NSA: Please Turn off the Lights When You Leave. Nothing to See Here.

Linux Advocate Dietrich Schmitz shows how the general public can take action to truly protect their privacy using GnuPG with Evolution email. Read the details.

Mailvelope for Chrome: PGP Encrypted Email Made Easy

Linux Advocate Dietrich Schmitz officially endorses what he deems is a truly secure, easy to use PGP email encryption program. Read the details.

Step off Microsoft's License Treadmill to FOSS Linux

Linux Advocate Dietrich Schmitz reminds CIOs that XP Desktops destined for MS end of life support can be reprovisioned with FOSS Linux to run like brand new. Read how.

Bitcoin is NOT Money -- it's a Commodity

Linux Advocate shares news that the U.S. Treasury will treat Bitcoin as a Commodity 'Investment'. Read the details.

Google Drive Gets a Failing Grade on Privacy Protection

Linux Advocate Dietrich Schmitz puts out a public service privacy warning. Google Drive gets a failing grade on protecting your privacy.

Email: A Fundamentally Broken System

Email needs an overhaul. Privacy must be integrated.

Opinion

Cookie Cutter Distros Don't Cut It

Opinion

The 'Linux Inside' Stigma - It's real and it's a problem.

U.S. Patent and Trademark Office Turn a Deaf Ear

Linux Advocate Dietrich Schmitz reminds readers of a long ago failed petition by Mathematician Prof. Donald Knuth for stopping issuance of Software Patents.

Showing posts with label SpiderOak. Show all posts
Showing posts with label SpiderOak. Show all posts

Tuesday, January 7, 2014

Insidious Chromebook, Mega Email Preview, Smartwatches, Pirate Bay Decentralizes, CES 2014

by Dietrich Schmitz

Insidious Chromebook

Yet another major PC vendor has tossed its hat into the Chromebook ring.  Toshiba announced their very own Chromebook.  What a chuckle.  Oh, a 'Flying Chair Alert' memo has been issued at One Microsoft Way.  Be careful if you work there.  Toshiba's unit has 13 inch display, for the amazingly economical price of US$280.  What a chuckle.  I've stopped keeping count -- how many vendors are making Chromebooks now?  Enough said.



Mega Email Preview

I have attempted to reach out to Kim DotCom (born Kim Schmitz) himself in the hopes that I can have a chat with him on his views regarding Privacy.  His intent to further advocating privacy for the masses is clear: Mega Cloud ISP is now out of beta, over a year old, and provides free 50GB of Zero Knowledge Encrypted storage.  Kim DotCom continues to raise the bar and has become, despite his travails with MegaUpload, an iconic 'hero' and source of hope for obtaining true privacy on the Internet.

Most recently, news leaked onto the Internet about Mega's newest project: ZKE Encrypted Email (see screenshot below).  For those who may not grasp its significance, it is, for example, not the case that Google Gmail is encrypted.  In fact, the aged RFC specification for email doesn't even consider encryption and by virtue of its age includes defects that foster wholesale email forgery (it is child's play to insert a forged sender's email address, for example), which is why there is spam in your spam folder.  It can't be stopped without revising the specification.


A leaked screenshot of the soon-to-be-released Mega ZKE Email/Chat system

It is outrageous to contemplate that, despite the recent disclosure of the NSA having taken up camp on the inside of Google's firewall to cherry-pick the public's data (Drive, Gmail) with impunity, Google has not thus far publicly stated any intention to encrypt consumer services data.  Other ISPs, including Yahoo and Microsoft have gone on public record with statements that they intend to shore up their services with strong encryption.

On the point of ZKE, only a few cloud storage providers currently offer encryption (Mega, Wuala and SpiderOak--promulgator of ZKE and their open source ZKE developer SDK framework).  Other initiatives for encrypted email are few that support ZKE, but, most notably, Mega and SilentCircle are hot on the trail to developing a system that will ensure 100% privacy--meaning the ability to crack/decode messages will effectively become impossible.  Those following this topic will recall SilentCircle initially provided email but found the level of harassment from the government for access to be a breach of the public's privacy and so pulled the plug on that service.  Now, they have stated it will be reopened and reimplemented with ZKE in mind. 

Such luxury comes currently at a cost with, for example, Symantec Corporation (merged with PGP Corporation) providing to Corporations hosted PGP-encrypted email service.

As for the masses, the Government willingly follows 'convention' in accepting US Postal Service mailed parcels and letters in envelopes with both an expressed and implied assurance that your privacy is protected on delivery to its endpoint recipient.  Federal criminal liability is defined for any tampering with your mail even.  Yet, they have no motivation to provide the same level of expectation for privacy with your Internet email.  That stands out ever-more boldly in the backdrop of the NSA PRISM/Snowden disclosure in 2013 and punctuates all the more an unmet need to provide strong encryption on the Internet for not just commercial but consumer privacy.

In an apparent double standard, Google has feathered their own nest, by ensuring that commercial security standards are being met by providing encryption for their Google Cloud service.

Be assured, if Google take no action on this issue, I will exit using Google Gmail/Drive just as soon as Mega ZKE Email arrives.


Smart Watches

Pedestrian1: "Excuse me, Do you have the correct time?"
Pedestrian2: (Proudly brandishes his smartwatch) "Yes I can give it to you to the millisecond and in any time zone.  Oh, if you like, I can tell you the value of pi with 12 decimal places of precision!  Oh wait.  Someone is calling me on my watch."

Sound far-fetched?  Maybe a little.  But if things continue the way they are unfolding (image right: Samsung Smartwatch), we'll see the end of Swiss Watches with ruby jewel-pivot accuracy and a flood of what appear to be silicon-laden wrist watches that condense on their ASIC chipsets all manner of technology providing yet more techno-lust in a smaller, lightweight form-factor, with convergence of smart phone and any other imaginable application that can run in the current nanometer-realm.  There doesn't seem to be any constraint as memory capacity continues to increase, SSD form factor gets smaller, and ARM processors with reduced power consumption grow in power (processor arrays) and operating systems containing a Linux kernel continue to pervade all corners of our lives.


Pirate Bay Decentralizes

Let me be clear.  I am strictly against the theft of Intellectual Property or Copyrighted material.   But I do feel strongly that revision to laws on a country-by-country basis need to keep pace with the level of change occurring around us.  Real-world personal habits have changed, and technology has single-handedly changed our lives in many positive ways that could not have been imagined 50 years ago or more when the laws were originally framed and enacted.  

By virtue of how the Internet works, there is an increased desire and tendency to share.  People conduct sharing on many levels (texting, email, pictures, documents, music, video) and given how easy it can be to do, they do it often without giving any thought to the legal implications.  Generally speaking I think people know when they are doing something wrong, but I maintain, 'fair use' should come into play when doing certain kinds of sharing on the Internet.

By the same token, enforcement of laws governing IP and Copyright Ownership should not preclude consideration for if and when censorship should be applied.   Enforcement efforts have been in effect for some time.  The MPAA and RIAA have rolled out a Six Strikes and You are Out enforcement plan with the assistance of Internet Service Providers (ISP) to 'monitor' user Internet activities.  (Not all ISPs have agreed to participate in this program.  Please check with your Internet Service Provider's policy on this issue.)

This is, to my mind, wrong and smacks of a total breach to the public's right to privacy as well as an overreach of censorship.  How effective their plan has been is not clear, but many new software technologies are coming to bear to provide users with the needed tools and resources to ensure their activities remain private such as ZKE, RetroShare, Mega, Wuala and SpiderOak.

The NSA scandal of 2013 has now galvanized public awareness and catalyzed a renewal of initiatives to offer strong encryption across all Internet services for both consumer and commercial use.

The Pirate Bay has clearly been the target for long-standing IP and Copyright theft.  That cannot be disputed.  Yet, despite what happened to their founders (jailed) and what happened to MegaUpload (take down of central servers) the Pirate Bay lives on. They are now are embarking on a plan to decentralize their network to beat censorship.  At the very least, new technology that curbs inappropriate censorship is needed until the gray area between 'fair use' sharing and outright theft is clearly defined.  This is all complicated by a 'borderless' Internet which doesn't see country borders or know about treaties to offer recognition for differing treatment of existing international laws.

CES 2014

The annual Computer Electronics Show begins today, January 7 and goes through January 10.
I was an avid follower of this event going back to 2006 when many new technologies were first revealed.  In 2007 I recall the level of anticipation was palpable surrounding new technology paradigms like the Nokia N95 (I bought one) and the first generation Apple iPhone (I didn't buy one -- hate it to this very day -- Android is King).

Anyhow be tuned over the next few days for product announcements.  I'll be watching closely.

--Dietrich




Enhanced by Zemanta

Friday, December 6, 2013

Google: Don't try to change the law. ENCRYPT GMAIL/DRIVE!

by Dietrich Schmitz

Okay so Google are pushing today for changes to be made to Internet request for access to their data infrastructure by third party entities, namely, our Government.

I think this is the wrong way to go about it, and I won't sign their petition (below). (Image credit: zeroknowledgeprivacy.org)

If Google can encrypt their 'Google Cloud' product, then they should apply the same standard for the general consumer (public) of their Gmail/Drive services.

If software vendors like SpiderOak, Wuala, and now Microsoft and Yahoo can muster the requisite technology to facilitate encrypting all of consumers' private data, there is no excuse for Google not following suit.

Do the right thing Google.  ENCRYPT GMAIL/DRIVE with Zero Knowledge Encryption technology.  -- Dietrich




Enhanced by Zemanta

Thursday, October 31, 2013

Tyranny Will Gain a Foothold if People of Good Conscience Remain Silent

by Dietrich Schmitz

A good Friend, +Yie-Ming Chen wrote in a Google Plus post of mine today:

"All tyranny needs to gain a foothold is for people of good conscience to remain silent." - Edmund Burke 
Tyranny is at our door knocking.  Today's news included a story in the Washington Post NSA Infiltrates links to Google, Yahoo, worldwide, Snowden documents say.  (Image credit: Washington Post)

Another revelation has been made that the NSA have been camping out on the inside of the Google cloud firewall, cherry picking data -- yours -- like taking candy from a baby -- the method for how the NSA exploit to break through the front-end SSL server is documented in slides like the one shown above.

Sadly, the data fest has been going on for quite some time and Google and Yahoo officially disclaim any knowledge that such activities have been occurring.

It's too bad because the entire cloud behind the firewall has been 'clear text' as shown in the above slide, which means your data isn't encrypted and directly human readable.

Why hasn't Google taken steps to protect your Drive data with encryption?

The truth of the matter is: MONEY

Advertising revenue is obtained by parsing your documents and positioning adverts in the gutter margins as users of Google services like Drive and Gmail go about their daily business.  If Google were to encrypt your data, then they could not read it and run adverts any more.   

It is outrageous that Google chose not to take action because of this and I would suspect the same pertains for Yahoo.

This is a major error of negligence and abrogation of responsibility on the part of Google to protect the public's right to privacy.

The technology has been available right along which is now routinely used by other cloud services like SpiderOak, Wuala, and Kim Dot Com's Mega to encrypt the entire data stream of data space in the cloud.  It's not difficult to implement and even SpiderOak have now offered their own software framework, Crypton.io, for Developers to implement Zero-Knowledge Encryption (ZKE) at any Cloud ISP.

This is no longer an option.  ZKE should be considered a mandate and, as such, consumers and businesses should insist upon having it or boycott using the respective Cloud ISP's services.  If we all insist on it, we will have power in numbers and can have an effect on the outcome hopefully in a positive way.

The benefit to the user of rented Cloud data space employing ZKE is that all data stored in the Cloud is first encrypted locally (in the memory space of the user's PC) and a private key is maintained locally by the user not physically present on the Cloud data drive.  This makes the data on the Cloud transparent and as such the ISP will have Zero Knowledge of what is being stored other than an encrypted byte stream written to a block level drive.

With ZKE for a third party to request access would then require their serving the owner of said data with a warrant before viewing the personal and privately protected information.  Good citizens presented with a warrant will comply and unlock their data if the warrant is justified by a Court Judge as having 'probable cause' for issuance.  That has always been historically the case up to 9/11 but with the Patriot Act, the erosion of the U.S. Constitution was begun.

Today, some twelve years hence, the degree to which the law has been disregarded is allowing unobstructed intrusion into all corners of our private electronic communications.

I am drawing the line here.  Google must take steps immediately to adopt ZKE for all of their media storage used by consumers and businesses or I will no longer support and use any of their services whatsoever.

They have two weeks to come up with a clear public plan to protect the public's data from unwarranted access or I will end it.  Boycott Google Cloud services if they fail to act.

 -- Dietrich 
Enhanced by Zemanta

Sunday, July 21, 2013

Your Privacy and How Not to be Surveilled on the Internet

by Dietrich Schmitz

Now that the dust has settled over the disclosure that the NSA has been actively engaged in a surveillance program called PRISM for several years, we can now get down to the business at hand. (Image credit: www.techinasia.com)

Namely, this post highlights some of the ways you, the general public, can exercise your right to privacy on the Internet all on your own and for free.  The discussion is limited to Desktop systems only, not Tablets and Smartphones.

Some rules apply to this discussion:

1) Don't talk about private matters in a public place
2) Don't leave your valuables in an unsecured public place, lock them away for safe-keeping
3) Provide information only on a 'need to know' basis

If those rules seem obvious, it's because that's how you conduct yourself in the physical real world.  And, it's no different on the Internet.  That is common sense really when you think about it.

On-line Storage

Kim Dot Com and the MegaUpload ISP seizure by the U.S. government is a blazing roadside neon sign from which we can all learn.  It's an incomplete yet to be told story about how people used this site for storage of their personal things but turned into an International scandal when corporate entities assisted by the government brought pressure to bear with a website take down.  The whole issue of what happened and how it was handled is still unclear, but it is nonetheless emblematic of what potentially can happen if such a take down occurs and results in interrupted service for all ISP tenants, irrespective of whether they were negligent in any way.

It also points to the question of 'how' data is stored on Cloud ISPs.  Is the ISP doing anything to protect your data?  If so, what?  Those questions should be answered before storing any sensitive data in the Cloud.

In fact, MegaUpload did nothing to protect its customers' data.  As a result, the majority of tenants were held hostage to a takedown because of a few who used the site for illegal file sharing.

So what should you be looking for?  If you really have sensitive personal data then take the same precaution as you would in the real-world -- keep it locked away and don't give the key to anyone.

In the real world that is fairly easy to accomplish.  That's why we have a burgeoning business with locksmiths and safe manufacturers and such to maintain privacy.

As for the Internet, well, essentially the only way to guarantee your privacy is by employing encryption. That's it my Friends.  Encryption.  And, the only 100% fool-proof way to do defeat access thereto is with what is called Zero Knowledge Encryption (ZK).

Effectively, ZK encryption encrypts your data store at an ISP but only you have the private key to unlock the data. (Image credit: www.spideroak.com)

ZK cleans up a heretofore otherwise 'messy' relationship between the lessor of Cloud storage drive space and lessee who stores data in it for free or an agreed to periodic subscription fee.  As a direct side effect and benefit of using ZK technology, the lessor then has zero knowledge of what the lessee is storing.  Had this been the case with Kim Dot Com and MegaUpload, Kim could have asserted 'plausible deniability'.  In so doing, neither the RIAA nor the MPAA would have had reasonable and justifiable cause to legally challenge MegaUpload, as the ISP could irrefutably claim to possess no knowledge of what the lessee is storing.  Thus, commercial and governmental third-parties would have no choice but to come directly to the lessee to question how that space is being used and would be put in the position to present specific details for their inquiry directly related to suspicion of wrong doing and demonstrating probable cause for granting any search warrant.

Currently, the U.S. Patriot Act has a provision called a demand National Security Letter which allows U.S. governmental access to any ISP to obtain a copy of any account holder's private data and it legally restrains the ISP from communicating in any form that the event occurred to anyone.  Microsoft, Google and civil liberties group the Electronic Frontier Foundation, are petitioning that such represents a violation of our constitution's First Amendment rights with the Federal Intelligence Surveillance Court which oversees provisions of the Federal Intelligence Surveillance Act of 1978.

So, you can plainly see why it is coming to this.  Encryption.  Use it to protect your privacy.

Start looking for an ISP that offers Zero Knowledge, such as SpiderOak and Wuala.  Any other form of encryption in the Cloud is unacceptable.

(There are 'unofficial' rumors that Google is beginning to roll out encryption for their Google Drive storage.  If it is anything but ZK, don't use it for your personal data.)

Browsing the Internet

If you want to keep your Internet browsing habits truly private, deleting cookies, and setting the user agent string to 'DO NOT TRACK' are useless.  It's entirely up to the ISP to 'respect' the latter so don't rely upon it.

The best way to do anonymous surfing is by using a VPN proxy service.  Essentially, this service sets up the VPN service as a proxy connection encrypted tunnel between you and their end point.  The ip address given to you going out of the VPN's end point to the Internet is then randomized so that there is no relationship to your actual ip address and a translation mapping brings back all browsing over the VPN to you transparently.  Some VPNs are free, others will require a subscription fee payable monthly or yearly, such as vpnproxy, for example.

SocialNets and Chat

Being 'social' is the latest rage, of course, and the need to stay in touch with Friends encourages use of devices to text and chat.  Currently, Facebook and Google Plus use the open source standard Jabber/XMPP protocol.  By default, your chat log is stored in a central server.  And, Google very recently announced they will be phasing out Google Talk (the XMPP component) in favor of their own 'Hangout' proprietary protocol.

There is more than one way to keep your chat's fully private.  With Google's Hangout on Google Plus, you can explicitly set, for example, your chat as 'off the record' and there will be no persistent logging of your chat sessions.  Even then, if a third-party (cough PRISM) chooses to bridge your stream (aka 'Man in the Middle') they can eavesdrop on your voice, video, and text streams.

For the ultra-paranoid, currently there are a few solutions.  One is to use Pidgin with their 'Off the Record' (OTR) plugin, a name borrowed from the well-known cryptographic protocol of the same name.  This effectively allows taking any stream (AIM, Facebook, G+, etc.) and setting up an encrypted tunnel between you and the other person with whom you are communicating.




Another option is to install the Cryptocat plugin for Chrome or Firefox.  Cryptocat also uses the OTR cryptographic protocol for private messaging.

Otherwise, yet another alternative is to avoid using any of the standard messaging protocols in favor of a P2P decentralized encrypted connection via RetroShare.  I've written several stories regarding the importance of RetroShare.  Retroshare, being on its own P2P closed loop, has it's own secure messaging chat software.

Email

Email by default is clear text and if you use it to communicate it can be read along the path of mail transfer agents to its destination recipient.  And, in the case of Gmail, that email along with everything else on Drive is all unencrypted.  That means all of your data can be read by third-parties.

Encryption solutions include using GnuPG or PGP encryption.  The problem with methods like GPG encryption is that, while free, most software application implementations are not user-friendly and, as such, difficult to use by the general public.  Commercial solutions include Symantec Encryption Solutions and Phil Zimmerman's newest Silent Circle, and are both viable options to consider. (Image credit: www.philzimmerman.com)

One other realistic alternative is to use RetroShare's email.  Essentially, Retroshare's 2048-bit RSA encrypted F2F channels are totally encapsulated on a 'closed loop' away from the world wide web's non-encrypted email system.  As such, RetroShare email is guaranteed to be strictly private and devoid of any spam.

DarkNet

If you want to employ tools which offer guaranteed pure privacy, then your list of choices is only a few.  I'll save you some trouble -- the technology used is called DarkNet and, while it does sound subversive, it, however, represents the only form of software technology which is  100% 'effective' in combating Internet snooping of any kind.  Not all darknets are alike and I would encourage you to only consider RetroShare's product.  If you want to fully lock down your RetroShare environment, you are only a few click settings away from running in pure stealth darknet mode.  You need not feel embarrassed in employing this tool -- it is the NSA who should be ashamed of their activities, spying on Americans without the use of the traditional and appropriate procedural Judiciary search warrant oversight process, which provides constitutional checks and balances on the potential for abuse of authority.

RetroShare offers currently the best reference design for what should be integrated into all computer desktop GUIs.  We accept the need for integrated Office Automation tools and soon privacy-mandated applications will find their way onto the Desktop as part of a standard default deployment of operating system software.

RetroShare is written in C/C++ using the advanced Qt gui framework and is currently available for Windows, Linux, OSX, and BSD machines.

Be safe.

-- Dietrich





Enhanced by Zemanta

Thursday, June 27, 2013

Privacy. It's Your Right. Own It With Zero Knowledge Application Framework

by Dietrich Schmitz

It's really time to stop having our Internet Privacy rights trifled with.  And SpiderOak's new Crypton Zero Knowledge Application Framework (ZKAF) could not have come soon enough, a toolset for developers world-wide to employ in encrypted data storage applications.

The idea behind ZKAF is that a developer need not understand cryptography to write applications which need to implement ZKAF to the underlying data store's hardware.  The framework guarantees that stored data will never be accessible to anyone other than its owner who is the only authority that can unlock it.

Third parties will simply be unable to access such data without the permission of the owner.  And, the premise of Zero Knowledge is that the Cloud ISP which is providing storage service using ZKAF can prove 'plausible deniability'.

Possessing absolutely no knowledge of what is being stored on their hardware drive infrastructure relieves them from any responsibility for what gets stored and also contingent liability (recall the MegaUpload Dot Com website Government seizure).  That type of seizure cannot happen with ZKAF.

This puts third party commercial or governmental agencies at a distinct disadvantage in not having any choice but to go straight to the owner of the data requesting access.  Citizen's taking advantage of ZKAF-enabled Cloud storage can invoke their right to privacy and leave those agencies to take legal action in public court to challenge why such access should be granted.  

We used to be a country where a court ordered warrant meant something and was first obtained before a search and seizure in a citizen's home or on their private property could be performed.  With 9/11, that effectively went out the window with the Patriot Act and National Security Letter which are unconstitutional at best.

Isn't this really the way things should be?  Isn't it time for Americans to fight back and reclaim their right to privacy?

Assert guaranteed privacy in the cloud. Insist that your Cloud ISP employ ZKAF for their storage service.  Accept no other standard.

Internet Privacy.  It's your right.  Own it with ZKAF.

God Bless America.

-- Dietrich
Enhanced by Zemanta

Sunday, June 16, 2013

Zero Knowledge for Cloud Storage: A Proposed Internet Privacy Mandate

by Dietrich Schmitz

What do you know about the 'Zero Knowledge Privacy Standard'?

What?  Oh.  That's right.  Heh.  It doesn't exist.  Sorry.

So, then you probably have zero-knowledge about the Zero Knowledge Privacy Standard.  Sorry, I am getting clever.  But I hope to raise your awareness in this story about something which you will find very important. (Image credit: spideroak.com)

What is Zero Knowledge?


For starters, it isn't a standard.  Let's get that out of the way.  It's an emerging practice used by SaaS Cloud storage providers.  Essentially, getting storage for your files in the cloud has become common-place.  The problem is that those files are directly readable by any third-party governmental agency (cough Patriot Act, National Letters, NSA PRISM) requesting access.  That makes getting to your personal and private data like 'shooting fish in a barrel'.

Zero Knowledge works by having all of your files encrypted on your local device 'first', giving you and only you ownership of the private encryption key and puts the data in the cloud SaaS provider's storage without the accompanying private key.

Effectively, that gives the ISP Zero Knowledge of what you are storing.  They don't have the private key--you do.  And, that also gives them 'plausible deniability' in not being complicit for any form of illegal activity as they can reliably assert no knowledge of what is in your files.

Also, this takes the pressure off of the ISP in acting as 'police' for governmental and powerful commericial concerns (RIAA and MPAA) who want to enforce for what types of activities people can or cannot engage in when using cloud storage.

What is happening today is a total breach of your right to privacy.


The solution, Zero Knowledge, is technically feasible and I might add being offered by several ISPs, such as SpiderOak and Wuala.

We, the U.S. citizenry, continue to watch as our constitutional rights erode.  The only tool we have to fight back against the growing incursion into all corners of our personal life is encryption.

I submit that Zero Knowledge for Cloud Storage be strongly lobbied as a Federal mandated piece of legislation.  Contact your Senator, Congressman and let them know you want Zero Knowledge for Cloud Storage enacted.

-- Dietrich
Enhanced by Zemanta