NSA: Please Turn off the Lights When You Leave. Nothing to See Here.

Linux Advocate Dietrich Schmitz shows how the general public can take action to truly protect their privacy using GnuPG with Evolution email. Read the details.

Mailvelope for Chrome: PGP Encrypted Email Made Easy

Linux Advocate Dietrich Schmitz officially endorses what he deems is a truly secure, easy to use PGP email encryption program. Read the details.

Step off Microsoft's License Treadmill to FOSS Linux

Linux Advocate Dietrich Schmitz reminds CIOs that XP Desktops destined for MS end of life support can be reprovisioned with FOSS Linux to run like brand new. Read how.

Bitcoin is NOT Money -- it's a Commodity

Linux Advocate shares news that the U.S. Treasury will treat Bitcoin as a Commodity 'Investment'. Read the details.

Google Drive Gets a Failing Grade on Privacy Protection

Linux Advocate Dietrich Schmitz puts out a public service privacy warning. Google Drive gets a failing grade on protecting your privacy.

Email: A Fundamentally Broken System

Email needs an overhaul. Privacy must be integrated.

Opinion

Cookie Cutter Distros Don't Cut It

Opinion

The 'Linux Inside' Stigma - It's real and it's a problem.

U.S. Patent and Trademark Office Turn a Deaf Ear

Linux Advocate Dietrich Schmitz reminds readers of a long ago failed petition by Mathematician Prof. Donald Knuth for stopping issuance of Software Patents.

Showing posts with label Edward Snowden. Show all posts
Showing posts with label Edward Snowden. Show all posts

Thursday, December 18, 2014

Your Browser: A General Purpose Remote Code Execution Tool

Google Chrome web browser security warning message


I've been reviewing the current state of Internet Privacy.

It's still a mixed bag and my conclusion is that it will remain so for quite some time.

Efforts to provide Internet Privacy are varied, depending on which ISP is employed.

The primary means for conveyance to a target website to do any kind of task is the web browser.

To put security risk into context, the web browser is a remote code execution tool.

Yep.  Let that sink in for a minute.

Where ever the user goes, the browser is set to 'trust' a remote stream of bytes which get 'interpreted' as program instructions on your PC by the web engine.

Sounds quite troubling when you think about it really.

I mean, your browser is one big catcher's mit and absorbs everything it sees in an attempt to execute instructions sent from a remote web server.

So, this catcher's mit is by default a 'security risk'.

Different software vendors take different approaches to the responsibility of writing their software in a manner that ensures it should always operate securely.

For example, Internet Explorer on Microsoft Windows, is written by Microsoft and employs 'protected mode', something akin to a software sandbox, but, technically isn't.

Google Chrome for Windows is designed with a quasi-sandbox by Google Engineers.  But they have publicly stated it cannot stop certain kinds of exploits (Javascript DLL injection) from successfully executing and gaining administrative control on Legacy Windows.  This is a fact.

But, that isn't really my point.  In each software project some 'defensive' coding has or has not taken place.

I've reported in the past that, where Fedora Linux is concerned, users running Firefox, the default installed browser, are placed in a 'real' sandbox, called Linux Security Modules (LSM) and the particular module used by Fedora is SELinux.

From a security standpoint, this is a prime differentiator between Linux and Windows.

An exploit may propagate on Windows running Chrome.  It will never propagate using Linux with SELinux.

The word 'never' comes with a catch.  You see the browser's memory space is up for 'fair game' and various code, Java, Javascript can execute remotely exposing certain parts of your running PC.

In theory, nothing bad should happen and it is assumed that code in the browser PID will never escalate to the Admin level.

But what it is doing in its own memory space is an open question.  The issue of cross site scripting remains an unsolved problem.

In this context, if a user chooses to employ a browser-based security tool designed to protect their local PC, this sets up the conditions  -- a 'fictional' exploit may, for example, attempt to steal a local browser's in-memory private keys for encryption.

So, you see, I am revising my thinking.  I'm not sure any more about using the browser for any kind of security.  It's that risky.

Using compiled, well maintained free standing open source security applications is entirely a different matter.

For example, I have Gmail.  But I don't use the browser client to access it.
I use GNOME Shell's integrated Evolution Email client, which is also used to prepare outgoing mail using GnuPG (OpenPGP) encryption.

The PID for decoding/encoding gmail runs in Evolutions local memory space, not in a browser.  Once the email is encrypted, signed, it is then and only then sent and a copy gets stored (IMAP) on the Gmail web server, in PGP encrypted form.

That's a routine process I feel confident in completely.

The notion that other software vendors can fork GnuPG and refactor it in Javascript troubles me.  This is precisely what Google is doing in their End-to-End encryption project, currently in Alpha.

The whole end to end encryption runs as javascript in the browser.
That puts the whole premise of security in the hands of the browser.

It's not acceptable.  Even now, I am rethinking how MEGA works.  Again, here, there is secureboot.js code running in your browser.

I believe there has to be a total segregation from the browser for any kind of security tool client application.  It must be compiled.  It must be open source and it must employ upstream industry standard GnuPG OpenPGP.

The browser will always be a target for attack.  Always.  Letting it also run your security is a fundamental mistake.  -- Dietrich

Tuesday, December 2, 2014

Lions, Tigers, Bears, and FBI Warnings, Oh My!

Wizard of Oz Movie (Image credit: prairiecloudware.com)


Seriously, do you tire of seeing major news plastered with warnings about cyber attacks, malware and viruses?

It really has grown to a fever pitch lately.

What stuck in my craw today was a Bloomberg report Exclusive: FBI warns of 'destructive' malware attack in the wake of the SONY attack.

Like, I should be mortified maybe?  Do these 'brainiacs' remember StuxNet?

Would it help to revisit the topic?  I'd rather not, thank you very much.  Please feel free to read the Wikipedia link on the subject.

It was the perfect road-side billboard if there ever was for why Microsoft Legacy (x86) Windows should be abandoned on grounds of National Security.

Sadly, the software industry hasn't changed and quite frankly isn't going to as long as 'big business' is married to a security-flawed 'by design' operating system.

What do I mean by 'by design'?  Microsoft provides undocumented APIs through their Trusted Platform to domestic and foreign governmental agencies (the FBI included) to have unfettered access to any Windows PC without the user's expressed permission.  (Insert sound of crickets here.)

That seems to me to be a major violation of public privacy.  And that's what the public get using proprietary software.  Transparency is non-existent.

Could writing code that facilitates having 'back doors' on to computers exist in the Open Source World?  I should think not!

Well, so far, we haven't seen any.

Of course there have been recent documented attempts by the NSA to weaken string constants in Elliptic Curve Cryptography used by Secure Sockets Layer, but it is a different kettle of fish to write a bank of code, spanning perhaps thousands of lines, dedicated to the specific purpose of providing 'backdoors' without going noticed under the Gnu General Public License for Open Source.  That kind of exploitative code cannot exist in FOSS projects.  Transparency is in full force with 'many eyes' providing the much-needed oversight.  As it should be.

Edward Snowden is correct:


“Encryption works. Properly implemented strong crypto systems are one of the few things that you can rely on." 

Unlike Open Source, the Proprietary Software Anti-Virus Business gets a boost every time one of these 'sensational' stories comes out.  It's a stimulus to obtain a desired result: the masses run out to buy AV Tools which get immediately installed.  End users fire up their AV tools, then passively watch a pretty widget on screen scanning, despite for foregoing 'backdoor' api.  The asthetic is dispensed  as the user receives a 'false sense of security'.   AV software vendors make billions of dollars in sales annually.  The partnership between Microsoft and AV Vendors is entrenched and the myth lives on.

None of this would have been mentioned if I didn't know better -- it insults my intelligence.

I know full well that if every Windows PC were to switch to Fedora Linux, all of the security issues would be gone.  Zero.  None.

So, please.  Spare me the FUD.  -- Dietrich


Thursday, August 28, 2014

Google Does Evil. And Then Some.


Every day, I go about my business using my computer tools, all the whilst thinking about what I am doing.  Specifically, I am most concerned about Privacy on the Internet.

We all know what that means at this point and given past events that punctuate the need for Privacy Protection, I see little being done about it, in particular, by Google.

You see, Google stands to profit on every little piece of meta data connected to you.  Use their products, as they want you to and you will become a slave.

Yet, the reality is Google's Terms of Service let them get away with doing with your data as they see fit.  Some of the readers may be non-plused by that fact, but it grinds my gears.


Do No Evil

Remember that slogan?  I bought into it.  They gaffed me, pulled me up on the boat.  It was real easy.

You might be thinking:  "But they have free Gmail and I've become so dependent on it and also Drive is coOL".

That is a pervasive mindset which hasn't diminished and despite my writing this post, isn't going to change anytime soon.  But my purpose here is to help the reader gain a new perspective on the services Google provides.

And, the services to which I refer are NOT the ones which you, the consumer, use.

No, this is about what Google does to profit from parsing your clear-text gmails and Drive documents.  Clear Text means they are not encrypted in any way.  That is by design.

Among all of the hideous revelations that came last year from one Edward Snowden, was the disclosure of the PRISM program run by the NSA.  When the story hit the press, the ISPs reflexively, like sleeping hound dogs, woke up and began to howl in unison, Google, Yahoo, Microsoft, expressing outrage at the extent to which the NSA has intruded electronically in Americans' private lives.  The story turned quickly to it becoming apparent that the NSA was pitching camp as revealed by Edward Snowden on the inside of Google's firewall, knowledge of which was immediately disclaimed by Google, Inc., naturally.

Time passes, people revert to their normal habits.  Not a lot has changed to force the end-user to alter their computer habits insofar as using the Internet is concerned, really.

Initiatives have been started by the ISPs to make their repositories more secure and encrypted, with exceptions, Google being one of them.

Google won't encrypt your Gmail.  Nor will they encrypt your Drive.  That would defeat their ability to parse meta data and key words they claim are used in a 'benign' way for generating Advertising revenue.  Really Google?  I've checked my Drivers License and can confirm, I wasn't born yesterday.  So please.  Don't insult my intelligence and the intelligence of my readers.

This may come to you as a surprise, but, Google is not just in the Advertising business.

And here is the kicker.  According to a story on Veterans Today by Gordon Duff dated April 10, 2013, entitled Google, Beyond the CIA: Insurgence and Espionage Factory, Mr. Duff sheds light on some of the undisclosed 'profit centers' in which Google has a vested ongoing and active interest:

"Intercepted emails expose Google as an intelligence contractor openly involved in aiding terror organizations throughout Africa, Asia and the world, working well outside any official oversight and authority, far beyond even the CIA’s wildest abuses."
Wikileaks obtained copies of some interesting email exchanges with STRATFOR, an American global intelligence company headquartered in Austin, Texas.

From one such STRATFOR email comes this:


“GOOGLE is getting White House and State Department support & air cover. In reality, they are doing things the CIA cannot do. But, I agree with you. He’s going to get himself kidnapped or killed. Might be the best thing to happen to expose Google’s covert role in foaming up-risings, to be blunt. The US Gov. can then disavow knowledge and GOOGLE is left holding the (expletive deleted) bag.”
Gordon Duff goes into further detail to explain Google's Google Ideas Groups special interests with:

"Among the STRATFOR emails Wikileaks received were some exposing Google as, not just an intelligence contractor for the CIA and Department of Defense but foreign governments as well.
Text within the highly sensitive cables outlines criminal and even terrorist activities on the part of Google including the planning of insurgency operations.  Sources have confirmed Google has helped plan military operations against Syria and has been directly involved, working with Arab states, Turkey and Azerbaijan to plan destabilization of Iran.
Emails expose meetings between Google executives and insurgency groups in Azerbaijan operating against Iran.
Under the front name of “Google Ideas Groups,” with support including “air cover,” authorized by the White House and State Department, Google Corporation is directly involved in planning terror attacks.
Wikileaks intercepted STRATFOR emails outlining Google operations in planning insurgencies and illegally conduction both foreign policy and espionage."

It is apparent that Google holds a special place in the hearts of certain Domestic and Foreign Intelligence agencies with whom they conduct business and exchange information presumably for profit.

You, the consumer are their target.  And if your profile is parsed searching for key word triggers, then you become, oh, let's see, A Person of Interest?  Yes, that's it.  Mr. Duff writes further:


"Google had long been criticized for selling “keyword intercepts” from Gmail accounts to advertisers.
However, it has long been known that, not only does Google go much further, scanning emails for intelligence, both security related and corporate, but there is no clear accounting of who Google’s clients are.
Sources indicate that Google sells email and search related intercepts to governments like China, Vietnam, North Korea and others.
Additionally, Google has been proven to accept payment for suppressing searches of news stories clients find embarrassing, to push conspiracies, to support hate groups, to work in smear campaigns and now, of course, is exposed as having armed personnel working directly with insurgents in direct violation of international law."

So, I will tell you this.  Google is doing you no favors, in fact, if you happen to be a shareholder, what they are allegedly doing constitutes Investor fraud, being involved in covert activities of the kind described above.

The Google Investor site goes so far as to say:

“We believe in the importance of building stockholder trust. We adhere to the highest levels of ethical business practices, as embodied by the Google Code of Conduct, which provides guidelines for ethical conduct by our directors, officers and employees.”

Mr. Duff astutely writes:

Nothing in any Google publication indicates that employees are involved in illegal covert operations that fall within the ICC’s definition of “war crimes.”
That pretty much makes it clear, yes?

You can appreciate that during the past few months I have begun distancing myself from Google product usage where possible and as regards especially Internet Privacy.  I felt obligated to share this information since I am now taking a much more guarded position with usage of any software.  The starting criterion for me is, it must be Open Source.  That means Google Chrome is out.  I don't store anything on Drive or Gmail unless it has been encrypted with GnuPG encryption (Ultimate) before uploading -- this is easily accomplished from the command line with google-drive-ocaml and Evolution Email Client with GnuPG.

This is a strong caution to everyone reading this.  Google is not your Friend.

Google Does Evil.  And then some. -- Dietrich

Wednesday, May 14, 2014

Edward Snowden Email GPG Encryption Tutorial

English: from http://logo-contest.gnupg.org/su...
English: from http://logo-contest.gnupg.org/subm-6.html, copyright info see http://gnupg.org/misc/logo-contest.en.html (Photo credit: Wikipedia)
by Dietrich Schmitz

Folks, I've been on a privacy jag for over a year now since whistle blower Edward Snowden broke the story of how the NSA monitor everybody's electronic communications (PRISM).

It is understandable that many have been reluctant to start using email encryption.  But there is no risk and if done with strong encryption such as free open source Gnu Privacy Guard (GPG), you can be assured that only your intended recipient will be able to open and read your mail.

So, with that, today I am bringing to your attention a youtube video put up by none other than Edward Snowden himself wherein he provides a step-by-step tutorial of how to encrypt your email with a Windows version of GPG encryption, called GPG4Win.

So, even if you aren't a Windows user per se, you can watch to get a feel for the steps required to set up your public/private key pair and publishing to a key server and how to import a public key from one of your email contacts who has set up encrypted email also.

I use Fedora 20 LXDE with Evolution and GPG.  Once you've created the keys, you don't have to repeat the same process.  It is a 'one-time' affair and then creating and sending email is done with the existing GPG keys in place.

It's not hard after you've done it a few times.  Trust me.  It will make sense.

Here's Edward Snowden's youtube tutorial.  Enjoy!  -- Dietrich



Enhanced by Zemanta

Thursday, April 3, 2014

NSA: Please Turn the Lights off When You Leave. Nothing to See Here.

by Dietrich Schmitz


It's all out in the open now. The NSA can 'cherry pick' your private and personal Internet meta data whenever they wish. Right?

Wrong. They cannot.

That is, of course, provided you, the general public, place obstacles in their way which will impede, or, better yet, stop them entirely from peering into your private affairs.

Yes, that's right. You have tools at your disposal which will most assuredly put the kibosh on the NSA. Stop them cold in their tracks. They'll come, discover they can't see anything, and leave.

What is it that will stop them from seeing your private data?:

Gnu Privacy Guard (GnuPG) or, just GPG for short.


Free and Gnu Public Licensed GnuPG is a form of strong encryption which has been deemed by experts, including whistle blower Edward Snowden, as effective in keeping your data from being snooped upon.

I recommend to Linux users free Gnu Public Licensed Evolution email for both personal and business needs. (Image left, Edward Snowden, credit: Flickr user DonkeyHotey)






Evolution email running on my Fedora 20 LXDE Desktop


Evolution is feature-complete, mature (that means stable), and supports GnuPG (OpenPGP) encryption formatted email.

Use it once or twice and I am confident you'll get the hang of it.  It will even use your existing Gmail or other email account with secure TLS POP3/IMAP connectivity.

And, for those eager to install Evolution, here is a good tutorial to get you up to speed quickly.

Need to wrap your mind around GPG? Read more about it here.


Just to give you a visual of what an Evolution created gpg-encrypted gmail looks like 'after the fact' from Gmail's web view -- there's truly nothing to see -- this is what the Google staff and NSA would find:

Evolution GPG-protected email stored on Gmail.  Nothing to see.


And, as always, if you have questions or need help, do not hesitate to contact me.

So, NSA? Please turn off the lights when you leave. Nothing to see here.  Thanks!

-- Dietrich

Enhanced by Zemanta