NSA: Please Turn off the Lights When You Leave. Nothing to See Here.

Linux Advocate Dietrich Schmitz shows how the general public can take action to truly protect their privacy using GnuPG with Evolution email. Read the details.

Mailvelope for Chrome: PGP Encrypted Email Made Easy

Linux Advocate Dietrich Schmitz officially endorses what he deems is a truly secure, easy to use PGP email encryption program. Read the details.

Step off Microsoft's License Treadmill to FOSS Linux

Linux Advocate Dietrich Schmitz reminds CIOs that XP Desktops destined for MS end of life support can be reprovisioned with FOSS Linux to run like brand new. Read how.

Bitcoin is NOT Money -- it's a Commodity

Linux Advocate shares news that the U.S. Treasury will treat Bitcoin as a Commodity 'Investment'. Read the details.

Google Drive Gets a Failing Grade on Privacy Protection

Linux Advocate Dietrich Schmitz puts out a public service privacy warning. Google Drive gets a failing grade on protecting your privacy.

Email: A Fundamentally Broken System

Email needs an overhaul. Privacy must be integrated.

Opinion

Cookie Cutter Distros Don't Cut It

Opinion

The 'Linux Inside' Stigma - It's real and it's a problem.

U.S. Patent and Trademark Office Turn a Deaf Ear

Linux Advocate Dietrich Schmitz reminds readers of a long ago failed petition by Mathematician Prof. Donald Knuth for stopping issuance of Software Patents.

Showing posts with label Pretty Good Privacy. Show all posts
Showing posts with label Pretty Good Privacy. Show all posts

Friday, June 6, 2014

Google's End-to-End is Unacceptable

by Dietrich Schmitz



Regular readers will know that I have taken issue with Google since last year on how they manage Gmail and Drive.

For starters, should any governmental agency manage to break through Google's firewall (oops, the NSA did and pitched camp last year), they will have unfettered access to your meta data and direct access to your Gmail and Drive files. (Image right: Google's End-to-End Logo)

Why?  Because they are stored in clear text (unencrypted) format.

That's odd.  Google Cloud does just the opposite.  Hmmm.  I Wonder why.  (Taps fingers.....)  That's because Google Cloud is for the 'paying customers' who INSIST that their data meet critical mandated security thresholds (FIPS).  So, Google Cloud customers, in the interest of keeping them from leaving altogether, are being assured, by Google, their data is FIPS-compliant and cannot be viewed by third-parties.  How nice of them.

When it was determined last year that the Fox is in the Hen House, many corporations left en masse U.S. domestic cloud ISPs for Western- and Eastern-Europe ISPs to avoid the NSA.  This concern is quite understandable on many levels and still nothing has been done to impede, much less stop the NSA from continuing their global eavesdropping.

Gmail and Drive are considered part of Google's consumer-facing services which are, at present, offered for free.  Most everyone using Gmail likes the fact that they get it for free, but, were they to make the effort to read their 'Terms of Service' agreement, would discover that Google reserves the right to parse any and all meta and personal clear text data belonging to the respective account holder.

Principally, the main thrust of this stipulation is so that Google can use intelligent advertisements positioned in the account holder's Gmail gutter margins that reflect subjects which might be of potential interest to said account holder by virtue of the parsing logic applied to their data stream.  Very nice, yes?  No!!!!!!!!!!!!

This is fundamentally wrong.  Users may be stuck with the current terms of service for getting their free Gmail and Drive, but, do they have a recourse?

Certainly, one option would be to drop using Gmail and Drive entirely in favor of some other solution.

Another solution is being provided by Google who have been under great public pressure to do something to protect account holders' right to privacy.

The solution is being named End-to-End in an announcement posted on Google's website.  It's not even available yet and coding for the solution is being worked on and tested before it will ever reach production release to the general public.

While that may sound good, a cursory inspection of the Google Code website reveals a few issues which I feel make this solution unacceptable from the start.

1) Google is only offering 'the solution' as a Google Chrome browser extension.  Many use Chrome.  I don't because it is 'proprietary'.  That means it is not 100% open source and so violates one of the cornerstones of FOSS: Transparency.  We cannot and do not know what is or isn't in proprietary code and because of that, potential rogue code and abuses can be introduced without the general public's knowledge and/or approval.  That is what Transparency is all about.  So, Google wants you to have 'their' solution on 'their' terms, stipulating the use of 'their' browser which in and of itself has volumes of code nobody can claim to know or understand.

2) As if #1 wasn't bad enough, Google has chosen to 'reinvent the wheel'.  Namely, the long-standing, mature, fully-debugged gpg2 open source OpenPGP standard codebase is being rejected out of hand, again because they want to do things 'their' way by creating a duplicate, immature, bug-laden codebase port of gpg2 as an incomplete subset into slow, interpretive Javascript.  That's right.  Javascript.  gpg2 is fully compiled C/C++ code.

3) Google chooses to adopt a new Eliptical Curve cryptographic standard over the proven mature RSA standard.  Recall that NIST is now in a public relations dilemma having been exposed as consorting with the NSA in introducing 'weakened' cryptographic string constants into their ECC codebase last year.  In discovering the problem with ECC, the NIST insist they had no part or knowledge of the NSA's intentional introduction of weakened code and put the code out for public review and follow up action to correct any seen defects based on public comment.  That leaves a 'cloud' in my mind over any software dependent on EC.  In terms of severity, in comparison to items 1 and 2, a thorough audit of EC might restore confidence and make item 3 less an issue in the long-term.

But fundamentally, Google's developers, it would appear, are taking shortcuts and making fundamental flawed decisions by forcing a solution which requires proprietary Chrome (Transparency violation) and creating their own immature crypto codebase to 'emulate' a subset of gpg2 OpenPGP features.  EC will only be compatible with version 2.1 of gpg2.

I am giving this project a 'thumbs down'.  Unacceptable.  Back to the drawing board Google.

-- Dietrich
Enhanced by Zemanta

Thursday, March 27, 2014

Mailvelope for Chrome: PGP Encrypted Email Truly Made Easy

by Dietrich Schmitz



I've spent considerable time researching the question: Is there an easy to use software that will let you email using PGP encryption?

The answer after several days looking, I am happy to report is 'YES'!

The software is an extension for Google Chrome called Mailvelope.

Watch the below video to help you to configure and use Mailvelope.




I am endorsing Mailvelope as the 'easiest' software, 'to date', and can assure you that if you create your PGP with a minimum of 2048-bit key length, the NSA will never be able to read your email. NEVER.

Please take control of your email privacy with Mailvelope.

Questions, concerns, do not hesitate to contact me.

Be well. Be safe. -- Dietrich


Enhanced by Zemanta

Sunday, July 21, 2013

Your Privacy and How Not to be Surveilled on the Internet

by Dietrich Schmitz

Now that the dust has settled over the disclosure that the NSA has been actively engaged in a surveillance program called PRISM for several years, we can now get down to the business at hand. (Image credit: www.techinasia.com)

Namely, this post highlights some of the ways you, the general public, can exercise your right to privacy on the Internet all on your own and for free.  The discussion is limited to Desktop systems only, not Tablets and Smartphones.

Some rules apply to this discussion:

1) Don't talk about private matters in a public place
2) Don't leave your valuables in an unsecured public place, lock them away for safe-keeping
3) Provide information only on a 'need to know' basis

If those rules seem obvious, it's because that's how you conduct yourself in the physical real world.  And, it's no different on the Internet.  That is common sense really when you think about it.

On-line Storage

Kim Dot Com and the MegaUpload ISP seizure by the U.S. government is a blazing roadside neon sign from which we can all learn.  It's an incomplete yet to be told story about how people used this site for storage of their personal things but turned into an International scandal when corporate entities assisted by the government brought pressure to bear with a website take down.  The whole issue of what happened and how it was handled is still unclear, but it is nonetheless emblematic of what potentially can happen if such a take down occurs and results in interrupted service for all ISP tenants, irrespective of whether they were negligent in any way.

It also points to the question of 'how' data is stored on Cloud ISPs.  Is the ISP doing anything to protect your data?  If so, what?  Those questions should be answered before storing any sensitive data in the Cloud.

In fact, MegaUpload did nothing to protect its customers' data.  As a result, the majority of tenants were held hostage to a takedown because of a few who used the site for illegal file sharing.

So what should you be looking for?  If you really have sensitive personal data then take the same precaution as you would in the real-world -- keep it locked away and don't give the key to anyone.

In the real world that is fairly easy to accomplish.  That's why we have a burgeoning business with locksmiths and safe manufacturers and such to maintain privacy.

As for the Internet, well, essentially the only way to guarantee your privacy is by employing encryption. That's it my Friends.  Encryption.  And, the only 100% fool-proof way to do defeat access thereto is with what is called Zero Knowledge Encryption (ZK).

Effectively, ZK encryption encrypts your data store at an ISP but only you have the private key to unlock the data. (Image credit: www.spideroak.com)

ZK cleans up a heretofore otherwise 'messy' relationship between the lessor of Cloud storage drive space and lessee who stores data in it for free or an agreed to periodic subscription fee.  As a direct side effect and benefit of using ZK technology, the lessor then has zero knowledge of what the lessee is storing.  Had this been the case with Kim Dot Com and MegaUpload, Kim could have asserted 'plausible deniability'.  In so doing, neither the RIAA nor the MPAA would have had reasonable and justifiable cause to legally challenge MegaUpload, as the ISP could irrefutably claim to possess no knowledge of what the lessee is storing.  Thus, commercial and governmental third-parties would have no choice but to come directly to the lessee to question how that space is being used and would be put in the position to present specific details for their inquiry directly related to suspicion of wrong doing and demonstrating probable cause for granting any search warrant.

Currently, the U.S. Patriot Act has a provision called a demand National Security Letter which allows U.S. governmental access to any ISP to obtain a copy of any account holder's private data and it legally restrains the ISP from communicating in any form that the event occurred to anyone.  Microsoft, Google and civil liberties group the Electronic Frontier Foundation, are petitioning that such represents a violation of our constitution's First Amendment rights with the Federal Intelligence Surveillance Court which oversees provisions of the Federal Intelligence Surveillance Act of 1978.

So, you can plainly see why it is coming to this.  Encryption.  Use it to protect your privacy.

Start looking for an ISP that offers Zero Knowledge, such as SpiderOak and Wuala.  Any other form of encryption in the Cloud is unacceptable.

(There are 'unofficial' rumors that Google is beginning to roll out encryption for their Google Drive storage.  If it is anything but ZK, don't use it for your personal data.)

Browsing the Internet

If you want to keep your Internet browsing habits truly private, deleting cookies, and setting the user agent string to 'DO NOT TRACK' are useless.  It's entirely up to the ISP to 'respect' the latter so don't rely upon it.

The best way to do anonymous surfing is by using a VPN proxy service.  Essentially, this service sets up the VPN service as a proxy connection encrypted tunnel between you and their end point.  The ip address given to you going out of the VPN's end point to the Internet is then randomized so that there is no relationship to your actual ip address and a translation mapping brings back all browsing over the VPN to you transparently.  Some VPNs are free, others will require a subscription fee payable monthly or yearly, such as vpnproxy, for example.

SocialNets and Chat

Being 'social' is the latest rage, of course, and the need to stay in touch with Friends encourages use of devices to text and chat.  Currently, Facebook and Google Plus use the open source standard Jabber/XMPP protocol.  By default, your chat log is stored in a central server.  And, Google very recently announced they will be phasing out Google Talk (the XMPP component) in favor of their own 'Hangout' proprietary protocol.

There is more than one way to keep your chat's fully private.  With Google's Hangout on Google Plus, you can explicitly set, for example, your chat as 'off the record' and there will be no persistent logging of your chat sessions.  Even then, if a third-party (cough PRISM) chooses to bridge your stream (aka 'Man in the Middle') they can eavesdrop on your voice, video, and text streams.

For the ultra-paranoid, currently there are a few solutions.  One is to use Pidgin with their 'Off the Record' (OTR) plugin, a name borrowed from the well-known cryptographic protocol of the same name.  This effectively allows taking any stream (AIM, Facebook, G+, etc.) and setting up an encrypted tunnel between you and the other person with whom you are communicating.




Another option is to install the Cryptocat plugin for Chrome or Firefox.  Cryptocat also uses the OTR cryptographic protocol for private messaging.

Otherwise, yet another alternative is to avoid using any of the standard messaging protocols in favor of a P2P decentralized encrypted connection via RetroShare.  I've written several stories regarding the importance of RetroShare.  Retroshare, being on its own P2P closed loop, has it's own secure messaging chat software.

Email

Email by default is clear text and if you use it to communicate it can be read along the path of mail transfer agents to its destination recipient.  And, in the case of Gmail, that email along with everything else on Drive is all unencrypted.  That means all of your data can be read by third-parties.

Encryption solutions include using GnuPG or PGP encryption.  The problem with methods like GPG encryption is that, while free, most software application implementations are not user-friendly and, as such, difficult to use by the general public.  Commercial solutions include Symantec Encryption Solutions and Phil Zimmerman's newest Silent Circle, and are both viable options to consider. (Image credit: www.philzimmerman.com)

One other realistic alternative is to use RetroShare's email.  Essentially, Retroshare's 2048-bit RSA encrypted F2F channels are totally encapsulated on a 'closed loop' away from the world wide web's non-encrypted email system.  As such, RetroShare email is guaranteed to be strictly private and devoid of any spam.

DarkNet

If you want to employ tools which offer guaranteed pure privacy, then your list of choices is only a few.  I'll save you some trouble -- the technology used is called DarkNet and, while it does sound subversive, it, however, represents the only form of software technology which is  100% 'effective' in combating Internet snooping of any kind.  Not all darknets are alike and I would encourage you to only consider RetroShare's product.  If you want to fully lock down your RetroShare environment, you are only a few click settings away from running in pure stealth darknet mode.  You need not feel embarrassed in employing this tool -- it is the NSA who should be ashamed of their activities, spying on Americans without the use of the traditional and appropriate procedural Judiciary search warrant oversight process, which provides constitutional checks and balances on the potential for abuse of authority.

RetroShare offers currently the best reference design for what should be integrated into all computer desktop GUIs.  We accept the need for integrated Office Automation tools and soon privacy-mandated applications will find their way onto the Desktop as part of a standard default deployment of operating system software.

RetroShare is written in C/C++ using the advanced Qt gui framework and is currently available for Windows, Linux, OSX, and BSD machines.

Be safe.

-- Dietrich





Enhanced by Zemanta

Sunday, April 7, 2013

Email: A Fundamentally Broken System

by Dietrich Schmitz

Many are too young to remember Phil Zimmerman.  He's the creator of Pretty Good Privacy (PGP) an encryption standard, now perhaps the most-used method of encrypting email. (Image right: Phil Zimmerman)

It was in 1991 when Phil saw the unmet need and brought into fruition a much needed way to encrypt human readable text.  Coincidentally, the Internet had begun to unfold and his method of encryption soon gained in popularity.

Mr. Zimmerman became, as a result, the target of a criminal investigation, brought by the U.S. Customs Service and RSA charged with violating provisions of the Arms Export Control Act.   Charges, however serious, ultimately were dropped in 1996 and Mr. Zimmerman went on to form the PGP Corporation which was bought by Network Associates in 1997.

You see, email is clear text.  Yes.  Naked.  When you casually press 'send' on an email, it travels across the mail transfer agents to its destination as a stream of human readable text which makes it child's play for interception and viewing by any agency or individual.  Essentially, you are placing your correspondence in the mail without an envelope.

Seems odd when it's put that way doesn't it?

We go to great lengths to assure the safety of all paper mail delivery (warnings on mailboxes even) as we diligently place our correspondences in an envelope for what?  Privacy, of course.  There are Federal laws on the books to protect your paper mail but none for the electronic equivalent.

So it begs the question:  Why isn't email encrypted by default?

It seems that no one really thought that question through, or, at least there was a time when the email RFC 2822 (supercedes RFC 822) was used only by a small population of  technology-elite individuals.  Times have since changed and along with change the RFC was never updated to contemplate electronic privacy.  Nor, has there been a Federal Mandate for such, which might have funded meeting a new email privacy standard.

Worse, is the now all too well-known fact that the email RFC standard can be exploited.  How so?

SPAM.  No, not the kind you eat.  Email RFC sending id field can be forged and Spammers exploit that design deficiency and insert forged sending email addresses into emails sent from compromised PCs, which unbeknownst to the user (usually a compromised Windows PC), is running a deamon process (svchost) spambot in the background, sending out literally millions of emails a day, all forged.

Thus, unless you have a spam filter program installed, your email in-box may be filled with unsolicited emails some of which are benign, others contain attachments which if opened will trigger a script to run on the victim's machine, which may be designed to gain administrative rights and install yet another trojan spambot, or, worse ransomware or keyloggers.

It's all fairly well-understood but nothing, to date, has ever been done to correct the RFC standard.

Phil Zimmerman has always been a privacy advocate, and while he developed PGP, others fortunately saw fit to follow and extend his work and developed an open source and compatible equivalent, called Gnu Privacy Guard (GnuPG).

Today, GnuPG or GPG is the linch-pin for the vast majority of Linux Distributions (Distros) and provides a 'keyring' feature to ensure that software obtained from a Distro's repository will be guaranteed to be safe from tampering (trojan horses, viral code insertions).  So, too, GPG is compatible with PGP email and allows users to encrypt (envelope) their email correspondences to guarantee privacy.

Thus far, however, the implementation of low-cost or free, 'easy-to-use' email systems with standard encryption have been few, so there truly is a huge unmet need here--world-wide.

As more users embrace the Internet and become comfortable incorporating it into their daily lives, they have also come to understand the crucial importance of privacy.  In fact, many feel that such privacy is their given right.  I agree with that.  The right to privacy is implicit and incorporated into our nation's Bill of Rights.  It's no different than the paper mail envelope analogy I gave above.

So, as I read about Phil Zimmerman in recent news, I thought, here is a Man who is passionate and truly believes in what he is doing.  You see, Mr. Zimmerman has surfaced once again, only this time he is building is own infrastructure available to the general public to use as a turnkey encrypted easy to use email service, an expansion of a company he opened last year called Silent Circle.

From the story at TheRegister.uk, Chief Technology Officer for Silent Circle elaborates on this new service:


"Email is fundamentally broken," Jon Callas, Silent Circle's CTO, tells The Register, pointing out that security was not a serious factor in the original protocols. Wrapping messages in the best possible encryption will give a measure of security, and the team have spent nearly two years honing their product. 
"We believe we've got it as good as we can get it," he said. "Nothing is perfect, and anything we find there's a problem with, we'll fix it." 
To further test the system's mettle, Silent Circle has put its source code up on Github for analysis by the security community. So far, Callas said, three possible problems have been found. None of them were serious, and all have since been fixed or ameliorated. 
The new email service will take the best of this encryption, plus some extra special sauce and tools from PGP, and aims to offer secure service to subscribers across the world.

This is going to revolutionize and create a new 'de facto' standard for email privacy.  Code for the email service is being published to GitHub for security analysts to examine and provide feedback on including recommended feature enhancements and bug fixes.

As Phil Zimmerman wrote in an essay on his website, Why I Wrote PGP:

It's personal. It's private. And it's no one's business but yours. You may be planning a political campaign, discussing your taxes, or having a secret romance. Or you may be communicating with a political dissident in a repressive country. Whatever it is, you don't want your private electronic mail (email) or confidential documents read by anyone else. There's nothing wrong with asserting your privacy. Privacy is as apple-pie as the Constitution.
The right to privacy is spread implicitly throughout the Bill of Rights. But when the United States Constitution was framed, the Founding Fathers saw no need to explicitly spell out the right to a private conversation. That would have been silly. Two hundred years ago, all conversations were private. If someone else was within earshot, you could just go out behind the barn and have your conversation there. No one could listen in without your knowledge. The right to a private conversation was a natural right, not just in a philosophical sense, but in a law-of-physics sense, given the technology of the time. 
But with the coming of the information age, starting with the invention of the telephone, all that has changed. Now most of our conversations are conducted electronically. This allows our most intimate conversations to be exposed without our knowledge. Cellular phone calls may be monitored by anyone with a radio. Electronic mail, sent across the Internet, is no more secure than cellular phone calls. Email is rapidly replacing postal mail, becoming the norm for everyone, not the novelty it was in the past. 
Until recently, if the government wanted to violate the privacy of ordinary citizens, they had to expend a certain amount of expense and labor to intercept and steam open and read paper mail. Or they had to listen to and possibly transcribe spoken telephone conversation, at least before automatic voice recognition technology became available. This kind of labor-intensive monitoring was not practical on a large scale. It was only done in important cases when it seemed worthwhile. This is like catching one fish at a time, with a hook and line. Today, email can be routinely and automatically scanned for interesting keywords, on a vast scale, without detection. This is like driftnet fishing. And exponential growth in computer power is making the same thing possible with voice traffic.

So, are you just a little bit incredulous about this story now?  Well, you should be and I hope you will exercise due care in your Internet activities.  

This service cannot come soon enough.

-- Dietrich




Enhanced by Zemanta