7 ms·
An encrypted message to Edward Snowden
- peripetylabs 13y agoAn open message to Snowden: this reporter would hand over his private key in a second.
- b_emery 13y agoFrom http://www.gnupg.org/gph/en/manual/x110.html http://www.gnupg.org/gph/en/manual/x110.html "A public and private key each have a specific role when encrypting and decrypting documents. A public key may be thought of as an open safe. When a correspondent encrypts a document using a public key, that document is put in the safe, the safe shut, and the combination lock spun several times. The corresponding private key is the combination that can reopen the safe and retrieve the document. In other words, only the person who holds the private key can recover a document encrypted using the associated public key."
- auctiontheory 13y agoIn a world where the US government is scanning all your electronic communications, and (we'll next discover) searching your OS X- and Windows-based computers at will, how do you, as a practical matter, keep your private key "private"?
- caycep 13y agoObviously, hide it in the "garbage file". Even Angelina Jolie knows this!
- deleted 13y ago[deleted]
- mpyne 13y agoKeep it public, but use a very good passphrase. That's not impossible to do. I'm not a crypto type but I believe what you want is a password-based key derivation function such as scrypt, the output of which you can then use as the symmetric key to encrypt/decrypt the private key. (This might even be what GPG/SSH does for you; I'm not at all sure)
- trotsky 13y agoIf you want a realistic chance of not losing control of your private key the only real answers are hardware based - using a tamper resistant smart card, hardware security module, tpm or similar systems in which the signing is done inside the chip that contains your signing keys and no general purpose device ever sees the key at all. Most people using software only solutions won't ever have their keys stolen, but that's because nobody tried to steal them. The compromise of a client os is inevitable if targeted by a competent actor, given enough time. Smartcards and HSM's may not be infallible, but their rate of compromise appears to be negligable at best and an extremely rare capability for an offensive team to have access to. Smartcards are surprisingly cheap and easy to work with, and due to their simplicity and long history are quite secure. The only real attack on them involves physical access and causes obvious physical damage that'd be impossible to miss.
- nthj 13y agoI would be very interested in a a tutorial or guide for getting something like this set up on OS X.
- dsl 13y agoOS X has smart card support for FileVault 1 but not FileVault 2. It only includes enough drivers to support US DoD CAC cards, and other NATO countries that have standardized on our stuff.
- kgo 13y agoWith regard to PGP, you can get a reader and smartcard from Kernel Concepts. Assuming you already know how to use GPG, it's pretty easy to set up. http://shop.kernelconcepts.de/index.php?cPath=1_26&sort=2a&language=en http://shop.kernelconcepts.de/index.php?cPath=1_26&sort=2a&l...
- trotsky 13y agoThe answer depends on what kind of key material and applications you use. Sadly there is no one size fits all system. https://www.opensc-project.org/opensc/wiki/OverView https://www.opensc-project.org/opensc/wiki/OverView this would probably be the place to start, at least to figure out which type of card you'd want. The main choices are a) support pgp and ssh b) support x.509 certificate based signing c) support time or use type tokens (like smartphone 2 factor apps) or d) some non standardized system running custom code on a tiny jvm inside the card. a) would be what you'd want in the context of this conversation, but b) is much more supported and has a wider set of use cases. In most cases it amounts to making sure you buy the right card & reader, plugging it in, and compiling the opensc and related packages
- jlgreco 13y agoOnly use your private key with Tinfoil Hat Linux on an offline air-gapped computer: http://tinfoilhat.shmoo.com/ http://tinfoilhat.shmoo.com/ I recommend disconnecting your monitor and only receiving output by having it blinked out at you through your capslock light on your keyboard. Bonus points if you can get your hands on some TEMPEST hardened hardware, and/or tamper-resistant hardware. Anything less will leave you vulnerable to the black helicopters! Note: I'm joking obviously, but this is something to take seriously.
- MiguelHudnandez 13y agoThe light reflected off your eyes from the capslock key is readable from high-res cameras. It's better to have leads hooked up to one of your toes and to toggle a 24V source so you can interpret the pulses in morse code. Edit: obviously the 24V must come from a battery which is charged only at specific intervals -- otherwise they can interpret your messages by watching mains voltage variation.
- cheald 13y agoThose leads are gonna generate magnetic distortions. You should only do this with your feet next to a giant 18" subwoofer while blasting dubstep in order to mask any electromagnetic fluctuations. Bonus: Anyone surveilling you via audio bugs will need new ears.
- trotsky 13y agoI know this is all in good fun, but you all are uncomfortably close to describing things that will soon get added to the practical threat landscape. As long as you have a flexible hardware platform that lets you crank up some of the voltage regulator outputs, gpios that can be attached to a long trace/external wire as a makeshift antenna and have a decently fast cpu clock you have all the ingredients for a crude but usable software defined radio. maybe not super fast if you can't repurpose a hardware phy or radio interface, but more than enough bandwidth to exfil a secret key or 10 for maybe a couple dozen meters. Tools to do sdr utilizing only general purpose processors and no radio specific gear are already available here and there as research implementations, and code that uses gpus/audio dacs/ and re-purposed phys to make a radio interface with a different spec or broadcast frequency is already in production use (wifi phy using a dvb radio interface -> tv whitespace communicator). Using an approach like that to exfil or bridge an air gap is just too tempting for it to not happen. Honestly, I'd be willing to bet there's already an example of that somewhere out there in the wild today.
- joeblau 13y agoFIPS 140-2 hardware encryption module - Generate your keys on an IronKey.
- drivebyacct2 13y agoI don't get it, unless Snowden's published his public key somewhere and Wired has some really, really important information for him?
- msandford 13y agoMore likely that it's a publicity stunt, raising awareness of strong encryption that the NSA (probably) can't crack yet.
- caycep 13y agoyeah, I was wondering about how strong GPG was. Back in the day, i.e. the 90's, the assumption was it would take years for then-current NSA supercomputers to factor the keys. Nowadays, with all sorts of new attacks, analyses, and cheap as hell compute time, I would wager that time requirement has gone significantly down.
- teraflop 13y agoAFAIK, the current publicly-known record for breaking RSA keys is the factorization of RSA-768 in 2010: http://eprint.iacr.org/2010/006.pdf http://eprint.iacr.org/2010/006.pdf That paper says it took about 1500 CPU-years to break a 768-bit key, and that the difficulty increases 1000x for each additional 256 bits of key length. For a back-of-the-envelope cost estimate, I'm going to assume that there have been no major theoretical breakthroughs in the last couple of years, and that the machines they used were roughly equivalent to an EC2 "medium" instance. That puts the cost of breaking a 768-bit key, using spot instances for cost-efficiency, at about US$200k. That sounds small, but encryption/decryption are still reasonably efficient with larger keys, while factorization becomes vastly harder. Breaking a 2048-bit key would take something like 200 quadrillion dollars worth of CPU time. A 4096-bit key, like the one used for this message, would be vastly more secure than that.
- donrhummy 13y agoAssuming there's no known exploit. The NSA might know of an exploit for that algorithm.
- CptCodeMonkey 13y agoLet's see, carry the N, divide by P and "Be sure to drink your Ovaltine"
- joeyh 13y agoInteresting, the encrypting key is "Verax (Informed Democracy Front)" and claims to have been created on May 20th. I can't tell what key the message is encrypted for. They may have used --hidden-recipient
- LoganCale 13y agoVerax is the recipient, not the sender. Messages are encrypted using the recipient's public key. You can confirm this yourself by encrypting a message to someone else and checking to see what which key it shows under "encrypted with".
- joeyh 13y agoThanks for that correction. Makes this all even crazier, if Wired is straight up trying to send him a message this way.
- jevinskie 13y agoWhat more is there to glean from this bogus message? $ gpg -vvv -d letter-to-snowden.txt gpg: using character set `utf-8' gpg: WARNING: using insecure memory! gpg: please see http://www.gnupg.org/documentation/faqs.html for more information gpg: armor: BEGIN PGP MESSAGE gpg: armor header: Version: GnuPG/MacGPG2 v2.0.19 (Darwin) gpg: armor header: Comment: GPGTools - http://gpgtools.org :pubkey enc packet: version 3, algo 1, keyid 5B50940B79DEBE35 data: [4096 bits] gpg: public key is 79DEBE35 :encrypted data packet: length: unknown mdc_method: 2 gpg: encrypted with RSA key, ID 79DEBE35 gpg: decryption failed: secret key not available
- reeses 13y agoThere's a 'secret' URL in there that anyone able to decrypt the message will be compelled to click on, at which time the creator can claim either to have contacted Snowden, or to have empirical evidence that the NSA can crack 4096-key RSA PGP messages and none of us are safe.
- mvc 13y agoBest rick-roll ever!
- _bpo 13y agoThe target key was published on 5/20. # gpg --list-packets /tmp/snowden.asc :pubkey enc packet: version 3, algo 1, keyid 5B50940B79DEBE35 data: [4096 bits] :encrypted data packet: length: unknown mdc_method: 2 gpg: encrypted with 4096-bit RSA key, ID 79DEBE35, created 2013-05-20 "Verax (Informed Democracy Front)" (79DEBE35 can be found on the subkeys.pgp.net keyserver)
- kgo 13y agoMeanwhile, per the Washington Post article, he asked the guardian to setup PGP in Feb, and his contact finally did so in March, both before this key's listed creation date.
- gasull 13y agoSnowden, just remember that Kevin Poulsen and Adrian Lamo helped the US Government in catching Bradley Manning. EDIT: Also, a pretty safe way to carry an interview would be VPN + Tor + Bitmessage. EDIT2: Users sneak and tlb claim Tor isn't safe because of timing attacks. Read below.
- sneak 13y agoThat's not safe at all, considering the organization tracking him.
- tlrobinson 13y agoIf not that, then what? If anything?
- alan_cx 13y agoIf it were me, literally, I go olde skool. Nothing electronic what so ever.
- rfnslyr 13y agoWhat about a pager? Can that somehow lead them to you? I'm not talking about tactics, but about the device in itself.
- alan_cx 13y agoNo idea. I wouldn't dare to risk it. For me, I just have always assumed that electronic communications are easier to compromise than old traditional ones. In the end, you connect to an ISP and packets can be inspected. OK, you might have encryption, but there have been too many schemes cracked or broken. So, why ever think that electronic comms can ever be secure? In the extreme, if the spooks get your encrypted data and they really believe that the data contains the "ticking bomb", they'll just torture you until you give up the key. So, you're still stuffed. Why give them even that much? More over, the one big issue I have to electronic communications, is that it is very hard to know if you are under surveillance. The old methods give you a better chance to discover that you are being watched. It is also easier to hide the fact that you are communicating at all. The clincher for me was that a while ago an "amusing" story appeared in a British news paper. Essentially it "exposed" MI6 spies in Moscow using actual drop boxes to pass along information. Now, if MI6 are still using pre-WWII methods, that has to tell you something, right? They don't trust the electronic methods. So, if secure communications really mattered to me, life or death type mattered, then I'd be looking at things like one time pads, drop boxes, people, etc. Of course a lot of it depends on what you are trying to communicate, how many people are involved, and frankly how much money you have to use. One thing I do know, electronics would be something I would work very hard to avoid. Lastly, if I were going to whistle blow to a journalist on this scale, the first thing I would establish would be several methods of communication. Times, places, codes, etc. I suspect that, given the nature of this exposure, that will have been done, and none of it will be electronic.
- cdjk 13y agoIf Edward Snowden does have a pgp key (I can't find one online), it hasn't been revealed in this message. It looks like the signing and encryption keys are the same: gpg: armor: BEGIN PGP MESSAGE gpg: armor header: Version: GnuPG/MacGPG2 v2.0.19 (Darwin) gpg: armor header: Comment: GPGTools - http://gpgtools.org :pubkey enc packet: version 3, algo 1, keyid 5B50940B79DEBE35 data: [4096 bits] gpg: public key is 79DEBE35 :encrypted data packet: length: unknown mdc_method: 2 gpg: encrypted with RSA key, ID 79DEBE35 gpg: decryption failed: secret key not available Of course, they could have used --hidden-encrypt-to, but I think it's more likely a publicity stunt. Oh, and if you do find a key claiming to be for Edward Snowden online, verify that it's actually him, ideally through the web of trust, and that it isn't just a key that was created after the news was leaked. I'd be wary of any keys on keyservers claiming to be him that have been uploaded after he went public with this.
- sneak 13y agoThere's no way to tell when a key was uploaded to a keyserver without the keyserver's logs.
- kefka 13y agoBut that's metadata. You dont need a court order for THAT! Oh wait. That plan only works for federal agencies and secret courts. Never mind.
- deleted 13y ago[deleted]
- unsignedint 13y agoIf --hidden-encrypt-to is used, there still will be signs of that. Specifically, the message addressed to 0x0000000 and the recipient will basically brute force it uses every key he/she has. Having said, that, according to PGP Dump Old: Public-Key Encrypted Session Key Packet(tag 1)(524 bytes) New version(3) Key ID - 0x5B50940B79DEBE35 Pub alg - RSA Encrypt or Sign(pub 1) RSA m^e mod n(4096 bits) - ... -> m = sym alg(1 byte) + checksum(2 bytes) + PKCS-1 block type 02 New: Symmetrically Encrypted and MDC Packet(tag 18)(4096 bytes) partial start Ver 1 Encrypted data [sym alg is specified in pub-key encrypted session key] (plain text + MDC SHA1(20 bytes)) New: (1024 bytes) partial continue New: (18 bytes) partial end It looks like we can merely see that the message is destined to 0x5B50940B79DEBE35. We won't be able to tell who's signer until it is decrypted.
- trotsky 13y agoEvery now and then I start thinking that Poulsen is starting to get the hang of honest journalism and some amount of professionalism, and then something like this comes along that makes it obvious he's still the same pathological attention whore whose primary hacking talents amounted to getting caught a lot.
- outworlder 13y agoWhat's with the posted image? Is that just for illustration, or is there steganography going on too? I couldn't find anything running a couple of programs on it, but then again I don't have the contents of the attached message.
- jmyc 13y agoIt's a picture of the NSA headquarters at Ft. Meade. That may be all there is to it.
- EGreg 13y agohttp://xkcd.com/1181/ http://xkcd.com/1181/ "If you want to be extra safe, check that there's a big block of jumbled characters at the bottom." :)
- tzury 13y agoThere is more to it than what you see. The NSA is known[1] to be able to take advantage of weaknesses found (or planted) in crypto algorithms, however, not in PGP[2] and other strong ones. 1. http://en.wikipedia.org/wiki/Cryptography#NSA_involvement http://en.wikipedia.org/wiki/Cryptography#NSA_involvement 2. http://www.philzimmermann.com/EN/faq/faq.html http://www.philzimmermann.com/EN/faq/faq.html (3rd question)
- LoganCale 13y agoThere are a few things about this that seem odd to me. From elsewhere in the comments, the key is encrypted with 79DEBE35, which, if you look it up on your keyserver of choice, belongs to "Verax (Informed Democracy Front)", created on May 20, 2013. Verax was the name used by Snowden to communicate with Laura Poitras (and perhaps others as well), but the story didn't break until June 5 and his identity wasn't revealed until days later. So why is Wired encrypting a message with a key using that name that was generated before the name was publicly known in association with Snowden? EDIT: Disregard the above—the "encrypted with" key is the recipient's key, not the sender/signer. 79DEBE35 may well be Snowden's key (but that's not proven either).
- aaron695 13y agoSo at a guess basically they've encrypted a message that is not Snowden's key that somehow calls back when decrypted (link, exe or something) so they know if the NSA is listening in.
- antocv 13y agoThat would be damn interesting if during decryption it could exploit the decryptor software, PGP, and ping a server or two. Is that possible? To epxloit a decryptor software while it is decrypting something.
- j2labs 13y agopainfully cheesy
- edgesrazor 13y agoI was hoping to find something in the EXIF data of the image of NSA HQ on the page, but I think I'm trying way too hard...
- marshray 13y agoIf you look closely, about halfway down, in the ciphertext you can almost make out some non-random parts: http://pastebin.com/q7mxqRn7 http://pastebin.com/q7mxqRn7
- kyberias 13y agoThis made my day. Thank you! :)
- rlwolfcastle 13y agoHonestly, who do they think he is, John McAfee?
- AKifer 13y agoIs this just another way to locate him as if it's really serious, only his private key can be used to decrypt it, and his former employer have the public key they use to exchange crypted messages before. In this case it's really stupid
- motters 13y agoMy guess is that this message is Wired asking Snowden for a chat so that they can get some kind of exclusive story. However, as others have pointed out, Wired magazine doesn't exactly have a good reputation when it comes to defending whistle blowers.
- piratebroadcast 13y agoLets say I wanted to send an encrypted message to Poulsen. (I do NOT, just figuring out the tech) How would I find his public key? Ask him for it? Is there, like, a directory?