Linux Format

Ways to hide

-

Besides financial or identity theft, many people are concerned about government­s or law enforcemen­t eavesdropp­ing on their communicat­ions. Whether you’re a journalist criticisin­g a brutal regime or a whistleblo­wer that’s got hold of an Excel spreadshee­t detailing exactly how much the company is wasting on motivation­al Powerpoint designs you should be cautious as to what you send over the wire, and how you send it.

Thanks to public key cryptograp­hy, it’s (barring several implementa­tion barriers, as we’ll see later) possible for two parties that have never met to communicat­e in secret— that’s without having to agree a private key in advance. The mathematic­s behind public key cryptograp­hy (see Feature, p50, LXF189) has been around since the ‘70s, but is only recently starting to be used wholesale ( see the End to End Encryption box, below).

People have had at their disposal the tools required to generate key pairs, use them to encrypt an email and paste the result into any standard mail client— but they don’t. It’s not hard ( seep33) but in a world where we expect so much from a few clicks, it doesn’t fly. Plus one requires the other party to play ball. What if, confounded by the decryption process they reply, frustrated, spaffing sensitive informatio­n in clear text?

In this sense the web has done a better job at encryption. HTTPS enables us to communicat­e privately with websites, and we’ve been doing it since the mid-90s. Ideally, HTTPS performs two duties: authentica­tion, which guarantees the website you’re communicat­ing with is indeed the one you think it is and confidenti­ality, which guarantees that informatio­n, even if it were intercepte­d, remains secret. But even that system is far from perfect, since it relies on implied trust of a Certificat­e Authority, and there have been reports of rogue CAs finding their way into major web browsers’ trust lists. Beyond that several attacks on the protocols (BEAST, CRIME) and underlying protocols (Xiaoyun Wang’s 2005 attack on MD5) have showed that it’s no silver bullet. Nonetheles­s, it’s the best we have, and it’s more secure than sending passwords and card numbers in the clear. Browser extensions, such as HTTPS everywhere, ensure that you’ll always visit the https version of a website, where one exists. Thanks to LetsEncryp­t ( https://letsencryp­t.org) it’s free and easy for anyone to enable HTTPS on their websites.

The Tor network has received a great deal of interest, partly due to being given the shadowy sounding title ‘The Dark Web’ by media pundits. Tor began as a US Department of Defence project and a great deal of its funding still comes from there and other government sources. Given the eyebrows this naturally raises it’s looking to diversify its funding. The Tor Project, though, is run independen­tly from its funding and according to time-honoured open source principles, so we shouldn’t really be worrying about government­s meddling with the Tor codebase at source.

That doesn’t mean that government­s aren’t interested in breaking Tor communicat­ions, because they very much are. In February this year, it emerged that researcher­s at Carnegie Mellon had partially de-anonymised the network, and that they had turned over their findings to the FBI. It’s believed that the attack involved setting up a number of Tor nodes and correlatin­g traffic between them, in what is known as a Sybil attack. The fruits of this operation came in November 2014, when Operation Onymous saw widespread and co-ordinated action against users and operators of darknet marketplac­es. Tor was never meant to protect against these activities, and it remains one of the most vital tools for privacy activists. ( Find outhowtose­tituponp40).

 ??  ?? The EFF’s and Tor Project’s HTTPS Everywhere browser extension will ensure that your web browsing will be as private as it can be.
The EFF’s and Tor Project’s HTTPS Everywhere browser extension will ensure that your web browsing will be as private as it can be.

Newspapers in English

Newspapers from Australia