage and have its own personal micro data center.
Someone could also consider Citadel (http://www.citadel.org/ http://www.citadel.org/)
If you ask me, I'd say that the personal data center is the future ( the free future )
- sahirh 13y agoFor XMPP, I recommend checking out Prosody (http://prosody.im http://prosody.im). You can get a working system up with Off-the-record instant messaging and internal file transfers in an afternoon, if you're familiar with UNIX system administration. If you use a client like Jitsi, you can do ZRTP encrypted calls through the server as well. Use your own SSL certificates for SSL. Ejabberd is also good, however the debug information was pretty inadequate. Also helps to be familiar with erlang.
- tn13 13y agoWell, I wonder why cant we create too many false positives for them to make the whole data meaningless ? Instead of hiding all our private communication we can generate fake communication across the whole internet which might raise flags in NSA's system. (I would have given more concrete examples but I am scared that tomorrow some NSA freak might knock on my door.)
- zer0gravity 13y agoWhat you're proposing is like this: I want to say a sentence to someone, but in order for an unintended listener not to understand what I'm saying I will say 10 sentences. Five of which will be "I will kill you and everyone you know" and "I will bomb America". Isn't that just a meaningless waste of energy? -- The government spies on you because you make it easy for it to do it. Instead, keep your personal data personal, use encryption and there's not much more that it can do, without becoming physical... ( it has no problem doing that either, but at least its intentions will be more obvious that way, and hopefully will wake up all the ignorants that think that some old guys peeking into everyone's lives is justified).
- TeMPOraL 13y ago> Isn't that just a meaningless waste of energy? It is. People suck at being random, so there's a good chance that those "false positives" will actually be trivially filtered out. And even if not immediately, this is an algorithmic problem - they will just throw few dozen kUSD at some math and CS graduates to make it go away.
- DanBC 13y agoThere are some extensions that generate a lot of extra traffic. They were developed around the time that Phorm[1] was being introduced in the UK. I agree with you and TemPorAL (apologies for incorrect capitalisation!) that these are probably a waste of time for the user - they don't work. NSA and GCHQ are very good at math - I'm constantly surprised that people don't appear to get this. Maybe it's because secret government agencies don't publish much? Just for fun here's one extension: (http://trackmenot.org/ http://trackmenot.org/) (https://cs.nyu.edu/trackmenot/ https://cs.nyu.edu/trackmenot/) People can probably come up with ways to improve it. But still, these are probably pointless measures.
- freshhawk 13y agoI do like the fuzzing idea, but you need some incentives in place. Bandwidth is pretty cheap these days but how would you convince people to install some software that just visited random websites and send randomly generated messages around? But how would actual people filter out the junk messages in a way that the NSA couldn't? I seems unrealistic. Just run a Tor exit node and encourage a lot of other people to do the same, similar benefits and no downsides. A more realistic and useful one would be for email clients sending mime email (almost all of them) to always send an encrypted version as well no matter the options in the client. No keys set up? Then just send random data that looks right. Email providers might hate this because of the bandwidth but if you start sending a lot of encrypted data around right now you are going to match a profile you probably don't want to match. I think step one is to make sending encrypted text around a normal thing.
- amirmc 13y agoI'm looking at doing something similar. Are you writing about any of this as you go? Would be interesting to learn about the hurdles.
- zer0gravity 13y agoUnfortunately no, I'm just pushing to make something usable and stable. Then I plan to release it in the wild along with the documentation, as free open source of course
- amirmc 13y agoWould you be happy to keep up with our updates? I'm putting together a website and mailing list about the work we're doing. My email is in my profile.
- DanBC 13y agoHosting your own email server is sub-optimal for several reasons. Email is still being sent as plain text. Encryption is possible even if you're using someone else's server. Your deliverability is reliant upon other people's good will. Those people have no idea who Joe Sixpack in Idaho is, and have no reason to extend goodwill. Your deliverability is also subject to wingnuts using a variety of good and not so good blocklists. You may find your time is better spent doing work rather than working around various weird blocklist delisting policies. Hosting your own email does nothing to prevent traffic analysis. The only thing it does is to stop your email being held in a big bunch at an email providers servers, but you can do that by wiping it from their servers and holding a local store. (tl;dr use a commercial email provider but keep your email on your machines not theirs; encrypt everything before sending it; consider using tor if you want anonymity.)
- zer0gravity 13y agoI just want to start by holding my own data. (While you my be right that big providers allow to wipe your mails, they can make copies). I just don't want for a third party to relay my data in the first place. While your points are right there are solutions, and in the long run it's worth it
- DanBC 13y agoYou make a good point, and I had forgotten about the legal requirements for some providers to make and keep copies.
- IgorPartola 13y agoMore than that. Big companies have big backups. Once a piece of information leaves localhost it is logged somewhere permanently. Even if you go and purge all your email now, Google is not going to spool up tape backups and erase all copies.
- sciurus 13y agoIn addition to Citadel, look at Kolab (http://www.kolab.org http://www.kolab.org).
- tlack 13y agoI wonder if there might be some way to do secure, PK-encrypted, federated message-based services using Tent.io or similar?
- zer0gravity 13y agoWell I've just learned that the guys from https://www.cozycloud.cc/ https://www.cozycloud.cc/ have come a long way implementing a user centered platform ( personal cloud ). It really looks promising.
- rickr 13y agoI have been messing around with this idea for a while with a few friends. I'd love to talk more if you're interested. You can find my contact details in my profile.