To explain a potential adversary, how crypto works or how he becomes a valueable asset for any given intelligence service without any given payment may not even attract people like me.
HN user
noerps
Key infrastructure doesn't even emit security anymore. The P in PKI is for painful, and I really doubt that some CA, owned by big corporate entity (microsoft, oracle, ca) wouldn't manipulate the eternal append-only log-file for any given human factor and just re-roll it.
There is no benefit in auditing it permanently, like rewarding auditing with payment in bitcoin.
A given conglomerate CA would just revoke and reissue client/customer certificates for some reason and that eternal append log-file gets a short restart and everything is fine again, because of OOPPS compromise.
No CA ever, would host a eternal append-only log-file where you can simply point at and tell: I told you so.
It is simply beneficial for any CA to deploy compromising evidence, just in case, of OOPPS compromise. You sure know whom to blame.
It is not beneficial for a given CA (usa) to allow any other CA (china) to forever store their certificates and make you pay for it.
There is no benefit in eternal log-hoarding for PKI, and they make you pay it.
There is no benefit in it for customers even, because you cant even store that log, retrieve that log or even process it as an individual.
I am at a point where I would try web of trust with unicorns, raindows and flying cats before trying again and again with PKI by taking something from virtual currencies and attach it to PKI. Certificate Transparency is like Chrome, it is not build to let you or me delete, or remove CA-Certificates, we may dislike for any given reason, or just because we can.
I am at a point were I really conclude that taking away certificates or keys and delegate them, is the worst idea ever.
Certificate Transparency is baiscally the same wet-hot idea as in 1994 with PKI: PKI, nearly twenty years ago: In the perfect PKI world imagined by netscape, there would be no war, only love, because secrets would stay secrets forever and the NSA would still chew on their first intercepted message.
Reality check please.
CAs have proven not to be reliable trust providers. It is so easy to find the weakest CA and attack and compromise it. Certificate Transparency won't change that, its not even beneficial for CAs.
So lets try web of trust, it hasn't failed us yet, it just wasn't sexy enough. May we need that P in PKI pain to gain something after 20 years.
Imagine certificates trust-validated from your nerd friend, facebook group, google circle, 4chan, whom you trust, ymmv.
Everthing is better than certificates from the folks that hold your browser, operating system, data, e-mails or docments hostage and make you pay for some binary data blob and logging their failures.
Stackexchange is using the same approach to get rid of trolls.
Even if we are hyping or sensationalizing this topic, current behavior is a very good indicator for future behavior.
Since RSA patents expired, it's available, easier to comprehend and good enough until 2020 when the ECC patents expire.
No, but people may be.
See http://fail0verflow.com/blog/2013/megafail.html there are still security concerns.
Same with c3 in berlin.
"Once Panic Mode is on all requests issued by your browser will be forced over SSL" have an E for Effort Google Chrome.
It's a hidden argument, but ymmv.
A picture says more than 1024 words, and its funny, thanks a lot.
Putting a better UX or UI has been considered for PGP/GPG a very long time, and if you really reflect on that topic, you'll learn that a fancy interface or UX won't solve anything.
Foolproof software is operated by fools. Facebook has only proven that to an extent that you simply can't deny it anymore.
If fools use PGP/GPG, they will compromise you by putting the message in the subject and encrypting their disclaimer/footer.
OTR uses, iirc, AES and DH-kex, that are the same basic building blocks like RSA and AES or any other symmetric cipher you like to use for PGP/GPG/SSL. OTR adds deniability which is fancy for privacy but won't do for other scenarios (like business, money, profit), it works fine in one to one sessions, but group sessions are off the record.
We can conclude that OTR is fine for chat, sorry to hear google dropped the interoperability protocol in hangouts, take a wild guess why.
PGP/GPG can sent to group-messages (one message encryped for multiple recipients and may optional provide proof of the sender), does not imply any protocol like XMPP, and stores messags in a secure manner too. The drawback is, you have to take care of your private-key and your friens, partners, business-associates public-keys.
If somebody really inists that key management sucks with GPG/PGP let them do some key management and distribution only with a symmetric cipher.
Key-Managment with PGP/GPG is a light, soft breeze compared to that. Some people even used it as an excuse to party.
I understand why people have dropped privacy and anonmyity, it is no fun to follow procedure and there are so less benefits compared to every other social media app, it is so comfy to state you have nothing to hide and not care about the implications.
With PGP/GPG you won't have 600 friends, that means caring about 600 keys, that is basically one revoke a week if you are lucky and all you friends master crypto and revoking and getting their new key signed.
If you want to understand a bit crypto it may take a good tutor to teach you the very basic concepts and history of using crypto within 2 schooldays, 16h (and they'll hate you afterwards and they won't pay that).
Another way to accomplish anonymity is to not use the so called internets, but I guess that is either very comfy or intresting.
Welcome to counterintelligence, have a nice day.
Sorry I forgot to point out https://en.wikipedia.org/wiki/Perfect_forward_secrecy
The video and the links at <http://ec.europa.eu/justice/newsroom/data-protection/news/12... contradict at least the point of free personal data flow, european data seems to go only in some directions:
Facebook: http://www.facebook.com/EUJustice
Twitter: https://twitter.com/EU_Justice
That would nullify the only acceptable reason to use it in the first place, I think I'll stay with vi ~/TODO :)
I really concur and like to add there are now one or two generations of young adults and their kids out there, who have never even considered privacy (as in non-exhibitionism).
Last time I checked Chrome it wasn't possible to remove certificates from the store, has this changed yet?
On consumers I would not expect much change to any other non-us service that keeps you invested and locked-in. There simply are no alternatives, some european services are currently shutting down.
Even Schneier is stating that if you aren't connected with us social media, you simply stop to exist for certain groups of people. That rule applies to nearly every european user too.
The option that somebody already is self hosting and using secure end to end crypto, it may be wise to add that option; it is not really breaking news to the people with the tin-foil-hat.
I will never, ever, understand why I would like to delegate something so trivial and marginal to a distant server, for example:
Todo: change password from XXX to ZZZ.
I can imagine only procrastination as a valid reason to do so, because you can state that your todo-list isn't available to you, and its not your fault.
There may be information leaking (as in fingerprinting) from your device (that you are not aware of) that would allow very easy correlation, like in a mac address or existing session cookie, similar address in a public open network or whatever you can imagine to compromise your anonymity, that gives an adversary any advance to successfully correlate your current session with one of your previous sessions.
At this event your anonymity becomes a pseudonym.
The next step would be to try to reproduce or predict behavior and setup a trigger for that information.
If the loss (compromise) of anonymity or pseudonymity may lead to imprisonment, torture, assassination or death this maybe an issue to consider.
If you try to obfuscate your access to porn, it is a completly different story.
It depends on distribution and packetmanager, I quit using debian based approaches a long time ago for that and some other reasons.
The tradeoff is the same as keysize in crypto. It is time.
If you choose to communicate a second time from the same endpoint with the same equipment you may achieve only pseudonymity.
Since Tor doesn't limit the encapsulated protocols, it depends on the implementation and awareness of the user and you can't put a number or percentage on that.
Imho the Tor-role has changed, it provides access against censorship, DPI, region-partioning and hidden services. Simply try to access youtube or any other global service via different tor exits, that may be intresting, not from an anonymity point of view.
With SSL, both parties negotiate synchronous encryption (like in AES) and key exchange (like in RSA) for that, the trust is established with signed certificates obtained from a 3rd party. Which is/was fine on paper and concept, the implementation sucks and we don't have alternatives to that.
All Convergence does is delegate to another 3rd party, which may lead to the conclusion there may be an attack in progress, that you may not have noticed before. You still have to trust another stranger that may offer you some perspective on issued and signed certificates (or not).
Convegernce i.e. refused to work with CDNs which may have different certificates for the same domain for example, which may be completly valid.
The key of public key crypto (like in RSA) was to make key management easier and independent of a 3rd party, to avoid further bloat, overhead and complexity.
This is the same for Certificate Transparency/Pinning mentioned earlier, given the details it looks very strong on paper, but the implementation will suck in r/l terms.
Learn and understand crypto, develop and follow procedure to embrace secure end-to-end communications with your peers.
It simply does not need to scale very well to scare the few people which understand crypto and plausible deniability.
Since you are doing crypto, chances are high you are doing it wrong the first approaches.
Considering this, my choice would be to start with a believable pseudonym and generate a gpg- and/or rsa-key to sign stuff and tie it to that psudonym.
If something goes wrong you simply revoke and nothing happend. For the rare occasion of success you can still prove your are that person.
There are no implications for an average netizen, since an average netizen doesn't use strong end-to-end crypto nor does he/she avoid cloud-like-storage/services (it doesn't matter which).
Average individuals aren't opposing her/his government or committing a felony.
They simply can't anymore because they would provide their own evidence/leverage against them or simply because there is nothing left to hide anymore.