Showing posts with label Encryption. Show all posts
Showing posts with label Encryption. Show all posts

Monday, July 7, 2014

'Invisible' - Encrypted instant messaging project seeks to obscure metadata.


'Invisible' - Encrypted instant messaging project seeks to obscure metadata.(TechWorld). By JeremyKirk.

Cyber “security researchers are have a working prototype of an instant messaging application that aims to thoroughly obscure and scrub evidence that two parties have been chatting.”

“The Invisible.im Project,” notes Mr. Kirk, “is looking for developers, and aims to solve a difficult security problem of online messaging services: metadata, or information about other data that can give law enforcement and governments, leads on people they’re investigating.”

Even if an IM conversation between two people is encrypted,” adds Mr. Kirk, “a determination that two people merely communicated, can be enough for authorities to ask a court for warrants for other information — that could eventually compromise their [previous] conversations. That information could come from buddy lists; or, instant messaging servers that broker conversations and log information.”

“Invisible.im makes it possible for any member of the public to communicate with a journalist (or, indeed anyone) without leaving a retrospectively recoverable forensic trail behind on third-party servers,” according to the project’s website. Mr. Kirk notes that “Invisible.im was launched by [cyber] security IT analyst Patrick Gray; and HD Moore, Chief Research Officer at the security company Rapid7; the vulnerability researcher known as “The Grugg,” and another researcher, Ducktor Richo.”

Mr. Kirk adds that “the foundation of Invisible.im is built around XMPP, the widely used chat protocol. But, rather than using servers across the Internet to broker the transfer of messages, Invisible.im sets up a local XMPP server on a user’s computer. That local XMPP server then connects to the TOR hidden service.

TOR is short for The Onion Router, an [Internet] anonymity network that encrypts Internet traffic in order to give greater privacy to a Web browser. TOR can also be used to set up a “hidden” website; or, one hosted on the network whose true IP address is masked.”

“Chats are encrypted,” he notes, “using OTR, Off-The-Record, an encryption plugin. Invisible.im will use “ephemeral” encryption keys for those OTR sessions, which are scrubbed when the chat session ends. Chats will also have another layer of encryption by virtue of using TOR.”

“An “anonymous” mode of Invisible.im will allow a person to contact another person, for example, by downloading Invisible.im ; and, then entering the hidden service address of the person,” notes Mr. Kirk.

“The project is considering creating an address book so people can find the verifiable addresses of others they wish to contact. A more secure mode will allow two people who have been cryptographically verified, to chat. In that mode,” he notes, “no one can tell they are on each other’s ‘buddy lists’ or, that they have ever had a conversation, let alone when,” according to the project’s website.”

“It means authorities will not be able to infer relationships between users of the program — by passively observing internet traffic,” it said.

There Is No Such Thing As ‘NSA Proof’

While Invisible.im is clearly a move towards greater Internet privacy, I know of no ‘cyber maginot line;’ or, firewall that is absolutely, 100 percent foolproof. Brendan Sasso writing in the June 17, 2014 DefenseOne.com, contends that “while thousands, perhaps millions to billions of us as well as private-sector companies, nation-states, others, etc. — are taking measures such as adopting end-to-end encryption, there is nothing ‘NSA-Proof’ out there.”

“If they want it [NSA], they can get it,” is the bottom line to his article. And, that is almost certainly the truth. Joseph Lorenzo Hall, the Chief Technologist for The Center for Democracy and Technology, said “the idea of becoming ‘NSA-Proof, is “just silly.” “If they want it, they can get it,” he added. “The agency [NSA] can hack or, bypass many security measures — if it is determined enough,” Hall said.

Friday, February 21, 2014

Breakthrough over 600-year-old mystery Voynich manuscript.

SOURCE

Breakthrough over 600-year-old mystery Voynich manuscript. (BBC).
A breakthrough has been made in attempts to decipher a mysterious 600-year-old manuscript written in an unknown language, it has been claimed.
The Voynich Manuscript, carbon-dated to the 1400s, was rediscovered in 1912, but has defied codebreakers since.


Now, Bedfordshire University’s Stephen Bax says he has deciphered 10 words, which could lead to more discoveries.

In June last year, Marcelo Montemurro, a theoretical physicist from the University of Manchester, UK, published a study which he believes shows that the manuscript was unlikely to be a hoax.

Dr Montemurro and a colleague, using a computerised statistical method to analyse the text, found that it followed the structure of "real languages".


In February this year, a paper published in the journal of the American Botanical Council said one of the plant drawings suggested a possible Mexican origin for the manuscript.Read the full story here.

More on the Voynich manuscript here.

Friday, August 23, 2013

Built-in backdoor: German govt warns of significant Windows 8 security danger.


Built-in backdoor: German govt warns of significant Windows 8 security danger.(RussiaToday).

Documents uncovered and leaked by German news outlet Zeit Online found that the German Ministry of Economic Affairs was displaying significant unease with the combined technologies, suggesting the possibility that a backdoor could be created for further covert NSA surveillance operations.
The backdoor in question would allow Microsoft to control the computer remotely. “Trusted Computing,” a method developed and promoted by the Trusted Computing Group, is nothing new - fears were being aired over its capabilities and potential as early its founding in 1999.

TPM appeared in 2006 as security technology. However, version 2.0 would implant a chip on every single PC, allowing it to control which programs could and couldn’t be executed because under Windows 8, there is no override. The users thus basically surrender control over their computers.

One of the documents retrieved by Zeit Online found that BSI stated that “unconditional, complete confidence” in Trusted Computing by stipulations of TPM 2.0 was not possible. Trusted Computing cultivated specifications for how the chip would work with operating systems.

Another document from early 2012 mourned the fact that “due to the loss of full sovereignty over the information technology, the security objectives of ‘confidentiality’ and ‘integrity’ can no longer be guaranteed.”

While not fully clear on the specifics, the documents appear to indicate that the NSA had some form of representation at the TCG meetings – during which German officials were also present - saying that they were in favor of leaving the technology in its existing state, without any changes being necessary. This suggests that the NSA does not see TPM 2.0 as hindering its operations.

A Snowden leak from July this year showed how Microsoft worked hand-in-hand with the United States government in order to allow federal investigators to bypass encryption mechanisms meant to protect the privacy of millions.

Penton’s Windows IT Pro trade publication pointed out that Zeit Online “seem[ed] to be using a bit of imagination to connect the dots and maybe the German government has other ideas.”

In a press statement released late Wednesday, the BSI insisted that “From the perspective of the BSI, the use of Windows 8 in combination with a TPM 2.0 is accompanied by a loss of control over the operating system and the hardware used.” 


Related:

NSA has total access via Microsoft Windows.


Tuesday, June 25, 2013

NSA has total access via Microsoft Windows.


NSA has total access via Microsoft Windows.HT: WND.By F. Michael Maloof .
WASHINGTON – The National Security Agency has backdoor access to all Windows software since the release of Windows 95, according to informed sources, a development that follows the insistence by the agency and federal law enforcement for backdoor “keys” to any encryption, according to Joseph Farah’s G2 Bulletin.
Having such “keys” is essential for the export of any encryption under U.S. export control laws.
The NSA plays a prominent role in deliberations over whether such products can be exported. It routinely turns down any requests above a megabyte level that exceeds NSA’s technical capacity to decrypt it. That’s been the standard for years for NSA, as well as the departments of Defense, Commerce and State.
Computer security specialists say the Windows software driver used for security and encryption functions contains unusual features the give NSA the backdoor access.
The security specialists have identified the driver as ADVAPI.DLL. It enables and controls a variety of security functions. The specialists say that in Windows, it is located at C:\\Windows\system.
Specialist Nicko van Someren says the driver contains two different keys. One was used by Microsoft to control cryptographic functions in Windows while another initially remained a mystery.
Then, two weeks ago, a U.S. security firm concluded that the second key belonged to NSA. Analysis of the driver revealed that one was labeled KEY while the other was labeled NSAKEY, according to sources. The NSA key apparently had been built into the software by Microsoft, which Microsoft sources don’t deny.
This has allowed restricted access to Microsoft’s source code software that enables such programming.
Access to Windows source code is supposed to be highly compartmentalized, actually making such actions easier because many of the people working on the software wouldn’t see the access.
Such access to the encryption system of Windows can allow NSA to compromise a person’s entire operating system. The NSA keys are said to be contained inside all versions of Windows from Windows 95 OSR2 onwards.
Having a secret key inside the Windows operating system makes it “tremendously easier for the NSA to load unauthorized security services on all copies of Microsoft Windows, and once these security services are loaded, they can effectively compromise your entire operating system,” according to Andrew Fernandez, chief scientist with Cryptonym Corporation of North Carolina.Read the full story here.

Related: How NSA access was built into Windows

Sunday, June 23, 2013

NSA: If Your Data Is Encrypted, You Might Be Evil, So We'll Keep It Until We're Sure.


NSA: If Your Data Is Encrypted, You Might Be Evil, So We'll Keep It Until We're Sure.HT: TechDirt.
There's been plenty of commentary concerning the latest NSA leak concerning its FISA court-approved "rules" for when it can keep data, and when it needs to delete it. As many of you pointed out in the comments to that piece -- and many others are now exploring -- the rules seem to clearly say that if your data is encrypted, the NSA can keep it. Specifically, the minimization procedures say that the NSA has to destroy the communication it receives once it's determined as domestic unlessthey can demonstrate a few facts about it. As part of this, the rules note:
In the context of a cryptanalytic effort, maintenance of technical data bases requires retention of all communications that are enciphered or reasonably believed to contain secret meaning, and sufficient duration may consist of any period of time during which encrypted material is subject to, or of use in, cryptanalysis.
In other words, if your messages are encrypted, the NSA is keeping them until they can decrypt them. And, furthermore, as we noted earlier, the basic default is that if the NSA isn't sure about anything, it can keep your data. And, if it discovers anything at all remotely potentially criminal about your data, it can keep it, even if it didn't collect it for that purpose. As Kevin Bankston points out to Andy Greenberg in the link above:
The default is that your communications are unprotected.
That's the exact opposite of how it's supposed to be under the Constitution. The default is supposed to be that your communications are protected, and if the government wants to see it, it needs to go to court to get a specific warrant for that information.Hmmmm......Innocent untill proven guilty?Read the full story here.

Sunday, January 20, 2013

Google Wants Password123 In Museum Of Bad Headaches.

YubiKey

Google Wants Password123 In Museum Of Bad Headaches.(Phys).Should typed passwords ever make their way into the Memory Bin, no tears will be shed in certain quarters at Google. The search giant is taking a serious look at a computing future where users have a safer environment that can secure their online information and accounts via physical passwords, perhaps in the form of finger rings or USB sticks or keys. Google’s Vice President of Security Eric Grosse and engineer Mayank Upadhyay have presented their suggestions for better hardware authentication in an upcoming research paper to be published in Security & Privacy magazine.
Google has been investigating alternatives to typed passwords, which includes a Yubico log-on device slid into a USB reader as part of Google’s quest to help strengthen password security. Google’s eyes are on future login techniques that will be primarily device-centric. 
Wired, in a sneak peek at the research paper set for publication, reported that the paper explores several physical device options, to make a password process that will be easy to accommodate but also sufficiently secure.
Google’s suggestions include a ring worn on the finger. and the YubiKey device from Yubico. In the YubiKey scenario, it would be programmed so that it can automatically log a user into that user’s Google account. (Yubico was founded in 2007 with a prototype of its YubiKey for securing online identities. The devices are manufactured in Sweden and the U.S.)
Along with many in the industry, we feel passwords and simple bearer tokens such as cookies are no longer sufficient to keep users safe,” Grosse and Upadhyay wrote in their paper, according to Wired.
Their project focus is none too soon, as, beyond Google and within the general Internet community, hacker fever has turned into password-reset fatigue. Users have complained over wiped out mail accounts and stolen data from their hacked accounts. Security experts have argued that no passwords are really secure enough, and even CAPTCHA schemes to prove the user is human have been found lacking in keeping users safe.
Media attention to the password impasse grew widespread in November, when Wired senior writer Mat Honan wrote, “This summer, hackers destroyed my entire digital life in the span of an hour. My Apple, Twitter, and Gmail passwords were all robust-seven, 10, and 19 characters, respectively, all alphanumeric, some with symbols thrown in as well-but the three accounts were linked, so once the hackers had conned their way into one, they had them all. They really just wanted my Twitter handle: @mat. As a three-letter username, it’s considered prestigious. And to delay me from getting it back, they used my Apple account to wipe every one of my devices, my iPhone and iPad and MacBook, deleting all my messages and documents and every picture I’d ever taken of my 18-month-old daughter.”
Google’s Grosse does not see the utter obliteration of the password but instead a situation where users can be freed from the need to implement and re-enter complex passwords. “We’ll have to have some form of screen unlock, maybe passwords but maybe something else,” he said. Nonetheless, he added, the primary authenticator will be some piece of hardware.
Grosse and Upadhyay acknowledged that others have tried similar approaches and actually did not achieve much success in the consumer world, but the two authors of the research paper are not deterred. Success may come with wider cooperation outside Google. “Although we recognize that our initiative will likewise remain speculative until we’ve proven large scale acceptance, we’re eager to test it with other websites.”
According to Wired, Google has created a universal protocol for device-based authentication that is able to work independent of Google’s own services; just a web browser is needed to support the standard.Read the full story here.

Saturday, February 4, 2012

Don’t Trust Satellite Phones - Satellite Phone Encryption Cracked.


Don’t Trust Satellite Phones - Satellite Phone Encryption Cracked.(Telegraph).German academics said they had cracked two encryption systems used to protect satellite phone signals and that anyone with cheap computer equipment and radio could eavesdrop on calls over an entire continent. Hundreds of thousands of satellite phone users are thought to be affected.
We were able to completely reverse engineer the encryption algorithms employed,” said Benedikt Driessen and Ralf Hund of Ruhr University Bochum as they announced their report, “Don’t Trust Satellite Phones”.
The encryption algorithms are known as GMR-1 and GMR-2, and are standards used across satellite phone operators, including Thuraya, a leading providers. Their technology is widely used in the Middle East and Africa, including in some military applications.
Mr Driessen told The Telegraph that the equipment and software needed to intercept and decrypt satellite phone calls from hundreds of thousands of users would cost as little as $2,000. His demonstration system takes up to half an hour to decipher a call, but a more powerful computer would allow eavesdropping in real time, he said.Read the full story here.
Related Posts Plugin for WordPress, Blogger...