NSA: Please Turn off the Lights When You Leave. Nothing to See Here.

Linux Advocate Dietrich Schmitz shows how the general public can take action to truly protect their privacy using GnuPG with Evolution email. Read the details.

Mailvelope for Chrome: PGP Encrypted Email Made Easy

Linux Advocate Dietrich Schmitz officially endorses what he deems is a truly secure, easy to use PGP email encryption program. Read the details.

Step off Microsoft's License Treadmill to FOSS Linux

Linux Advocate Dietrich Schmitz reminds CIOs that XP Desktops destined for MS end of life support can be reprovisioned with FOSS Linux to run like brand new. Read how.

Bitcoin is NOT Money -- it's a Commodity

Linux Advocate shares news that the U.S. Treasury will treat Bitcoin as a Commodity 'Investment'. Read the details.

Google Drive Gets a Failing Grade on Privacy Protection

Linux Advocate Dietrich Schmitz puts out a public service privacy warning. Google Drive gets a failing grade on protecting your privacy.

Email: A Fundamentally Broken System

Email needs an overhaul. Privacy must be integrated.

Opinion

Cookie Cutter Distros Don't Cut It

Opinion

The 'Linux Inside' Stigma - It's real and it's a problem.

U.S. Patent and Trademark Office Turn a Deaf Ear

Linux Advocate Dietrich Schmitz reminds readers of a long ago failed petition by Mathematician Prof. Donald Knuth for stopping issuance of Software Patents.

Showing posts with label RetroShare. Show all posts
Showing posts with label RetroShare. Show all posts

Friday, September 5, 2014

RetroShare: An Essential Privacy Tool Introduction

RetroShare shown running on my Fedora 20 LXDE Desktop


Maybe you feel defeated?  You have that sense of helplessness?

Yout think, "Don't fight it.  We can't win against them.  There is no privacy on the Internet."


Give up?

No.  Don't give up.  Fight back.  There is an easy tool, now, today, at your disposal, which as far as I am concerned is not difficult to install and immediately use that will assure 100% privacy on the Internet.

What tool?  It's shown above running on my desktop.  It's called RetroShare.

You see, the NSA is perfectly happy you use Google's tools, including Drive, Gmail.  They are clear text and there's no difficutly in their getting to that repository if they choose to do so.

On the other hand, the NSA is not happy about tools like RetroShare.  So much so, in fact, they cannot invade your privacy space on Retroshare.  They cannot penetrate the encryption.  Enjoy privacy on your own terms with RetroShare.

RetroShare is a mature product in continual refinement since 2006.  The feature set is robust.  To learn more, check out their wiki, FAQ, and screenshots.

So, go ahead and try RetroShare.  If you get on-line, give me a shout.  I'm here.

RetroShare is open source and free.  Download here.


Watch my screencast: RetroShare: An Essential Privacy Tool



-- Dietrich

Thursday, October 31, 2013

RetroShare: For the Paranoid in You!

by Dietrich Schmitz
(Originally published: 6/7/2013)
[Edit: Some raised concern about sharing their F2F key via regular email.  To use a 'darknet' method, try either cryptocat.bin or cryptocat.org]

It's all starting to make sense now.  We've heard rumors that this National Security Agency was snooping around in our private affairs.

Turns out, it's been going on for longer than we think, like, since 1952?  That's the latest.

So much for the book 1984.  Should have been 1952.  Okay so what if George Orwell was off by about 32 years.  Still, it's amazing how he pegged the future with such eery accuracy.

Okay great so, now what do we do given that our every move is being examined like getting a colonoscopy?

You should now not worry what people think if you take extra precautions with your privacy, particularly on the Interwebs.  That's right.  Let them call you paranoid and then throw one of these stories in their face and say with confidence: YES, I AM PARANOID AND I AM FINE WITH THAT!

So seriously, is there anything that can be done on the Interwebs without having it owned and/or seen by someone these days?

Actually, I am glad you asked the question.  It just so happens there is.

An interesting piece of software has been in development going on several years now, called RetroShare.  Errrm okay, sooooo.

So let's check it out.

RetroShare


What is RetroShare?


RetroShare is the next generation sharing network, which provides:

  • Reliable Identification and Authentication of your friends.
  • Plus an Introduction Scheme which connects you to the friends of your friends, and facilitates network growth.
  • Encrypted Communication, ensuring all shared information is known only to you and your peers.
  • A Communication Platform which can potentially support services such as Secure Email, File Sharing, Streaming, Video or Voice over IP, Photos, Wall and Messaging
  • A Decentralised Social Sharing Network designed **For the People** with no dependancies on any corporate system or central servers.
RetroShare is built on GnuPG and is a serverless encrypted peer-to-peer network, but with a slightly different twist, called 'Friend-to-Friend' or F2F for short.

You see, this is a 2048-bit RSA-encrypted SSL tunnel through which your activity travels but every node along the P2P network is on its own 'private' channel.  In other words, there may be thousands of users using RetroShare but you only see those 'Friends' with whom you explicitly take the step of sharing your private F2F key.

Setting up RetroShare is easy.  Once installed, you send an email to your Friend(s) with a copy of the F2F key.  Then, they do the same, by installing RetroShare and sending you their F2F key.

The result?  Log into RetroShare and immediately you'll see your Friend on the private chat, and if you choose you can also share file folders with them and also emails.

Probably one of the most interesting aspects of RetroShare aside from being P2P is that email is a totally closed loop--just between you and strictly your Friends.  For an email to reach you, the sender must possess a copy of your F2F key and you must have their F2F key.

It completely eliminates spam.  And provided that you are only friending people with whom you are personally familiar, there's no loss of privacy whatsoever, in terms of your private activities.

Aside from eliminating spam, it's going to be really hard for any kind of eavesdropping on this system because of the SSL tunnel and 2048-bit length RSA encryption key cipher strength.  How hard?  Reheheheheheheheheheheheheheheheheheheheheheeeeeally hard.  Here is an example of how hard:


I fully expect to see comments stream in with assurances that this key is crackable.  No one has been able to substantiate such claims to me.  But please, bring it.

Feature Summary

  • Serverless, completely decentralised
  • Multiple simultaneous downloads / uploads
  • Search Friends
  • Messages
  • Forums
  • Channels
  • Voice over IP
  • Instant messaging
  • Groupchat
  • GnuPG Authentication
  • OpenSSL Encryption
  • adding downloads via website links
  • Plugins support
  • UPnP / NAT-PMP port forwarding support
  • Graphical User Interface written with Qt4 toolkit
  • System tray integration

So Folks, this is really is a nice implementation and I seriously recommend you try it.  Now that cat has been let out of the bag that 'big brother' truly IS watching (like we didn't know pfffft chaahhh), go get your copy of RetroShare and let your paranoid Friends know about it too.

We can all live in a state of paranoia together, you know, as the paranoid circle of Friends on RetroShare. ;)

Be Safe.

-- Dietrich

Enhanced by Zemanta

Feeling Paranoid? Take Your Meds: RetroShare

by Dietrich Schmitz
(Originally published: August 12, 2013)

Feeling paranoid? Take your meds: RetroShare

It's therapeudic!

RetroShare is not circumventable by the NSA or any other agency.

Enjoy fool-proof privacy-assured communication with your dear and closest Friends and Family, including chat, audio/video calls, spamless-email and file sharing.



RetroShare is a peer-to-peer encrypted, decentralized (cannot be taken down like MegaUpload) system where you choose only those you deem to be 'known' friends with whom to explicitly share your Friend-to-Friend (F2F) RSA 2048-bit encryption key.

The NSA 'hate' RetroShare. It's open source and free and replicated on mirror servers around the globe so agencies cannot block its use by the general public who wish to maintain their 'right to privacy'.

Versions are available for Windows, Mac, Linux, and BSD Unix.

Privacy. It's your right. Own it with RetroShare.

Website link:

http://retroshare.sourceforge.net/

Be safe. -- Dietrich
Enhanced by Zemanta

Tuesday, August 20, 2013

Pamela Jones Voluntarily Shuts Down Groklaw.net

by Dietrich Schmitz

This is outrageous.  Pamela Jones has singularly been probably the biggest shining light on Linux Advocacy there is.  She has won many awards in recognition of her accomplishments.

Today, she posted a story about her decision to voluntarily take down her website because of her concern that email privacy has been compromised.

In her situation, she deals with and contacts many people throughout the world in the highest echelons and as such she deals with highly sensitive information, naturally.

How is she to operate in full confidentiality a website such as Groklaw in light of what has transpired with the disclosure that the NSA continue to operate a project which has become known as PRISM?  How is she to operate in light of the Patriot Act and National Security Letters, which to date haven't reached her door?

She has decided to shut down her site because she feels she has no recourse.

I submit that if she uses the RetroShare facility in conjunction with Cryptobin.org she can be assured of operating in full confidentiality, including email, file sharing, and audio calls.

We have long since past the point where government has gotten too big and isn't serving the best interests of 'the people'.

To the extent that I know and have corresponded with her on several occasions, I have reached out to her and I sincerely hope she will seriously consider setting up RetroShare to reach me (and other developers at Retroshare I know) and discuss how a 'fool-proof' method of sharing her F2F keys with anyone to whom she wishes to communicate in complete confidentiality can be implemented.  The NSA cannot circumvent Retroshare.

-- Dietrich
Enhanced by Zemanta

Sunday, July 21, 2013

Your Privacy and How Not to be Surveilled on the Internet

by Dietrich Schmitz

Now that the dust has settled over the disclosure that the NSA has been actively engaged in a surveillance program called PRISM for several years, we can now get down to the business at hand. (Image credit: www.techinasia.com)

Namely, this post highlights some of the ways you, the general public, can exercise your right to privacy on the Internet all on your own and for free.  The discussion is limited to Desktop systems only, not Tablets and Smartphones.

Some rules apply to this discussion:

1) Don't talk about private matters in a public place
2) Don't leave your valuables in an unsecured public place, lock them away for safe-keeping
3) Provide information only on a 'need to know' basis

If those rules seem obvious, it's because that's how you conduct yourself in the physical real world.  And, it's no different on the Internet.  That is common sense really when you think about it.

On-line Storage

Kim Dot Com and the MegaUpload ISP seizure by the U.S. government is a blazing roadside neon sign from which we can all learn.  It's an incomplete yet to be told story about how people used this site for storage of their personal things but turned into an International scandal when corporate entities assisted by the government brought pressure to bear with a website take down.  The whole issue of what happened and how it was handled is still unclear, but it is nonetheless emblematic of what potentially can happen if such a take down occurs and results in interrupted service for all ISP tenants, irrespective of whether they were negligent in any way.

It also points to the question of 'how' data is stored on Cloud ISPs.  Is the ISP doing anything to protect your data?  If so, what?  Those questions should be answered before storing any sensitive data in the Cloud.

In fact, MegaUpload did nothing to protect its customers' data.  As a result, the majority of tenants were held hostage to a takedown because of a few who used the site for illegal file sharing.

So what should you be looking for?  If you really have sensitive personal data then take the same precaution as you would in the real-world -- keep it locked away and don't give the key to anyone.

In the real world that is fairly easy to accomplish.  That's why we have a burgeoning business with locksmiths and safe manufacturers and such to maintain privacy.

As for the Internet, well, essentially the only way to guarantee your privacy is by employing encryption. That's it my Friends.  Encryption.  And, the only 100% fool-proof way to do defeat access thereto is with what is called Zero Knowledge Encryption (ZK).

Effectively, ZK encryption encrypts your data store at an ISP but only you have the private key to unlock the data. (Image credit: www.spideroak.com)

ZK cleans up a heretofore otherwise 'messy' relationship between the lessor of Cloud storage drive space and lessee who stores data in it for free or an agreed to periodic subscription fee.  As a direct side effect and benefit of using ZK technology, the lessor then has zero knowledge of what the lessee is storing.  Had this been the case with Kim Dot Com and MegaUpload, Kim could have asserted 'plausible deniability'.  In so doing, neither the RIAA nor the MPAA would have had reasonable and justifiable cause to legally challenge MegaUpload, as the ISP could irrefutably claim to possess no knowledge of what the lessee is storing.  Thus, commercial and governmental third-parties would have no choice but to come directly to the lessee to question how that space is being used and would be put in the position to present specific details for their inquiry directly related to suspicion of wrong doing and demonstrating probable cause for granting any search warrant.

Currently, the U.S. Patriot Act has a provision called a demand National Security Letter which allows U.S. governmental access to any ISP to obtain a copy of any account holder's private data and it legally restrains the ISP from communicating in any form that the event occurred to anyone.  Microsoft, Google and civil liberties group the Electronic Frontier Foundation, are petitioning that such represents a violation of our constitution's First Amendment rights with the Federal Intelligence Surveillance Court which oversees provisions of the Federal Intelligence Surveillance Act of 1978.

So, you can plainly see why it is coming to this.  Encryption.  Use it to protect your privacy.

Start looking for an ISP that offers Zero Knowledge, such as SpiderOak and Wuala.  Any other form of encryption in the Cloud is unacceptable.

(There are 'unofficial' rumors that Google is beginning to roll out encryption for their Google Drive storage.  If it is anything but ZK, don't use it for your personal data.)

Browsing the Internet

If you want to keep your Internet browsing habits truly private, deleting cookies, and setting the user agent string to 'DO NOT TRACK' are useless.  It's entirely up to the ISP to 'respect' the latter so don't rely upon it.

The best way to do anonymous surfing is by using a VPN proxy service.  Essentially, this service sets up the VPN service as a proxy connection encrypted tunnel between you and their end point.  The ip address given to you going out of the VPN's end point to the Internet is then randomized so that there is no relationship to your actual ip address and a translation mapping brings back all browsing over the VPN to you transparently.  Some VPNs are free, others will require a subscription fee payable monthly or yearly, such as vpnproxy, for example.

SocialNets and Chat

Being 'social' is the latest rage, of course, and the need to stay in touch with Friends encourages use of devices to text and chat.  Currently, Facebook and Google Plus use the open source standard Jabber/XMPP protocol.  By default, your chat log is stored in a central server.  And, Google very recently announced they will be phasing out Google Talk (the XMPP component) in favor of their own 'Hangout' proprietary protocol.

There is more than one way to keep your chat's fully private.  With Google's Hangout on Google Plus, you can explicitly set, for example, your chat as 'off the record' and there will be no persistent logging of your chat sessions.  Even then, if a third-party (cough PRISM) chooses to bridge your stream (aka 'Man in the Middle') they can eavesdrop on your voice, video, and text streams.

For the ultra-paranoid, currently there are a few solutions.  One is to use Pidgin with their 'Off the Record' (OTR) plugin, a name borrowed from the well-known cryptographic protocol of the same name.  This effectively allows taking any stream (AIM, Facebook, G+, etc.) and setting up an encrypted tunnel between you and the other person with whom you are communicating.




Another option is to install the Cryptocat plugin for Chrome or Firefox.  Cryptocat also uses the OTR cryptographic protocol for private messaging.

Otherwise, yet another alternative is to avoid using any of the standard messaging protocols in favor of a P2P decentralized encrypted connection via RetroShare.  I've written several stories regarding the importance of RetroShare.  Retroshare, being on its own P2P closed loop, has it's own secure messaging chat software.

Email

Email by default is clear text and if you use it to communicate it can be read along the path of mail transfer agents to its destination recipient.  And, in the case of Gmail, that email along with everything else on Drive is all unencrypted.  That means all of your data can be read by third-parties.

Encryption solutions include using GnuPG or PGP encryption.  The problem with methods like GPG encryption is that, while free, most software application implementations are not user-friendly and, as such, difficult to use by the general public.  Commercial solutions include Symantec Encryption Solutions and Phil Zimmerman's newest Silent Circle, and are both viable options to consider. (Image credit: www.philzimmerman.com)

One other realistic alternative is to use RetroShare's email.  Essentially, Retroshare's 2048-bit RSA encrypted F2F channels are totally encapsulated on a 'closed loop' away from the world wide web's non-encrypted email system.  As such, RetroShare email is guaranteed to be strictly private and devoid of any spam.

DarkNet

If you want to employ tools which offer guaranteed pure privacy, then your list of choices is only a few.  I'll save you some trouble -- the technology used is called DarkNet and, while it does sound subversive, it, however, represents the only form of software technology which is  100% 'effective' in combating Internet snooping of any kind.  Not all darknets are alike and I would encourage you to only consider RetroShare's product.  If you want to fully lock down your RetroShare environment, you are only a few click settings away from running in pure stealth darknet mode.  You need not feel embarrassed in employing this tool -- it is the NSA who should be ashamed of their activities, spying on Americans without the use of the traditional and appropriate procedural Judiciary search warrant oversight process, which provides constitutional checks and balances on the potential for abuse of authority.

RetroShare offers currently the best reference design for what should be integrated into all computer desktop GUIs.  We accept the need for integrated Office Automation tools and soon privacy-mandated applications will find their way onto the Desktop as part of a standard default deployment of operating system software.

RetroShare is written in C/C++ using the advanced Qt gui framework and is currently available for Windows, Linux, OSX, and BSD machines.

Be safe.

-- Dietrich





Enhanced by Zemanta

Tuesday, July 16, 2013

An Unmet Need: Privacy Integration on the PC Desktop

by Dietrich Schmitz

I had a nice chat (Google Plus) today with +Aaron Seigo regarding RetroShare.

He came to the realization as I have that really, thus far, there isn't any form of integrated privacy control built into any computing Desktop system.

Should there be?  We both agreed that the answer is a resounding 'YES'. (Image credit: Wikipedia.org)

It begs the question:

Should privacy software become an integrated feature, much as having a Microsoft Office or LibreOffice?

It also begs the follow-on question:

Is Internet Privacy-mandated software for general utilitarian email, chat, file sharing, voip, needed?

I submit that we are now confronted by the PRISM effect which has revealed that surveillance is ongoing with the assistance of ISPs, software vendors and the like.  Whether the assistance given to the U.S. government is voluntary or involuntary (National Security Letter) is a separate matter.

Has the government run 'rough-shod' over U.S. and foreign Internet users' privacy rights?

That question will be answered eventually and history will show whether privacy truly matters.

But in the meantime, the PRISM story has galvanized public reaction both domestically and internationally and spurred action by national concerns to begin moving their current tenancy on U.S. Cloud ISPs to off-shore safe-haven equivalents.  The general public are left without a solution to the dilemma that presents:

To what extent should I conduct my personal activities on the Internet?

This question will continue to linger and create fear, uncertainty and doubt unless an effort is undertaken to immediately shore up the general perception that Internet privacy is 'non-existent' with exception to a few limited use cases relegated to corporations and technology elite.

At least, with Federally mandated privacy laws in place, e.g., enacting an email encryption standard would have for example manifold benefits.

For one, folding the aged clear text MIME rfc standard into a layer of GPG encryption would ensure email is readable only by its intended recipient(s).  Email encryption is already being used by a small minority of corporations who must secure their correspondences.

But, there is nothing in the way of designing and implementing a 'turn key' drop-dead simple application to which the general public can avail themselves.  To date, the only application on the horizon which approaches the needed degree of usability I have found is RetroShare, and, it has the best opportunity for being further enhanced so as to become more user-friendly and a candidate for Desktop integration, since it is written in trending Qt and is ported to Windows, OSX, Linux and BSD versions.

If such a Federal mandate were legislated, it might also offer financial assistance to developers to defray their cost to create and/or modify software applications so as to become compliant.

Presumably, such a mandate would have to be on a phased schedule to come into full implementation over perhaps one or two years.  And with those dollars such software would be then made available as part of a larger privacy integration package on the Desktop.

The other perhaps as important benefit of such a mandate is that with open standard GPG keys for the sender and recipient, the currently abused/exploited MIME rfc spec sender id field could no longer be 'forged' by spammers.

ISPs could under Federal guidelines for handling email on Mailer daemon transfer agents shunt 'non-compliant' email off-line entirely if the sender's GPG key were not signed by the recipient.  The U.S. postal service could also have their own GPG postal key which by default all users would sign to receive USPS-routed email.  But as with ISPs, the USPS would also not forward email unless the sender's subkey was signed by the recipient.  That would result in a reduction of spam approaching zero and save billions of dollars spent annually on anti-spam software measures and labor expense.

Extending this idea further, having privacy integration in the Desktop ought to include support for other Internet-related activities:  Chat, file sharing, Voice over IP.

So, you begin to see that software such as RetroShare does have a large potential to be adapted for general public use to enforce mandated privacy measures for access to the Internet.

I hope that this post spurs additional feedback and moves the agenda forward for implementing standards of privacy for all who use the Internet.

-- Dietrich
Enhanced by Zemanta

Wednesday, July 10, 2013

Privacy Activists Get Involved: Looking for Able-Bodied RetroShare Testers

by Dietrich Schmitz

[Update: I've put up my F2F key on cryptobin.org -- here: https://cryptobin.org/g247b695 -- reach me by email: dietrich shift 2 linuxadvocates dot com to obtain the password. ]

Have you heard of the expression 'talk is cheap'?

With all of the controversy generated by the disclosure of NSA's PRISM surveillance program, you'd think there'd be a groundswell of interest in taking action to mount new privacy legislation.

Not so far.  But legislation isn't good enough.  What the public needs is an effective countermeasure to ensure that Privacy is maintained.

RetroShare is a true prototypical software application which immediately offers the following benefits:

fyi, I wrote a RetroShare installation how-to yesterday.  Help me test usability cases and establish feedback with the RetroShare developers.

If there are any issues which make its use difficult, they need to know.

For RetroShare to become mainstream, it needs to become 'drop-dead' easy to use.

It's not quite there yet, but it has come a long way.

Help with the testing.  Let me know if you'd like to participate.  Get involved.

-- Dietrich
Enhanced by Zemanta

Tuesday, July 9, 2013

RetroShare: True Internet Privacy Requires a Change of Habits.


by Dietrich Schmitz

I've been thinking about making changes to how I currently use the Internet.

One thing is for sure, it's hard to break old habits.

Of course, it's convenient to use Gmail.  And that it is unencrypted along with everything else including Drive is beside the point.

This convenience must be dealt with.  If your privacy is going to be protected, Americans, your only recourse is to employ encryption--unbreakable encryption.

And, I've been looking at RetroShare.

I think that RetroShare is perhaps the best example of what privacy-enabled software should offer.

But making a commitment to force oneself to adopt the needed technology is key.  It's not that hard to put into play.  I have RetroShare on my Netbook.  Let's see what it took to set it up.

Environment


First, I will say this is a discussion regarding the use of your 'home' PC.  I use PC to generically refer to your computing device.  It's an old term, and, I'm getting old.  Had an IBM PC in '83.  But I digress.  So, okay.  You are home and wondering how you can boost your privacy?.  Let's take a look at your Wireless Router.  Mine is a Cisco Linksys E3000, which I reflashed with DD-WRT, but yours may be any kind which supports uPnP.

Let's have a look at the router.  Bring up yours (my ip is 192.168.1.1) and login with your admin login id and password:

Enable uPnP support on your Wireless Router
The location of this information will vary according to your manufacturer's design.  Straight away, I am strongly recommending you use uPnP.  Why?  Because it will automatically make all of the port forwarding decisions for you.  Otherwise, you do have the choice to manually select an inbound TCP and UDP port and define the forwarding ip address of your PC on your home LAN.  But, I won't show how.  Just use uPnP if you have it.  Most routers support it.

RetroShare Software Installation


Okay with that out of the way, I am now taking you to the RetroShare website's download page.  On my PC, I am running Netrunner 13.06 Enigma, an Ubuntu derivative with KDE Plasma Workspace.  I'll just call it KDE.  I hope +Aaron Seigo and +Martin Gräßlin won't mind.  Anyhow, that means I can follow the directions pertaining to Ubuntu:

RetroShare installation instructions for Ubuntu
Sweet.  This should be easy.  And, it was.  I won't show you how to do the install steps.

So, great.  We've got RetroShare installed, you've input your name, email address, and created the needed GnuPG key and should arrive at this screen:

RetroShare main screen

There it is.  The main screen of RetroShare.  On the bottom of the window, note NAT and DHT.  If you are using uPnP on your router, both will be initially red and NAT will turn yellow and eventually green.  Both will become green all on their own without any further action on your part.  This is why I suggest uPnP.  It's the most painless way to get up and running.

If, however, your router doesn't support uPnP, you'll need to do some extra legwork on both the router side and on RetroShare in settings.  Let's take a brief look at settings:

RetroShare>Options (Gear)>Server screen
Click the gear on the left of your RetroShare, then Server and you'll see the above.  If you need to manually configure port forwarding on your router, you'll need to switch your settings to "Manually port forwarded" here.  This is the hardest part of setup on RetroShare.  But we are striving for maximal privacy here, are we not?  Yes.  I hope you will prevail and conquer this.  Be proud you did it.

And so we have presumably done the router configuration, installed RetroShare and can see we are on-line by the number of users across the peer-to-peer server-less system.

Connecting With Your Friends


Fantastic if you've gotten this far.  But, we are not doing much until we establish one or more Friends connections with people we know.  That sentence is subtle but the distinction here is important.

This isn't like a Bittorrent or Tor P2P system.  No, it is quite different and very restrictive.  It is a 'Friend-to-Friend' (F2F) 2048-bit RSA encrypted key system tunneled over Secure Sockets Layer (SSL) where all data moving along the Distributed Hash Table node list is multi-plex encrypted.

What that means is that all of the data is gibberish to anyone other than you and your designated 'Friends' with whom you have explicitly taken the crucial step to share your F2F public key.

Isn't that what you really want?  Yes, it is.  And one of the many benefits you will find in using RetroShare is that the exclusivity of F2F means that nothing will be on your private channel but what you choose, including email.  Yes, email will only go to and come from your Friends.  That means, NO SPAM.  Guaranteed.  Assured.  Isn't that great?

Alright, so sharing your public F2F key is something which you will want to exercise care doing.

Technically, you can go straight into email and send from RetroShare a Friend request to one of your gmail Friends.  But, if you take the 'ultra-paranoid' point of view (cough NSA PRISM), that email can be read by any third-party concern.  And, a rogue 'imposter' could conceivably assume the identity of one your supposed dear Friends.  That wouldn't be good.

What to do?  I think the simplest way to share privately your F2F key is to coordinate with them 'by phone call' a session for sharing, using either cryptocat.org or cryptobin.org.

It just so happens that I've tested both and they work quite well and are relatively easy to use and will become 'routine' after using once or twice.

The first thing you need to do is get a copy of your F2F key.  Where is it?  It is in Options>Profile>Certificate.  Don't be intimidated by what you see.  It's how encryption works.  You need to copy the certificate to the clipboard with the copy to clipboard button, or, right-click, select All, then right-click, copy to accomplish same.

There.  You've got a copy of the key.  Our goal here is to contact your Friend, have them do all of the preceding steps so they have RetroShare installed and ready to exchange F2F keys.  Here's the screen for the certificate:

RetroShare F2F Certificate screen
You'll notice, I intentionally erased a bit of the image to defeat anyone from copying my current F2F key.

Off we go with our Friend to cryptobin.org.  You'll see below, I have pasted in my F2F key, set the time to expire to 1 day and generated a password using the 'Generate' button.  If you leave the screen without recording the password, then your Friend won't be able to unlock the screen.  Ideally, if you have them on the phone, manually create a mutual strong password (no need to press Generate in that case).

If the user is not currently available, bookmark the url created by cryptobin and email it to your Friend.  Have them call you for the password.

Cryptobin.org screen where you can share your F2F key with your Friend securely.


And, they will do the same with you to exchange their F2F key.  Don't forget to press the 'Bin It!' button, which will encrypt your message and create the needed url for your Friend to access when they have time.

So where does the F2F key get added?  Click Add a new Friend, then select 'Enter the certificate manually' and press Next:

RetroShare Add a new Friend screen.  Select 'manual' and press Next

Now, you need to take the Friend's certificate which they sent to you using cryptobin and paste it into the second empty window and press Next:

Paste your Friend's certificate in second window

This is the Make Friend screen.  If I shared my F2F key with you, you'd be seeing my name as shown.  Only sign F2F keys for people you know personally.  This is important as GnuPG is based on the Web of Trust principle.  Here's a screenshot:

RetroShare Make a Friend screen
As you know this Friend personally, you should sign the key.  Click Finish and you are done!

Congratulations!  You are now connected to your Friend(s).

Now the fun begins with total privacy assured for Chat, email, file sharing, voice and video calling, Chat forums, and Channels.

As always, act responsibly, be a good Netizen, and obey all laws for your respective country.

I hope you will make a commitment and change your habits to reclaim your privacy.

Best of Luck and Be Safe.

-- Dietrich
Enhanced by Zemanta