Showing posts with label cryptography. Show all posts
Showing posts with label cryptography. Show all posts

Friday, July 11, 2014

Should you continue using TrueCrypt?




It was the last days of May when TrueCrypt website suddenly was took down and replaced with a page suggesting a migration to Microsoft Bitlocker.
No one really knows what happened, I personally believe that the NSA asked the devs to do something they didn't want to, so they decided to completely stop the project, similar to what happened to Lavabit some time ago.

You can find a lot of theories and even declarations of some guys claiming to be the developers, I don't trust much in those claims, as the TrueCrypt developers were anonymous and even if they were the real devs, probably are legally obliged to deny everything and say nothing strange happened.

But the real question is, should I continue using the latest version of TrueCrypt? Is there any other software that I could use to replace it?

If you run Linux is highly recommended you migrate your encrypted volumes to dm-crypt LUKS. Linux Mint 17 Qiana installation wizard includes an option to encrypt your system partition using it, so if you don't know much about Linux, that's an easy way to start.

If you need support in multiple platforms the response is simple, there is no other option than using TrueCrypt.

But is TrueCrypt safe to use?

A group know as OCAP ( Open Crypto Audit Project ) was crowdfounded to do an audit to TrueCrypt source code, on April 14th they released the Phase I Audit report that didn't found anything disastrous on it, they mentioned they had a big announcement coming, but then TrueCrypt project was halted.

So it seems its relatively safe to use TrueCrypt, for sure is way better than no encryption at all and is better than Microsoft's Bitlocker.

Another option if you are on Windows but don't want to use TrueCrypt anymore could be to run Linux inside a virtual machine and that way using dm-crypt LUKS.

But it really depends on how important is the info you are storing, if is your business documents, your porn stash or you live in a country other than US and the NSA wouldn't be asked to decrypt your disk even if they could, just continue using TrueCrypt until we have news about the fork, now called Ciphershed officially.


Friday, May 30, 2014

#ResetTheNet



The NSA has corrupted the Internet. On June 5, we will Reset the Net. We hope you’ll join us.

June 5 is the one-year anniversary of the first documents leaked by Edward Snowden. While EFF has
been fighting NSA surveillance for years, 2013 marked a new chapter in our battle against mass
spying. The documents made it clear to everyone why we care so much, and why they should too.

Surveillance affects everyone, in the United States and internationally. Millions of innocent people
have had their communications swept up by the NSA’s dragnet surveillance. Thomas Drake, former
NSA official and whistleblower described recently retired NSA chief General Keith Alexander’s
surveillance philosophy: “He is absolutely obsessed and completely driven to take it all, whenever
possible.” This philosophy clearly underpinned his nearly nine year tenure at the NSA. In addition to
this collect-it-all strategy, the NSA has used tactics such as deploying malware, trying to weaken 
encryption, and other sophisticated techniques that make the Internet less secure.

Mass surveillance is toxic for the Internet. The Internet is a powerful force that can promote
democracy, innovation, and creativity, but it’s being subverted as a tool for government spying.

That’s why EFF has joined with dozens of other organizations in calling for a day of action to Reset
the Net. On June 5th, Reset the Net is asking everyone to help by installing free software tools that
are designed to protect your privacy on a computer or a mobile device. Reset the Net is also calling
on websites and developers to add surveillance resistant features, like HTTPS and forward secrecy.

Don’t wait for your privacy and freedom. Start taking it back.

#resetthenet
https://www.resetthenet.org/

http://resetthenet.tumblr.com/



Thursday, May 29, 2014

TrueCrypt defacement a Warrant Canary?



Is the TrueCrypt "defacement" a Warrant Canary?
At the moment no one knows what is really going on, but this is very bad news...


Monday, May 5, 2014

Anonymous Browsing COMSEC Lesson



Hey guys

I just added a new lesson discussing what are the options you have to browse anonymously
on Internet and how good is the anonymity they provide.
Also in this lesson you'll learn what is Tor, how it works, how to install and use it.

As always just contact me if you have any question.

http://apx808.blogspot.com/p/anonymous-browsing.html

Sunday, March 2, 2014

Computer COMSEC Email and cryptography lesson



Hey guys

This week I discuss the basic working of email service, it's weak points, what email provider you
should use and a very popular tool called Enigmail that will ease your use of encrypted email.

Hope you find this useful, see ya.

Check the lesson HERE


Friday, February 21, 2014

Why do I need encryption? I have nothing to hide!



You're a normal guy, you have nothing to hide why should you use encryption?

Well, today you THINK you have nothing to hide.

Snowden leaked documents prove that the NSA can store your communications metadata/content for
15 years, 10 online and 5 offline.
Maybe today being a patriot or a gun owner isn't so bad, yes people think you're kind of crazy, but
whatever...

But let's suppose the next president cares about constitution and civil rights even less than the current
one and decides that your political beliefs, religion or sexual preference is a danger to society and
decides that people like you should be actively prosecuted, incarcerated or maybe summarily
executed?

You never know...
And besides that, NSA can't read and catalog your messages and they absolutely hate it!


Friday, November 15, 2013

Introduction to Bitcoin



Hey guys

Lately everyone talks about Bitcoins but not many really understand what a Bitcoin is, and I don't
mean the inner workings that are way too complicated dealing with mathematics and cryptography,
but their simple usage or understanding about the implications of such system.

At bitcointalk.org there is an excellent intro to what Bitcoin is that I wanted to share with you

Introduction to Bitcoin

Forget most things you've heard.  


People discover Bitcoin in a variety of ways, but usually pick up some sort of misconception like 
"Bitcoin gives free money to people with computers" or "in order to use Bitcoin I have to use a 
program that wastes electricity for nothing" along the way.  Here is a good summary to help you 
understand Bitcoin in general, by focusing on what Bitcoin is and what problem it solves.  
These two things are not typically well explained on most websites, and it is difficult to appreciate 
just how effective a technology Bitcoin is until they are understood.

What Bitcoin is:  


An agreement amongst a community of people to use 21 million secure  mathematical 
tokens--"bitcoins"--as money, like traditional African and Asian societies used the
money cowry.  

Unlike the money cowry:
  • there will never be more bitcoins
  • they are impossible to counterfeit
  • they can be divided into as small of pieces as you want
  • and they can be transferred instantly across great distances via a digital connection such as the internet.

This is accomplished by the use of powerful cryptography many times stronger than that used by 

banks.  Instead of simply being "sent" coins have to be cryptographically signed over from one entity 
to another, essentially putting a lock and key on each token so that bitcoins can be securely backed up 
in multiple places, and so that copying doesn't increase the amount you own.

Because bitcoins are given their value by the community, they don't need to be accepted by anyone

else or backed by any authority to succeed.  They are like a local currency except much, much more
effective and local to the whole world.  As an example of how effective the community is at "backing" 
the bitcoin: on April 4th 2011 30,000 bitcoins were abruptly sold on the largest Bitcoin exchange, 
consuming nearly all "buy" offers on the order book and dropping the price by nearly 1/3.  But within 
a couple of days, the price on the exchange had fully rebounded and bitcoins were again trading at 
good volumes, with large "buy" offers slowly replacing the ones consumed by the trades.  The ability 
of such a small economy (there were only 5 million out of the total 21 million bitcoins circulating 
then, or about 3.75 million USD worth at then-current exchange rates) to absorb such a large sell-off 
without crashing shows that bitcoins were already working beautifully.


What problem Bitcoin solves:  


Mathematically, the specific implementation of the bitcoin protocol solves the problem of "how to do 
all of the above without trusting anyone".  If that sounds amazing, it should!  Normally a local 
currency has to trust all kinds of people for it to be able to work.  So does a national currency.  And 
in both cases, that trust is often abused.  But with Bitcoin, there's no one person who can abuse the 
system.  Nobody can print more money, nobody can re-use the coins simply by making a copy, and 
nobody can use anyone else's coins without having direct access to their keys. 
 People who break its mathematical "rules" simply end up creating a whole different system 
incompatible with the first.  As long as these rules are followed by someone, the only way Bitcoin can 
fail is for everyone to stop using it.


This marvelous quality of not having to trust anyone is achieved in two ways.  First, through the use 

of cutting-edge cryptography.  Cryptography ensures that only the owner of the bitcoins has the 
 authority to spend them.  The cryptography used in Bitcoin is so strong that all the world's online 
banking would be compromised before Bitcoin would be, and it can even be upgraded if that were to 
start to happen.  It's like if each banknote in your pocket had a 100-digit combination lock on it that 
couldn't be removed without destroying the bill itself.  Bitcoin is that secure.

But the second way of securing the system, called the blockchain, is where the real magic happens. 

 The blockchain is a single, authoritative record of confirmed transactions which is stored on the 
peer to peer Bitcoin network.  Even with top-notch digital encryption, if there was no central registry 
to show that certain bitcoins had already been "paid" to someone else, you could sign over the same 
coins to multiple people in what's called a double-spend attack, like writing cheques for more money 
than you have in your account.  Normally this is prevented by a central authority, the bank, who 
keeps track of all the cheques you write and makes sure they don't exceed the amount of money you 
have.  Even so, most people won't accept a cheque from you unless they really trust you, and the bank 
has to spend a lot of money physically protecting those central records, whether they are kept in a 
physical or digital form.  Not to mention, sometimes a bank employee can abuse their position of 
trust.  And, in traditional banking, the bank itself doesn't have to follow the rules you do--it can lend 
out more money than it actually has.

The blockchain fixes all these problems by creating a single master registry of the already-

cryptographically-secured bitcoin transfers, verifying them and locking them down in a highly 
competitive market called mining.  In return for this critical role, the Bitcoin community rewards 
miners with a set amount of bitcoins per block, taken from the original limited quantity on a 
pre-agreed schedule.  As that original amount gradually runs out, this reward will be replaced by fees 
paid to prioritise one transaction over another--again in a highly competitive market to ensure the 
lowest possible cost.  The transactions are verified and locked in by the computational work of 
 mining in a very special way so that no one else can change the official record of transactions 
without doing more computational work than the cumulative work of all miners across the whole 
network.

In conclusion:  


All this mathematical technology may be a bit of a mouthful, but what it means in practice is that 
Bitcoin works just like cash.  Bitcoin transactions are intentionally irreversible--unlike credit cards 
or PayPal where chargebacks can invalidate a payment that has already been made.  And there are 
no middlemen.  Transactions are completed directly between the sender and the receiver via the peer 
to peer network.

Because of Bitcoin's intricate design, the network remains secure no matter where or how you 

process Bitcoin transactions.  Which is incredible--no one else has ever tried to create a system that 
worked this way!  All previous monetary systems have relied on trusting somebody, whether it was 
the king, town hall, the federal reserve, or banks.  Bitcoin doesn't.  It's guaranteed instead by the laws
of  mathematics, and that's why it has everyone from technologists to economists very excited.  I'm 
sure you have lots more questions, so scan the index below to see if they've been asked before, then 
dive in!  The so-called "canonical" threads linked from this index are considered newbie-friendly 
zones;  outside of them you're welcome to try your own luck.

And if you want to immerse yourself into the mysteries of Bitcoin and his creator 'Satoshi Nakamoto'
you can read this awesome research blog called Bitslog.

Also you can check the original paper at: http://bitcoin.org/bitcoin.pdf

For the tl;dr; kind of guys, you can watch the following video, but you'll get just a bare idea of what it is all about.


 
hit counter script