QuicksearchCodenews SearchDisclaimerThe individual owning this blog works at Sun Microsystems GmbH in Germany, a subsidiary of Oracle. The opinions expressed here are his own, are not necessarily reviewed in advance by anyone but the individual author, and neither Oracle nor any other party necessarily agrees with them.
NavigationCategories
|
< Proof-of-concept hack for encrypted direct messages on Twitter | The future of OpenStorage - or: Opensolaris Storage Summit >
DeniableMonday, February 23. 2009Trackbacks
Trackback specific URI for this entry
No Trackbacks
Comments
Display comments as
(Linear | Threaded)
Hi,
it's better not to be caught with the private key in your pockets or with a key that someone else had put in your pocket. And you better withstand some 'social engineering' tactics with hot coals or pincers. I hope most of us have their notebook harddisks encrypted for example. But how long can you stand if someone is beating you with a watschboing? IMHO this is one of the problems we are facing.
When you arenīt named as the receipient there is no hint pointing to you having the knowledge of the key, so it gets less probable that they warm the coals for you.
It is possible to find out the recipient's public key ID from looking at the ciphertext. Just try to decrypt it without having any secret keys in your keyring:
GNUPGHOME=/tmp gpg --no-default-keyring foo.gpg Use "--throw-keyids" during encryption to avoid this.
This would be one of the issues someone would have to solve in the case she or he wants to implment this outside a hack.
So you're writing up an article about deniability and then choose to ignore the major flaw in your architecture? That's just plain irresponsible. What you have here is not a "hack" but a stupid recipe for trouble.
Hi,
even if the identity of the participants is obscured by an approach it's sometimes enough to be suspected to be the owner of the key. According to a police chief from Frankfurt IIRC it's OK to hurt people to bring them to a point where they confess everything you want. The police chiefs statement led to far less opposition from our democratic parties than desired. Again, IMHO this is the way we are going. Maybe we can find technical solutions for this problems (Some people don't name this a problem, but I do), but I guess we need some other sharper tool.
The deniablity was just an add-on and not part of the original idea. Just an afterthought.
To fix this, i just have to add some gpg options .... the code isnīt meant for production, thus flagged as proof-of-concept ...
You can encrypt in shared secret key, optionally sign with a public key. Now, the person who posts such a message on a dead drop is always susceptible to the hot coal treatment, and if they know the recipient or any clues to finding the recipient, then the recipient is in trouble.
Also, ciphertext is pretty obvious. Steganography is not going to help you in Twitter, so you'll be limited to very small, coded-but-not-encrypted messages. For bulk espionage this just won't do. More nefarious uses are another story; for those the number of dead drops that could be used abound. |
Links in this articleThe LKSF bookThe book with the consolidated Less known Solaris Tutorials is available for download here
Twitterfeedstwitter.com/c0t0d0s0
just blogged: Reengining: I've learned in the last few weeks that a simple design decision can make your life much... http://bit.ly/d9luy8 twitter.com/codenews 6935782 need to manually increment build number one more time http://bit.ly/aMqEbX twitter.com/SunPatches 128365-04 - Sun Crypto Accelerator 6000 1.1: Driver Patch. Available for SPARC since Mar/19/10. http://bit.ly/agl9Nw twitter.com/SolPatchesX86 118192-04 - SunOS 5.9_x86: gtar patch. Available since Mar/19/10. http://bit.ly/cbnoJ7 twitter.com/SolPatchesSPARC 118191-04 - SunOS 5.9: gtar patch. Available since Mar/19/10. http://bit.ly/cb2Drj Web 2.0Contact
Networking open.bc My photos SyndicationTagged articlesAMD Apple avs Bahn Blogging Blogosphere braindump Business Travel CeBIT cec cec2006 CMT del.icio.us deutsch dtrace fliegen Fundsache General Hamburg IBM i hate sundays Intel iscsi jumpstart Links Linux lksf Mindfuck Movies Music Musik Niagara Opensolaris Opteron Photographie policy of ... Politik Security Solaris storage Sun suncec2007 sunw t1 The IT Business Ultrasparc ultrasparc t1 Wirtschaft Work ZFS
CommentsSat, 20.03.2010 08:55
Yes. And I just don't like the
way they're killing all of Su
n brands.
They could just buy
, help, let live, contro [...]
Sat, 20.03.2010 08:49
Well, I don't think many peopl
e were using Solaris at home b
efore Oracle acquisition too,
I see home servers more [...]
about Who are you?
Sat, 20.03.2010 02:15
Ich bin im Rahmen der Diskussi
on um das Zugangserschwerungsg
esetz auf dein Blog gestoßen.
Als Linux-Begeisterter d [...]
Sat, 20.03.2010 00:32
The article doesn't explain wh
y the adquisition of Sun is go
ing to be a sucessfull. It onl
y says that we all know: [...]
Fri, 19.03.2010 20:58
Well, I am being paid to take
care of Solaris 10 systems and
my company will continue to u
se it. But the relativel [...]
Buttons![]() This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 Germany License
![]() ![]() ![]() Blog Administration |