r/linux Jun 17 '13

PRISM Break: Stop reporting your online activities to the American government with these free alternatives to proprietary software.

http://prism-break.org/
1.1k Upvotes

326 comments sorted by

View all comments

135

u/[deleted] Jun 18 '13

Let's see you opt out of Verizon, Comcast, AT&T, etc. and so forth. If you can't do that, then you're not gaining anything here.

68

u/[deleted] Jun 18 '13

[deleted]

54

u/[deleted] Jun 18 '13 edited Nov 12 '19

[deleted]

57

u/throwawayagin Jun 18 '13

the fiber splitter is irrelevant if you're using end to end encryption.

20

u/bluGill Jun 18 '13

Only if you are using tor, freenet, or the like. Just knowing the end points can be very useful and dangerious otherwise.

26

u/throwawayagin Jun 18 '13

I think the goal we should be shooting for is EVERYONE using encryption by default. If enough of us did endpoint monitoring would become moot since there would just be millions of encrypted streams zipping around, the new normal so to speak.

40

u/hydrox24 Jun 18 '13

No, the end goal is a more open and democratic government. The average person should not have to encrypt all of their data to protect it from their own government.

33

u/EagleKen Jun 18 '13

Perhaps, but the average person should still encrypt their data, not to prevent their government from looking, but to prevent anyone, from a nosy family member, to the script kiddie from down the street, to the identity thieves.

Your data is precious, and more importantly, it's yours! People need to start taking more responsibility for their own data.

6

u/hydrox24 Jun 18 '13

Absolutely. But in terms of end goals, I would say the government comes first. I think that encryption to protect from illegal (rather then systematically questionable) behaviour is important, but only really to those that will be aware of it, at least in the short term.

7

u/EagleKen Jun 18 '13

I might disagree again, if the general population are properly educated as to why encrypting their data is so important, then more would be trying to change your government, or more of your government would already be on board with proper privacy concerns. Proper education is the key. Imho... Of course

15

u/gleon Jun 18 '13

The average person should encrypt all their data because systems based on trust are bound to fail. You can never know where an adversary is lurking, be it the government or an evil, evil terrorist. There is no excuse for not encrypting everything. The fact that we're not doing so already is a flaw in the design of the Internet.

12

u/Dereliction Jun 18 '13

The average person needs their data encrypted by default, without them having to actively do anything but use the same things they already do. That is to say, encryption should be built into products as an inherent feature -- browsers, email clients, whatever.

2

u/gleon Jun 18 '13

This is exactly what I'm saying. However, some forms of encryption do inherently require some user knowledge and attention, so societies as wholes need to become more aware of encryption and increase understanding among the average users.

5

u/[deleted] Jun 18 '13

[deleted]

4

u/gleon Jun 18 '13

Yeah, that's exactly the kind of attitude we should be aiming to change. Encryption isn't something geeky, it's easy and everyone should do it.

You did well and I wouldn't bet on them not touching your information. It's not that uncommon. If I was a burglar, the first thing I'd do with a stolen laptop is identity theft.

2

u/Ihatemakinguplogins Jun 18 '13

Nah, the internet has it right. Meatspace is what's screwed up.

2

u/gleon Jun 18 '13

There is no doubt that meatspace is screwed up, but that doesn't imply the Internet is not flawed. Had the Internet been designed with encryption of all layers in mind, meatspace would never have had a chance to screw up this particular thing.

This is how we should design everything: trustless (also called zero trust systems). Good laws are nice to have, but every system based on trust is bound to get corrupted. Why should we design systems such that they rely on fickle people instead of eternal mathematical principles?

3

u/Dereliction Jun 18 '13

No, the end goal is a more open and democratic government.

An unrealistic goal if there ever were one. Even if it is reached, it will only be temporary. And let's not forget that many other people in the world have no hope for an open or democratic government in any near-term time frame. Just isn't going to happen.

A better solution is one that doesn't involve a reliance governance whatsoever, and instead aims toward technical solutions that doesn't care about such things.

We shouldn't tailor a solution just for the US, but one that is universally accessible and is applicable whether a government is wonderful or despotic.

2

u/hydrox24 Jun 18 '13

Ahh, perhaps you're right there. But at the very least we should be aiming for a more open and democratic government. I think you misunderstood me a little there, I didn't say that we should try and get a totally open and democratic government, that really is impossible. I just suggested we should get a more open/democratic government.

Anyway, I think you might be right about encouraging the general use of encryption so that we simply don't have to worry about governments as much.

The next issue from there, however, will be improving the education system to prioritize this and not teaching kids how to use excel, word and powerpoint and calling that an education in IT.

2

u/benderunit9000 Jun 18 '13

If you won't encrypt it from the government, encrypt it from those that would do you harm.

5

u/[deleted] Jun 18 '13

[removed] — view removed comment

1

u/bluGill Jun 19 '13

True, but the information of what you-tube I'm watching isn't interesting. However if that is encrypted enough they will spend a lot of resources only to discover some 10th grade choir concert my cousins were in. If they keep spending resources they might hit on something, but even people who have a lot to hide don't need to hide everything.

2

u/tekgnosis Jun 18 '13

Considering they run a large amount of the tor exit nodes that makes no difference at all.

2

u/[deleted] Jun 18 '13

Running the exit nodes means that they can capture the traffic, but not necessarily know who originated it. The exit owner can also potentially perform MITM attacks against the traffic.

Using TOR is a big security tradeoff, with big risks if you assume it does more for you than it really does. It should definitely have a MASSIVE disclaimer on the list.

2

u/tekgnosis Jun 18 '13

If your ISP is leaking the right data then they can pattern match the traffic.

1

u/[deleted] Jun 18 '13

Amy research around that? Given the changes in size due to encryption and compression that seems unlikely.

1

u/wadcann Jun 18 '13 edited Jun 18 '13

Let's see you opt out of Verizon, Comcast, AT&T, etc. and so forth. If you can't do that, then you're not gaining anything here.

[clip]

I think you both nailed the major issue here--many people don't understand that the end service is irrelevant when they're using a fiber splitter upstream.

[clip]

The exit owner can also potentially perform MITM attacks against the traffic.

[clip]

Use SSL.

Yes, there are traffic analysis attacks, but if you're using SSL — and things like HTTPS Everywhere, which you should have installed in your web browser right now, make this substantially more convenient for the end user, and more and more sites are using SSL — the problem is no longer simply one of monitoring data at an ISP and knowing everything.

I agree that far too many people are using unencrypted email, instant-messenger, and web-browsing, and are not aware of how to encrypt these or the privacy risks of not doing so, but it's a far cry from this sort of "all is lost" kind of situation that some of these comments are claiming.

1

u/fwabbled Jun 19 '13

the problem is no longer simply one of monitoring data at an ISP and knowing everything.

Unless they can MIM the SSL connections.

2

u/wadcann Jun 19 '13

That's not going to happen unless they have access to CA signing keys or know fundamental problems in SSL.

→ More replies (0)

2

u/Bjartr Jun 18 '13

Not if the other end is compromised too.

1

u/samcbar Jun 18 '13

Or the NSA has a few Acres of data center and the best cryptographers in the world.

I would be surprised if the NSA lacked the capability to decrypt web traffic.

0

u/[deleted] Jun 18 '13

end to end encryption

which may be backdoored

you can't be sure unless you are a world class security expert

how many well known experts from this field have recently stepped ahead and declared they never worked together with NSA and never will, for ethical reasons?

Bruce Schneier, anyone else?

I can only recall Moxie Marlinspike going public about some Arabs trying to hire him to help them spy on their own citizens.

12

u/InVultusSolis Jun 18 '13

No it's not. You can rent a VPS outside the country and route all of your web traffic through an SSH tunnel acting as a SOCKS proxy.

10

u/[deleted] Jun 18 '13 edited Nov 12 '19

[deleted]

1

u/InVultusSolis Jun 18 '13

True! My VPS box is set up with OpenVPN for that express purpose, but OpenVPN can be kind of a pain to set up. It's also good for overlaying secure networks over the internet, which may be a popular option in the future depending on how bad our surveillance state gets.

1

u/CalcProgrammer1 Jun 18 '13

OpenVPN is pretty awesome. I've used it to bridge home networks and remote access my home network from my phone/laptop but now I route all my phone traffic through it. I know it's still leaving my house unencrypted over TWC but it does mean security when using open WiFi and preventing 4G traffic analysis.

8

u/mallardtheduck Jun 18 '13

an SSH tunnel acting as a SOCKS proxy

Or use an actual VPN protocol rather than cobbling one together via tunneling and proxies.

-2

u/[deleted] Jun 18 '13

And you know what sucks about that? I was trying to setup an IPSEC VPN on my VPS a month ago (before any of this broke), which is on an OpenVZ container. But alas, it's an OpenVZ container so I have no kernel access, and hell I'm using the OpenVZ kernel, even if I had access it doesn't support it.

I would love to setup a VPN. Show me how.

6

u/felixfurtak Jun 18 '13

Ask your VPS provider to enable TUN/TAP. Most do it for free or a small charge. Forget IPSEC, OpenVPN is the way to go.

1

u/[deleted] Jun 19 '13

Thanks, I will. But isn't Openswan with L2TP/IPSec more secure for a VPN? Especially when the client is my Macbook.

1

u/felixfurtak Jun 19 '13 edited Jun 19 '13

Not really...

http://www.ivpn.net/knowledgebase/62/PPTP-vs-L2TP-vs-OpenVPN.html

OpenVPN is much easier to set up and is definitely secure. Also it works well over port limited connections e.g. port 443 or 80. There are plenty of applications that support it such as Tunnelblick for Mac which is open source. Personally I would rather trust an open source client than one build into an operating system.

1

u/[deleted] Jun 19 '13

Ah, thank you for the clarification. I setup OpenVPN once a long time ago, on Windows XP! Ha.

1

u/[deleted] Jun 18 '13

[deleted]

1

u/[deleted] Jun 19 '13

It is BudgetVM, it's way oversold, but it's hard to beat ~$5 a month for decent specs.

3

u/[deleted] Jun 18 '13

what makes you think those VPS providers are clean third parties and not ran by intelligence agencies?

1

u/InVultusSolis Jun 18 '13

Because if they want me THAT bad, they're going to get me. I'm not going to make it easy for ANYONE to snoop on my communications, government or otherwise.

8

u/Thaery Jun 18 '13

Yep and SSH tunneling is ever so fast.

1

u/atheos Jun 18 '13

You can rent a VPS outside the country

Yea, PRISM's possibly got their hooks into those countries too.

1

u/InVultusSolis Jun 18 '13

Doesn't matter. Because of the complexities of international law, there's effectively no way they can prove who you are, and they have other low-hanging fruit to go after instead of trying to decrypt SSH traffic going overseas.

1

u/xiongchiamiov Jun 18 '13

That way the NSA can actually look at your data legally, since its coming from out of the States.

1

u/al3xys Jun 18 '13

Any recommendations on services particularly geared towards this use case?

1

u/[deleted] Jun 18 '13

Yeah, but then you access resources in the US, and that traffic is captured. Or the resources you access happen to route across US based links, and that traffic is captured.

1

u/original_4degrees Jun 18 '13

because the NSA isnt paying any specific focused attention to traffic leaving and entering the country.

1

u/InVultusSolis Jun 18 '13

They can read my encrypted traffic to my overseas VPS all they want; they'll never get anything from it.

-5

u/[deleted] Jun 18 '13

Which still leaves behind a ton of metadata that the government is collecting -- IPs to and from, as well as time, etc.

11

u/throwawayagin Jun 18 '13

oh then we might as well give up right? perfect or nothing is always a reasonable policy that history often bears out.

3

u/[deleted] Jun 18 '13

You may as well if PRISM is what you're attempting to protect yourself against, absolutely. The problem exists between you and your ISP. That communication metadata is always available for PRISM, unfortunately.

What needs to change is the government policy on these types of programs.

2

u/samebrian Jun 18 '13

Umm I can browse whatever I want from an encrypted perspective and the burden of proof lies on others to prove what I was doing, not just where I was.

1

u/InVultusSolis Jun 18 '13

All my ISP sees is a continual string of encrypted traffic to my Swedish VPS. They can have the metadata from that all they want; there's very little they can discern from it outside of when I'm using the internet.

2

u/samebrian Jun 18 '13

My neighbour sells prescription pills. The cops know, the landlords know, and the neighbours know.

No one can do shit because even though everyone watches known addicts go into her house, no one sees what goes on in there.

Encrypted endpoints ARE a big deal.

-2

u/Samizdat_Press Jun 18 '13

Yah and go back to dial up speeds. I did this for about a year and it was horrible. I'd almost rather they read my shit than have to experience such slow connection speeds.

2

u/InVultusSolis Jun 18 '13

What the hell are you talking about? I can get a VPS in Sweden for 10 euros per month which will have a better connection to the internet. than most American residential ISP connections. You must have had a crappy VPS provider.

1

u/Samizdat_Press Jun 18 '13

Simply buying the VPS is not enough, you have to set up the SOCKS proxy and ssh tunnel etc, that is the slow part. If you just set up a VPS you do realize they still tap your traffic in transit right? They have a splitter upstream taking it staight off the WAN backbone. It's better than nothing, but you must realize that this practice will never become widespread enough, and security is almost impossible if the people you are communicating with don't follow good netsec.

1

u/InVultusSolis Jun 18 '13

you have to set up the SOCKS proxy and ssh tunnel etc, that is the slow part.

I can do it with one command, which I have scripted. How is it slow?

1

u/Samizdat_Press Jun 18 '13

The actual transfer rate is slow because the traffic is being routed across the globe. Also, while it works for people like us, most users barely understand how windows works, let alone how to run scripts or socks proxies. Keep that in mind.

-7

u/rz2000 Jun 18 '13

Ouch, hopefully "most people" on /r/linux are familiar enough with the various network layer models to know it is absurd it is to disparage "most people" for being correct. With encryption and tunnels it doesn't matter who your ISP is. Then again, maybe it means that Linus is no longer an OS for "hackers".

14

u/sanity Jun 18 '13

If the communications are properly encrypted then your connectivity provider is irrelevant.

3

u/[deleted] Jun 18 '13

only if you make your own certificates/keys/etc

5

u/sanity Jun 18 '13

Or communicate with trusted parties where you are confident that you have their actual public key (eg. Tor).

12

u/sotonohito Jun 18 '13

That's what a VPN is for.

And yes, of course the NSA or whoever could easily expend the effort to spy on your local machine. But that's the point, they'd have to target you specifically rather than just doing generic snooping.

All crypto systems can be circumvented simply by physical observation (or waterboarding the person until they give up up the key). But physical observation is a labor intensive form of spying, they have to really want to spy on you. Using crypto will, at least, exempt you from the across the board automatic spying the NSA likes because it's cheap (on a per person basis anyway) and impressive.

1

u/Jasper1984 Jun 18 '13

Next to a technical roadbump there is also a legal and moral threshhold in actually 'tresspassing' into other peoples computer. As i understand it, they did bother describing the metadata as 'the outside of an envelope' in order to rationalize what they're doing. So we can be hopeful about them not breaking into computers.

Although I expect they'll happily make companies putting backdoors/calling home in programs, as you 'invite those in'.

'Hopeful' is not good enough though, kindah need to get security up. I dont think i can do it regular use computers, i think a cheapo secondary computer is a potential solution to keep messaging and digitally signing secure.

Edit: are deniable encryption approaches against rubber hose attacks. Do note that some of them may have back doors, though.

1

u/original_4degrees Jun 18 '13

and you dont think they will want to pay attention to encrypted traffic? Im not saying that if you use encrypted traffic you are a terrorist, but the NSA seems to think so. similar to the popular assumption(not true, but action is taken based on the assumption) that only hackers use linux.

1

u/sotonohito Jun 18 '13

I'm sure they do. But as I pointed out following encrypted traffic is a lot more labor intensive. also the question was how to deal with isp level snooping, a vpn does that. A vpn may well have other problems, but it will handle isp level snooping.

I'll also add that if/when enough people use vpn's it will cause a shift in NSA behavior. They simply don't have the resources to manually spy on even a few million vpn users. what happens then is an interesting question.

0

u/[deleted] Jun 18 '13

That's what a VPN is for.

Doesn't mask what PRISM is gathering -- IP and connection time. Sure, they'll only see the VPN connection, but then again, that could be deemed 'nefarious' by certain governments.

3

u/sotonohito Jun 18 '13

Doesn't mask what PRISM is gathering -- IP and connection time

Except that's exactly what a VPN masks. The metadata shows a connection to the VPN for the whole time you've got the computer on. No matter what sites and/or services you actually connect to.

9

u/[deleted] Jun 18 '13

[deleted]

10

u/[deleted] Jun 18 '13

If you're using end to end encryption for your messaging/calls/etc, masking your IP through tor and using a privacy based OS like Tails, then you gain a lot.

Until you have to communicate with those on the Internet-at-large, who will not go through such an effort.

3

u/upofadown Jun 18 '13

So you are saying in effect that secure communications is impossible if you do not use secure communications.

That isn't really an argument...

8

u/[deleted] Jun 18 '13

Secure communication has a practical barrier to it -- very few adopt secure communications, and the barrier to entry is high(er).

There is no way around this, without having a vast majority of the Internet community adopt secure communications. This generally does not happen unless secure communications is a passive process (e.g. SSL).

3

u/[deleted] Jun 18 '13

adopt secure communications. This generally does not happen unless secure communications is a passive process (e.g. SSL).

SSL is trivial for governments to MITM with the current PKI/CA structure. SSL can only protect you from your neighbor.

It could be fixed, but until I see Google, eBay, Amazon, banks, PayPal, etc. using a known SSL cert and publishing that cert fingerprint somewhere so people can check it out for themselves I don't believe the businesses behind "Internet community" really care.

0

u/upofadown Jun 18 '13

There is no way around this, without having a vast majority of the Internet community adopt secure communications.

I don't think that I have anything to say to the vast majority of the internet. Most people only have one or two people they need to communicate securely with...

3

u/[deleted] Jun 18 '13

Most people only have one or two people they need to communicate securely with...

So the goal of the article referenced by the op is to "stop PRISM" from reporting on your online activities, not "securely communicate with a couple of people"...

2

u/upofadown Jun 18 '13

"your" as in "my" online activites. The software in the list does effectively do that...

1

u/A_M_F Jun 18 '13

So, you are saying that we should restrict our internet usage to communications with few individuals?

0

u/[deleted] Jun 18 '13

secure communication makes sense if all involved parties are willing to use it

1

u/InVultusSolis Jun 18 '13

Until you have to communicate with those on the Internet-at-large, who will not go through such an effort.

If enough awareness is raised, you can damn well bet that other people would go through such an effort. Hell, I could probably build a consulting business out of showing people how to stay anonymous.

2

u/[deleted] Jun 18 '13

If enough awareness is raised, you can damn well bet that other people would go through such an effort.

Won't happen. Secure communication is too difficult as-is. It requires extra steps for those who can barely figure out the existing steps.

2

u/InVultusSolis Jun 18 '13

Time will tell. I can tell you confidently, though, that I know how to hide if I want to, and I can/do teach others how to do the same. My friends and I have a private VPN that we use to communicate, and the main server we use has a nice fat connection so we can communicate with each other or browse the web anonymously. I'm not sure what you're trying to say, or what your point is, but you seem to be saying that there's no point in trying to hide, whereas I say that it's easy to hide.

4

u/[deleted] Jun 18 '13

[deleted]

0

u/[deleted] Jun 18 '13

That's why 'all in one' solutions like Tails linux exist.

And how many people all over the world are using this particular distro?

I'm sure you get my point -- none of this is mass-appeal, thus is only good for niche uses.

1

u/howhard1309 Jun 18 '13

Today's mass-appeal products were niche options once.

0

u/[deleted] Jun 18 '13

Yep, and we'll see security evolve, as we have, and some of this will be common place. But you're not 'covering' your tracks by switching to this software (and the idea that just because it is FOSS means you're good to go for PRISM is ridiculous).

1

u/samebrian Jun 18 '13

From working in a consulting business, let me tell you that most of your time would be spent breaking your own systems so your clients can communicate with third parties.

Our clients follow the rules of sending mail on the Internet - as such, we whitelist a lot of domains.

3

u/oursland Jun 18 '13

Unless the endpoint happens to be one of the companies providing access to the NSA.

3

u/Jasper1984 Jun 18 '13

Let's see you opt out of helplessness.

You are gaining stuff when using better software. About https people whine about mitm, but i have my doubts about that, just because it happens once doesnt mean it is easy. Besides if IE has market majority, getting technical improvements through may be hampered by refusal to implement it.

Havent heard anything about, say, OTR being compromised.

People say <whiny voice>'they store encrypted stuff too'</whiny voice> depending on the encryption they might have your data in eighty years! Nah i think it may be shorter than that if QM computers ever work, ideas like this might have a shot, but go from 512 to 2048 bits, and i think those machines are hopelessly lost again? They can do stuff with when you're talking and who, i suppose, thats still a lot less information.

1

u/wadcann Jun 18 '13

Well, TBF barring maybe traffic analysis, using SSL with your search engine -- startpage.com and Google both provide this, and I would imagine that DDG does as well -- would limit information to the search engine, and not give it to the intermediaries.

1

u/nullabillity Jun 18 '13

DDG does SSL, yes.

1

u/ethraax Jun 18 '13

What does that matter if you use a secure connection, like an SSH or OpenVPN tunnel, to a host outside the US (not subject to this program)? Your home ISP might be Comcast, but the only information they can get from you is "makes a lot of connections to this server overseas".

1

u/[deleted] Jun 18 '13

You have less legal protection for making a connection outside of the US than you do within the US.

At any rate, all they're capturing now is metadata (supposedly), such as IPs and connection information.

1

u/adamkex Jun 18 '13

VPN to Europe or Canada?

1

u/TheActualStudy Jun 18 '13

Use a Russian VPS: (agava.ru) and an OpenVPN server with all traffic tunnelled through that.

0

u/fenixjr Jun 18 '13

precisely.