Showing posts with label COMSEC. Show all posts
Showing posts with label COMSEC. Show all posts
Wednesday, April 29, 2015
Saturday, August 23, 2014
INTDB for Linux and Mac OS X
Many of you were asking for a version of INTDB to run in Linux or Mac OS and finally after many days of hard work I could find a way to do it.
Sadly this version won't be portable, but the installation process is short and simple and I wrote an step by step tutorial so you shouldn't have any problem.
This new INTDB version will work using XAMPP that is a multi-platform easy to install and use Apache web server with MySQL, Perl and PHP, although we only will use Apache and Perl to run the INTDB TWiki.
So now there will be two distros of INTDB, those are "INTDB Portable for Windows" and "INTDB4Xampp" for Linux and Mac OS X, both distros will keep the same version number for simplicity.
Besides releasing INTDB4Xampp I'm also releasing today the version 1.2 of INTDB, this new version includes:
- Basic usage & tips guide.
- Google Earth integration example.
- The following cheatsheets:
- Structural Labeling
- Movement speeds
- SALUTE report
- METT-TC
- Glossary
The Google earth integration example will show you a great tip as you can open .kmz files from your pages an see them on Google Earth and when you close it no traces are left of your work in it.
Also 5 new pages are included with cheat sheets that will help you with your intelligence tasks.
As usual you can contact me if you need any help or would like to share templates or ideas.
Friday, July 11, 2014
Should you continue using TrueCrypt?
It was the last days of May when TrueCrypt website suddenly was took down and replaced with a page suggesting a migration to Microsoft Bitlocker.
No one really knows what happened, I personally believe that the NSA asked the devs to do something they didn't want to, so they decided to completely stop the project, similar to what happened to Lavabit some time ago.
You can find a lot of theories and even declarations of some guys claiming to be the developers, I don't trust much in those claims, as the TrueCrypt developers were anonymous and even if they were the real devs, probably are legally obliged to deny everything and say nothing strange happened.
But the real question is, should I continue using the latest version of TrueCrypt? Is there any other software that I could use to replace it?
If you run Linux is highly recommended you migrate your encrypted volumes to dm-crypt LUKS. Linux Mint 17 Qiana installation wizard includes an option to encrypt your system partition using it, so if you don't know much about Linux, that's an easy way to start.
If you need support in multiple platforms the response is simple, there is no other option than using TrueCrypt.
But is TrueCrypt safe to use?
A group know as OCAP ( Open Crypto Audit Project ) was crowdfounded to do an audit to TrueCrypt source code, on April 14th they released the Phase I Audit report that didn't found anything disastrous on it, they mentioned they had a big announcement coming, but then TrueCrypt project was halted.So it seems its relatively safe to use TrueCrypt, for sure is way better than no encryption at all and is better than Microsoft's Bitlocker.
Another option if you are on Windows but don't want to use TrueCrypt anymore could be to run Linux inside a virtual machine and that way using dm-crypt LUKS.
But it really depends on how important is the info you are storing, if is your business documents, your porn stash or you live in a country other than US and the NSA wouldn't be asked to decrypt your disk even if they could, just continue using TrueCrypt until we have news about the fork, now called Ciphershed officially.
Tuesday, June 24, 2014
INT DB TWiki Update
INT DB has it's first update, here is the changelog:
- Fixes configure script error.
- Includes ExitPlugin to take care of the referrer problem.
- Cleans up previous session log files on start up.
- Includes security notes in regards to document attachment.
- Includes POI, Enumeration and alphabetically sorted list templates.
The screenshot in this post is from the Person Of Interest Template, when you create a new page you'll be asked what template to use, there you can select it or also one of the other two included templates, one is a table to enumerate stuff, like your Intelligence requirements, and the other is an alphabetically sorted table to store links to your POI dossiers for instance.
I'm working on a file so you can install easily the INT DB in an already running TWiki installation, so you can use it in other OSs just installing Apache by yourself, soon there will be news about it.
FULL DOCUMENTATION AND DOWNLOAD LINK HERE
Monday, June 2, 2014
INT DB Portable TWiki
While doing the IPB course at culperinstitute.org I discovered that the amount of information you have to handle to be able to satisfy your intelligence requirements is huge and will require to be updated often.
I didn't find an already existing tool, and that's why I thought that a wiki page could help, because it's easy to update, can include media files and also keeps track of the changes you made, bad thing about a wiki is that it needs a webserver to run, and not tech-savvy guys will find really hard to set up one. INT DB solves that problem because with just one click you'll have a running wiki that leaves no trace of use in your computer.
INT DB is based on TWiki for Windows Personal but it includes the latest version of TWiki 6.0 with WYSIWYG editor, Tinyweb webserver, Perl and GNU Grep, all of it ready to use, no installation is required and it won't create entries in your registry.
You'll see that the INT DB home page is a plain wiki page for you to start working on, if you can create templates, cheat sheets or whatever may be helpful for our purposes, please contact me and I'll include it in a new version.
FULL DOCUMENTATION AND DOWNLOAD LINK HERE
Monday, May 5, 2014
Anonymous Browsing COMSEC Lesson
Hey guys
I just added a new lesson discussing what are the options you have to browse anonymously
on Internet and how good is the anonymity they provide.
Also in this lesson you'll learn what is Tor, how it works, how to install and use it.
As always just contact me if you have any question.
http://apx808.blogspot.com/p/anonymous-browsing.html
Sunday, April 20, 2014
Bundy's ranch information flow thoughts
This reflects my personal opinion as someone outside Bundy's ranch wanting to know
what was going on and just receiving reports like "This is a mess, no one knows shit,
the feds didn't shot yet".
I believe Bundy's Ranch event demonstrated a big flaw in Militia's SOP and is that they failed to create an official information source until a week after it started.
An official reporting channel is key absolutely, specially when the opponent is the gov. Venezuela is a clear example, the gov and media report nothing is going on, but people using social media like Twitter report the abuse and violence they are suffering.
If shots were fired and the militia guys in there were reduced to turtle food, the gov could start talking about how the domestic terrorist attacked and they had no other option but to repel the attack, and manipulate how the history is presented to the public.
Every unconventional force first has to obtain populace support to win, otherwise they will fail like Guevara in Congo and Bolivia. Part of getting populace support comes from showing them the flip side of the coin of what mass media feeds them.
A lot of people love to bash Occupy movement, but even if you don't fully agree with Occupy movement methodologies or ideology, there is always something to learn, specially for a country like the US, where you like it or not you don't have much experience manifesting against the government.
Occupy movement guys as soon as they took a place set up free Wi-Fi networks for people to be able to communicate and report anything that was happening, that is awesome, because the first thing the gov does is to shut down cell phone networks.
Also in Spain they created something called the "wifineta" that is a conjunction of the words Wi-Fi and truck in Spanish, that truck has the equipment to provide Wi-Fi and 3G for the people around it.
Also we need to keep in mind the COMSEC, if there is a centralized information outlet, it could define what should be public knowledge and what not, and then instruct the protestors about the information release guidelines.
Check this videos of the Occupy Wi-Fi providing tents.
I believe Bundy's Ranch event demonstrated a big flaw in Militia's SOP and is that they failed to create an official information source until a week after it started.
An official reporting channel is key absolutely, specially when the opponent is the gov. Venezuela is a clear example, the gov and media report nothing is going on, but people using social media like Twitter report the abuse and violence they are suffering.
If shots were fired and the militia guys in there were reduced to turtle food, the gov could start talking about how the domestic terrorist attacked and they had no other option but to repel the attack, and manipulate how the history is presented to the public.
Every unconventional force first has to obtain populace support to win, otherwise they will fail like Guevara in Congo and Bolivia. Part of getting populace support comes from showing them the flip side of the coin of what mass media feeds them.
A lot of people love to bash Occupy movement, but even if you don't fully agree with Occupy movement methodologies or ideology, there is always something to learn, specially for a country like the US, where you like it or not you don't have much experience manifesting against the government.
Occupy movement guys as soon as they took a place set up free Wi-Fi networks for people to be able to communicate and report anything that was happening, that is awesome, because the first thing the gov does is to shut down cell phone networks.
Also in Spain they created something called the "wifineta" that is a conjunction of the words Wi-Fi and truck in Spanish, that truck has the equipment to provide Wi-Fi and 3G for the people around it.
Also we need to keep in mind the COMSEC, if there is a centralized information outlet, it could define what should be public knowledge and what not, and then instruct the protestors about the information release guidelines.
Check this videos of the Occupy Wi-Fi providing tents.
Friday, March 7, 2014
Metadata COMSEC lesson
How can you extract it from other people's files? What can you do to eliminate it?
All those questions and more answered in this week COMSEC for preppers lesson, check it out
HERE.
Sunday, March 2, 2014
Computer COMSEC Email and cryptography lesson
This week I discuss the basic working of email service, it's weak points, what email provider you
should use and a very popular tool called Enigmail that will ease your use of encrypted email.
Hope you find this useful, see ya.
Check the lesson HERE
Friday, February 21, 2014
Why do I need encryption? I have nothing to hide!
You're a normal guy, you have nothing to hide why should you use encryption?
Well, today you THINK you have nothing to hide.
Snowden leaked documents prove that the NSA can store your communications metadata/content for
15 years, 10 online and 5 offline.
Maybe today being a patriot or a gun owner isn't so bad, yes people think you're kind of crazy, but
whatever...
But let's suppose the next president cares about constitution and civil rights even less than the current
one and decides that your political beliefs, religion or sexual preference is a danger to society and
decides that people like you should be actively prosecuted, incarcerated or maybe summarily
executed?
You never know...
And besides that, NSA can't read and catalog your messages and they absolutely hate it!
Computer COMSEC PGP/GPG Lesson
Hey guys
New lesson posted, this time about PGP/GPG.
What it is, why should you use it and the first practice where you'll need to install it and create your
key pair to start practicing and communicating securely.
Check it out HERE
Friday, February 14, 2014
Computer COMSEC Crypto lesson
Hey guys
I just posted today the first lesson of the course dealing with cryptography basics.
This week practice isn't very interactive, you'll need to watch a few videos, but the knowdlege you
will acquire will help you for the next lesson when we will start working with GPG.
Follow this link to start the lesson
http://apx808.blogspot.com/p/cryptography.html
Tuesday, February 11, 2014
Computer COMSEC for preppers
Previously I had mentioned there was a big project coming for this year, and here it is, is a course called
Computer COMSEC for preppers. The goal is to provide you with the tools and knowledge to
communicate securely using digital channels.
The course name is "Computer COMSEC" because COMSEC also involves operational aspects that
I would rather leave to more knowledgeable people like Sam Culper at Guerrilla America.
There is plenty of tutorials covering the tools we are going to use but the content of this course will
be targeted to preppers, III%'ers and Liberty Fighters so the lessons will be focused on our particular
needs.
Lessons will be in layman terms and explained simply so everyone can participate. More advanced
lessons will rely on previous lesson concepts.
Every Friday I will upload a lesson, article or tip that will include a practice segment which you can
use over the weekend.
These practice segments will be short so they won't eat up all of your weekend but will aide you in
retaining the needed knowledge.
In case you have a problem with the practice segment, you don't understand something, you have
doubts, or there is a topic you would like to see discussed, we have the "Questions & Answers"
board at Unchained Preppers or you can contact me. I encourage you to actively participate and ask
the questions you might have, don't forget your questions will give me ideas for new and future
lessons.
The course is absolutely FREE and you won't need to spend a single dollar. The only things you will
need is your computer, a 2GB or bigger pen-drive and some time.
This Friday February 14th the first lesson will be available, the intro is already available HERE.
Subscribe to:
Posts (Atom)







