Let's say that you're using OTR to provide very strong end-to-end encryption for a conversation between yourself and a buddy, Bob. Maybe he's in a hostile area, and you're worried that if his government sniffs his traffic, that he could be executed for speaking to Americans.
Data in transit that is intercepted, if configured correctly, is almost certainly safe. No one will be able to immediately decrypt it because of the strong encryption.
So are you safe?
Probably not. The next step that government would take would be to raid your friend Bob's apartment, arrest him, and take his hard disk. His OTR key (and, if using Pidgin, account credentials in plaintext if stored) is plainly available on the disk. You now have the private key.
But what if he used Truecrypt or PGP full-disk encryption? His data would be safe from decryption then, right?
Sort of. If they're trying to break the actual encryption, they'd likely be unable to do so. Unfortunately, the weak point for Truecrypt disks or volumes isn't the crypto... it's the passphrase. The passphrase can be brute-forced significantly more easily than breaking the encryption itself. Furthermore, as xkcd so accurately pointed out, a hostile government will throw you in prison (or, worse, hit you repeatedly with a wrench) until you divulge your passphrase and data.
Encryption is great, and I encourage everyone to use reliably strong crypto. Will that keep your data safe from the criminals that stole your work laptop? Absolutely. Will it keep your data safe from the NSA? You're kidding yourself.
Remember that post a little while ago about how most logical fallacies aren't actually logical fallacies? Here, you are committing an actual logical fallacy. It's called "shifting the goalposts."
The article is in response to a dragnet surveillance program, where everyone's communications are watched and presumably datamined. It's very easy to do this, because nothing is encrypted, and everyone uses services that expose metadata (like who is IM'ing who).
Your comment is entirely true. However, it presents an adversary that doesn't want dragnet, but targeted surveillance. It assumes that Bob will be immediately arrested if his communications become encrypted.
This is not the threat model that we're faced with now. Let's say you and Bob communicate using accounts you've made on random XMPP servers using Tor, and all the messages are encrypted with OTR. Both servers are in the US, and the NSA's metadata database shows E83Gxw@jabber.org sending lots of ciphertext to PAnd9B@jabber.org.
This is "NSA-proof" in that the NSA would not know to link PAnd9B@jabber.org with you using their existing systems. They would have to drastically escalate the cost of their surveillance program with respect to you and Bob to figure out what you're talking about. Unless you really are a political dissident, conspiracy theorist who accidentally discovered the UN's black helicopter program, or radical Islamist, you are now out of the surveillance dragnet.
That is to say, unless the threat model changes, using privacy-enhancing technology will keep your data safe from PRISM and similar dragnet programs.
I absolutely agree with you, but I was addressing the potentially misleading title of the article, not the current dragnet observation (which is why I quoted the title of the article). Many people that may not be experienced in cryptography may think that these techniques would protect them from law enforcement, or that their encryption would actually be "NSA proof."
Your description of secure communication (Tor, anonymous XMPP, etc.) is totally accurate and a great explanation for those who may not be quite as familiar with security and OPSEC.
Unfortunately, with great enough amounts of metadata and computing power, this could theoretically be correlated as well. DNS requests or Tor connections correlated with encrypted messages timed between two individuals seems like it would be too hard to make meaningful, but it's not impossible. There's precedence for this when the FBI suspected Jeremy Hammond of being a certain identity on IRC, and correlated his sign-ons with connections to Tor.
You're absolutely, 100% correct, though, that this data (even correlated), must be part of some sort of targeted surveillance. I wasn't trying to counter the dragnet argument as much as provide clarity on what these security measures would or would not do.
Thanks for providing even more clarity in the areas I didn't address :)
You're quite welcome. I'm glad you liked the description. The title of the article is indeed misleading; a better one would be "PRISM-proof."
With a total record of the entire Internet (global passive adversary), you could definitely defeat anything using Tor, but I wonder if you could make it significantly harder still by randomly generating XMPP accounts every time. There's a potentially infinite space, and you can do XMPP registration in-band.
Of course, you could also just run XMPP servers locally as chat endpoints, and never have subpoena-able records. These could be Tor hidden services, which would give you the added bonus of global reachability. I think this eliminates most correlation attacks you could do; all you'd see on Alice and Bob's endpoints would be Tor circuits.
All this will make for a really interesting Wire reboot, if/when that happens.
Not to mention, if we (US citizens) are actually so concerned with how hopeless encryption would be to protect us from government gestapo, versus reasonable encryption to protect data-in-transit, we're truly and hopelessly fucked. It's a disturbingly good, and ironic, argument to stand up against the illegality and unconstitutionality of the NSA's program.
> This is not the threat model that we're faced with now. Let's say you and Bob communicate using accounts you've made on random XMPP servers using Tor, and all the messages are encrypted with OTR. Both servers are in the US, and the NSA's metadata database shows E83Gxw@jabber.org sending lots of ciphertext to PAnd9B@jabber.org.
Tor won't help at all if all of the long-distance network traffic in the country is being mirrored (as it has been in the USA for most of a decade).
Corollary: The NSA knows exactly who runs The Silk Road. Stopping drug trafficking is obviously not as high a priority to them as not letting potentially kinetic adversaries know that Tor provides no anonymity to someone who can (and does) monitor _all_ network traffic.
Tor messages are disclosed only if the NSA etc. run enough of the entry/exit nodes. Simply passively recording Tor traffic might let you do traffic analysis, but won't let you deduce the contents of that traffic.
They'd have the whole of the tor network, including entry and exit nodes. Why run your own exit nodes when you can just sniff the traffic of the existing ones?
That's the old mentality: "NSA/CIA/FBI/UGA will actively spy on me."
The way I see it, that's not the greatest danger right now. Instead, we should be worried about the government being able to passively spy on everyone at the same time, by indiscriminately siphoning and analyzing data.
However, according to https://en.wikipedia.org/wiki/Perfect_forward_secrecy OTR does provide "perfect forward secrecy as well as deniable encryption". Doesn't that provide some protection against rubber-hose cryptanalysis?
No. As I understand it, the "deniable" in "deniable encryption" is that after the first handshake, there's no cryptographic proof that the messages sent originated from you. This is flimsy legal evidence, because there are more messages that originated from your Pidgin instance that are actually yours compared to those that are somehow fake, and nonexistent evidence when presented to someone who's already torturing you.
Perfect Forward Secrecy means that even if you want to you cannot decrypt old messages, since the keys used are ephemeral and destroyed at the end of the session.
> Perfect Forward Secrecy means that even if you want to you cannot decrypt old messages
Which means, if they're jailing you until you do decrypt the messages, you get jailed indefinitely. Contempt of court has very few limits in some circumstances, even compared to being imprisoned after being convicted of a crime:
> Which means, if they're jailing you until you do decrypt the messages, you get jailed indefinitely.
Maybe, but they wouldn't be waiting for you to do something for them. They would understand that there was nothing you could do to help them decrypt the messages. i.e. your encryption worked.
However, unless there is a legal requirement that you maintain the records in question, a documented habit of destroying them is almost certainly enough to get out of contempt of court for not producing them, absent some specific reason to believe you kept those special.
One thing widespread encryption would do is make it impossible for the NSA to just slurp the combined textual output of humanity into hadoop and mapreduce over it.
They can use "hitting the suspect with a wrench" cryptanalysis on a solo victim, but not on a crowd.
Except that they still have traffic data, which was the main thing they were collecting in the first place. Encryption only hides the contents of your communications - it doesn't hide who you were communicating with and when.
If we accept all claims to be true, that the NSA does have a PRISM program, and is able to get data from Google, Microsoft, Yahoo, Facebook, etc., and we also accept the claims from those companies that they have provided no 'direct access' to their systems, then perhaps SSL is broken?
There's no need to throw him in jail. They can just install a hidden camera and record him typing the password. Next time he's out shopping the "maid" will drop by and the copy the hard drive.
> The passphrase can be brute-forced significantly more easily than breaking the encryption itself. Furthermore, as xkcd so accurately pointed out, a hostile government will throw you in prison (or, worse, hit you repeatedly with a wrench) until you divulge your passphrase and data.
Not to detract from the point of your post, but for anyone interested, that's what TrueCrypt's 'plausible deniability' feature [1] is for. It can be used to create a hidden volume on your hard drive with a different password from your main volume, so if you're ever forced to give up the disk passphrase by a government agency or anyone else, you can give them the password to the hidden volume, and (in theory) you'll appear to be fully cooperating. It is impossible (short of cracking the main volume passphrase through brute force) to prove, given only the passphrase to the hidden volume, that the main volume exists. Ideally, you'd probably want to put something "embarrassing" but legal on the hidden volume (e.g., gay porn), to make the "plausible deniability" for using full disk encryption more "plausible".
> Probably not. The next step that government would take would be to raid your friend Bob's apartment, arrest him, and take his hard disk. His OTR key (and, if using Pidgin, account credentials in plaintext if stored) is plainly available on the disk. You now have the private key.
The DEFINING FEATURE of OTR is that of forward secrecy; key compromise does not permit retroactive decryption.
Otherwise, we could just use TLS. (Technically, we could now, just enforcing the EDH modes.)
Weren't there cases of the government forcing people to give them their passphrase in the US already? Somehow I seem to remember something like this very vaguely.
You're probably thinking about the child pornography case that's going on right now where the accused was ordered by the courts to provide his passphrase. Higher level courts say you cannot compel that sort of evidence.
> The passphrase can be brute-forced significantly more easily than breaking the encryption itself.
Doesn't brute forcing this depend on the strength of the passphrase? For large enough N, if neither can be done in the next N years, does it really matter if it's significantly easier? Isn't there a non-negligible likelihood that in the next N years we'll figure out ways to break stronger forms of encryption but we won't figure out how to brute force strong passphrases efficiently?
Doesn't truecrypt use PBKDF2 or similar? In which case (assuming a good password) it would still be uncrackable in any practical sense.
Besides , in such an example the government would have to be suspecting bob already on some other grounds. In the case of a despotic regime they probably already have him in prison.
It does use PBKDF2, and the input to that is not just a passphrase but also one or more keyfiles, a salt, and some other metadata. My understanding is that the keyfiles should supply most of the randomness.
These edge cases are stupid. If 99% of Americans are safe, that's good enough. Dudes that actually break the law are not our problem, government should get them. The problem is all the other people who are doing nothing wrong other than have opinions or beliefs that the government does not like. Or in the case now are simply sending e-mails. If we can make it harder to get their shit that's enough.
This whole idea that no we can't do it, is defeatist. We can and we should do it, and then we should do more. As much as we can to make it as hard as possible. And if the government still wants to do shit, then let them. That's their prerogative.
Yup. Except it's not that easy.
Let's say that you're using OTR to provide very strong end-to-end encryption for a conversation between yourself and a buddy, Bob. Maybe he's in a hostile area, and you're worried that if his government sniffs his traffic, that he could be executed for speaking to Americans.
Data in transit that is intercepted, if configured correctly, is almost certainly safe. No one will be able to immediately decrypt it because of the strong encryption.
So are you safe?
Probably not. The next step that government would take would be to raid your friend Bob's apartment, arrest him, and take his hard disk. His OTR key (and, if using Pidgin, account credentials in plaintext if stored) is plainly available on the disk. You now have the private key.
But what if he used Truecrypt or PGP full-disk encryption? His data would be safe from decryption then, right?
Sort of. If they're trying to break the actual encryption, they'd likely be unable to do so. Unfortunately, the weak point for Truecrypt disks or volumes isn't the crypto... it's the passphrase. The passphrase can be brute-forced significantly more easily than breaking the encryption itself. Furthermore, as xkcd so accurately pointed out, a hostile government will throw you in prison (or, worse, hit you repeatedly with a wrench) until you divulge your passphrase and data.
Encryption is great, and I encourage everyone to use reliably strong crypto. Will that keep your data safe from the criminals that stole your work laptop? Absolutely. Will it keep your data safe from the NSA? You're kidding yourself.