4 ms·
>That work is immensely complicated by the certainty that it would be highly unadvisable for Greenwald (or any other journalist) to regard any electronic means
by cmsmith 13y ago
>That work is immensely complicated by the certainty that it would be highly unadvisable for Greenwald (or any other journalist) to regard any electronic means of communication as safe.
Can anyone comment on how accurate that statement is? I would imagine that two people (Greenwald and Poitras) who frequently meet face-to-face could set up a secure way of transferring data.
- hondje 13y agoI wouldn't trust anything that important across a wire, and neither should you.
- fnordfnordfnord 13y ago>I would imagine that two people (Greenwald and Poitras) who frequently meet face-to-face could set up a secure way of transferring data. Two people that the gov't didn't know it needed to care about might be able to accomplish that feat. But Greenwald and Poitras against determined governments with vast resources? Imagine the motivation among the NSA operations and cryptanalyst folks at this moment. This has got to be one of the most exciting times ever to be an NSA spook (assuming of course you agree with the mission, and don't care too much about people's rights). I think in the current environment even guys like Zimmerman and Applebaum might find it challenging to operate under Greenwald's and Poitras' conditions.
- vidarh 13y agoThe natural response in this case is to communicate anything that is ok to have intercepted directly. E.g.copies of the documents that come from the NSA. Article drafts that'll get published soon anyway. That leave you with the much simpler task of securing communication of any details that needs to be kept safe, such as any knowledge of other sources, or details that might jeopardise their ability to publish, or the safety of other people. Hopefully that dataset is much smaller to the extent that someone acting as a courier can bring sufficient information "in his head" that remaining details can be rendered "harmless" by leaving out the information passed directly. It's interesting that Greenwald has admitted Miranda carried documents, as that makes very little sense - presumably they understood the potential of confiscation, and any documents would not be much more secure than if transferred directly. However Miranda might have carried with him knowledge of information otherwise left out, such as, say, pass phrases or a way to derive additional pass phrases that would allow any intercepted data to be protected better - any data on his devices ought to be inconsequential (at least that's what I'd hope, especially given Snowden mentioning that he started trusted Poitras when he realised she was more paranoid about him than he was about her). One such method would be for Miranda and/or other associates to take more than one trip. If intercepted you need to try again. If not, one or more of the files transferred might be a set of one time pads and all you need to do to massive increase security is to use said one time pads.
- wpietri 13y agoI wouldn't imagine that. All we really know about the NSA's cryptographic powers are that they have a shit-ton of money and a lot of very smart people. And even if your cryptography is actually as secure as you think, the power that can be brought to bear here is immense. Could they, from a distance, read the EM emissions of your computer? Could they compromise some physical object on which you set your computer and read the EM emissions from there? Can you afford to have somebody watching your computer every second of the day? Is there some possible attack that you haven't thought of but they, having devoted lifetimes of thought to the problem, have? Of course, they could also be bumbling idiots, so there may be no need to worry. Certainly, this sort of ham-fisted pressure suggests that there are, at least, idiots involved. But if you have gotten to the sort of prominence where somebody might be willing to burn a billion dollars to cause you trouble, it's really hard to say what's safe and what isn't.
- marcuspovey 13y agoNo need: Using a Mac? Compromised, the NSA has root access via the Patriot act. Ditto windows. And that's before you get to the idea of remote updates to the microcode supported by modern PCs (and not even running Linux keeps you safe from that, unless you recompile your kernel to turn it off). Lets also not forget that even the strongest crypto is vulnerable to cartel attacks and the rubber hose technique.
- dTal 13y agoUse a one-time pad, run Linux, don't connect to the net a machine with access to the keys or the plaintext. Encrypt your message, copy the file to a formatted flash drive, and send it to your communication partner however you like. Hell, stick it on pastebin, it won't matter. I'm confused at the perspective being espoused here - "encryption is pointless because the NSA can break anything, and failing that they can always beat you up". Encryption is not pointless, they probably can't even break standard open source crypto, they definitely can't break one-time pads which are trivially easy to make nowadays, and they can always beat you up anyway so you might as well encrypt. There's no plausible way any of that is less safe than running the gauntlet of border security with the data in your pocket.