4 ms·
Despite the banality of this project. I think the idea itself could be interesting: That is, mapping your encrypted email into authentic looking text. Sending t
by timtadh 12y ago
Despite the banality of this project. I think the idea itself could be interesting: That is, mapping your encrypted email into authentic looking text. Sending the text. Then your receiver would need to know that the text is encrypted (don't tell them in the email). This /might/ be a temporarily effective dodge against bulk storage of PGP encrypted emails.
- marbu 12y agoThat is an interesting idea, but I'm not sure that it's actually doable. How would you do implement it? Moreover it seems to me that it would be likely not worth the work, because training some ML algorithm to detect this kind of messages would be always much easier than to design and implement this kind of mapping in the first place.
- spiritplumber 12y agoThis would play merry hell with spam filters, so it may not work for email services that do server side spam blocking (and may get your source email address tagged as likely spambotted).
- p8952 12y agoDepends how "real" the content needs to look, especially as most email spam is almost illegible anyway. Would receiving this[1] from a random .ru email really be something that would flag suspicion? [1] https://gist.github.com/p8952/5ddd1dd560c15d3d2ba6 https://gist.github.com/p8952/5ddd1dd560c15d3d2ba6
- TillE 12y agoIt would be reasonably straightforward to generate encoded messages that are about as coherent as spambots plucking a series of random phrases from the web. I don't know how you'd generate anything plausibly human, though, unless you're doing obvious steganography with whitespace or capitalization.
- TazeTSchnitzel 12y agoYou could generate a Markov chain from your own emails to make it seem like you and perhaps be more consistent (single author). But this'd mean you'd need to share the dictionary somehow, and you might accidentally expose sensitive information in the Markov chains.
- irdan 12y agoYou might be interested in format transforming encryption then.[0] It is used in tor to prevent deep packet inspection from detecting the initial connection to tor. Using FTE you can make ciphertext match an arbitrary regex. In the case of tor they are making ciphertext match HTTP traffic. [0] https://kpdyer.com/publications/ccs2013-fte.pdf https://kpdyer.com/publications/ccs2013-fte.pdf
- Zaephyr 12y agoCool idea. If each PGP character is mapped to one (or more each) noun, verb, adjective, and adverb one could construct a message that looked like boring text but was actually encrypted.
- SCHiM 12y agoIt's probably easier and secure to embed this kind of data into signature images. Those are quite common and a normal user can't see that data is injected, as opposed to a system where data is transformed to look like a normal conversation using words.
- sehugg 12y agoThis lets you hide bits in punctuation changes (or whatever else you want): https://github.com/countrygeek/stegparty/blob/master/stegparty.txt https://github.com/countrygeek/stegparty/blob/master/stegpar...