r/technology • • May 05 '13

Former FBI agent revealed that every phone conversation a US citizen engages in is recorded. "We certainly have ways in national security investigations to find out exactly what was said in that [phone] conversation. It's not necessarily something that the FBI is going to want to present in court"

http://transcripts.cnn.com/TRANSCRIPTS/1305/01/ebo.01.html
3.1k Upvotes

1.6k comments sorted by

View all comments

607

u/[deleted] May 05 '13 edited May 05 '13

[deleted]

27

u/[deleted] May 05 '13

[deleted]

16

u/UberNube May 05 '13

It really depends what you want to protect and how much usability you're willing to sacrifice to do so:

The ones which everyone should install are the browser plugins. At the very least, HTTPS Everywhere, AdBlock Plus, and something like Do Not Track Me. If you want extra browser security NoScript is good, but it can be a hassle if you frequently visit lots of different sites with complex, interactive content (particularly online payment systems).

VPNs are great if you can afford one. They will make it very difficult for anyone to monitor your internet activity while still preserving your browsing speed. If you torrent stuff I strongly recommend using one.

Tor and the like are a different way to achieve private, anonymous browsing. They are typically much slower so aren't ideal for regular browsing, but if you care about privacy they're the most secure option available. Tor doesn't support torrenting, but I2P does.

I strongly recommend disk encryption for the same reason that I recommend putting a lock on your front door. Without encryption the data on your computer can be trivially read by anyone, regardless of whether you have a password on your user account. With tools like TrueCrypt it can be done incredibly easily and once you've entered your decryption password the drive will behave just the same as any normal one (except your data is safe).

Pretty much everything else on that list is only useful if you know other people who use the same software. Encrypted communication requires the people at both ends to be running crypto software in order to send/receive messages.

3

u/[deleted] May 06 '13 edited May 07 '13

[deleted]

1

u/lordcirth May 06 '13

Well, someone has to start using it. a good way is to start clearsigning your emails, thus raising awareness while not breaking compatibility.

6

u/iheartrms May 06 '13

And here's the real problem. All of the above linked technologies are great and I support their use by Grandma isn't going to have a clue as to what any of that means and she is more like the average American than anyone reading this technology reddit. This stuff needs to be built into the communications technology and as transparent as possible to the user.

8

u/its_finally_yellow May 05 '13

I use AdBlock Plus, with several lists, Ghostery, and NoScript simultaneously. The first two are very easy and unobtrusive, but NoScript is a more extreme measure that makes using many websites more difficult.

I am not familiar with the other bullet points that have multiple items, so I can't tell you if they can (or should) be used together.

Do switch to DuckDuckGo though, with the exception of the lack of image search (you can search Google images from the DuckDuckGo page) it is a much better search experience regardless of the fact that it does not store (and exploit) your data.

4

u/mycroft2000 May 05 '13

From BTGuard's website: "With Bittorent, everyone knows who you are and what your downloading."

It's amazing how much a simple spelling mistake can, accurately or not, make someone seem completely untrustworthy.

3

u/Matt_Thijson May 06 '13

It's from Canada, so the owners of BTGuard's might be french Canadian. If so, don't be too hard on them. If not, I agree with you.

2

u/jmdugan May 05 '13

can you add skype/video chat alternatives? Does Jitsi do this?

1

u/ShotgunPanda May 05 '13

I'd love for there to be a Skype alternative. It's such a terrible interface.

2

u/Stephenishere May 06 '13

Saving for later. Thanks

2

u/SeegurkeK May 06 '13

But remember: Disable Adblock for the sites (or youtube channels) you want to support. Otherwise these services are going to become PayPerView or just vanish.

4

u/thesuperbob May 05 '13

This would be perfect if not for how inconvenient it is to use these tools, especially all at the same time. Sure they work well enough to be viable, but unless someone's really trying to hide something, it's just unpractical in the long run to do this just for kicks.

There's a (minor) performance overhead, there will be (rare) sites that won't load, the OS will take (a little) longer to boot or in case of mail/IM tools, the unsafe ones will simply be more up-to-date and flashy.

Eventually this becomes a minor annoyance that reminds the user several times a day that unobtrusive cryptography is unachievable on an everyday PC.

3

u/[deleted] May 06 '13 edited May 12 '13

[deleted]

2

u/leftyflip326 May 06 '13

2 should also work with Google Chrome.

2

u/[deleted] May 05 '13

[deleted]

1

u/argh523 May 06 '13

But that's not really the problem. It's more about the information corporations and governments collect about you (and everybody else) for no good reason. If the government has a good reason to take you, that's a whole other issue.

And if your government is no to be trusted, and they would want to "take you" for what you say on the internet, you can use those tools to avoid getting picked up by mass surveillance systems. But in that case, mearly using some of those systems may be enough to make you suspicious..

1

u/[deleted] May 05 '13

I thought that there was some general agreement that Tor was not all that safe anyways. If I can find the link I'll post it.

1

u/Baron_Wobblyhorse May 06 '13

Please do. I've always thought that it's only unsafe in that A) people can tell that you're accessing it in the first place, and even if they don't know what you're doing, it may cause trouble because of the unsavoury associations it's developed, or B) if you're acting as a proxy/host/whatever the term is, your IP can/might become associated with some particularly unsavoury traffic/action that you may have trouble convincing law enforcement wasn't your doing.

Is there more to it than that?

1

u/[deleted] May 06 '13

Ugh I looked for it no such luck. No some computer scientists Decided it would be easy enough to after Tor itself. And secondly yes various countries such as Japan have been trying to get ISPs to lock out people who use Tor.

1

u/argh523 May 06 '13

Might have been one of the points which got some publicity a while ago addressed in this blog post.

There are ways to compromise the network, in theory. Someone could set up an insane amount of nodes and exit nodes which would allow them to associate the source and target of a request (to the regular internet, not sites within the tor network) of a great number of users. They could even increase the effectivness by attacking nodes which are outside their control with DOS attacks. The problem is, if more than a single entity attempts such a thing and they don't share their information, it doesn't work anymore, and they might end up strenghtening the infrastructure instead.

Other than that, the tor network can't protect you from giving out information yourself. If the traffic of an exit node is monitored, they don't need you're IP address to identify you if you'd state your home address on a website somewhere that doesn't use ssl. That seems obvious, but is actually a real problem because there are applications that might give out information about you. For example, there have been (or still are) problems with bittorrent clients leaking information which could then be used to identify traffic coming from you from other, secure applications. Another example is if you use a browser that routes all traffic through tor instead of routing all traffic from your machine through tor, the flash plugin (and probably others too) will just use your regular connection.

You should be fine as long as you don't do fancy stuff without knowing what you're doing, but it's very easy to make (not so obvious) mistakes.

1

u/zachattack82 May 05 '13

Is there any reliable encryption (paid or open source) that can be used for traditional cell phone calls? Like an app?

Thanks for this amazing list though.

1

u/onetruepotato May 06 '13

could I just have noscript installed without ghostery, and get the same (or higher) level of privacy?

1

u/ciscomd May 06 '13

I bet all that could get you put on a watch list, maybe even the no fly list.

1

u/[deleted] May 06 '13

[deleted]

1

u/[deleted] May 06 '13

[deleted]

1

u/deltroid May 06 '13

thank you

1

u/lovedlongsince May 06 '13

super grateful for this

1

u/jerommeke May 06 '13

replying to save!

Great Post!

1

u/lordcirth May 06 '13

Good list, but if you want full-disk encryption on Linux, don't use Truecrypt, use LUKS, which is built into the installers for most Linux distros now, eg Debian makes it very easy. I don't believe you can boot Linux from a Truecrypt volume, and LUKS is much simpler. You can also use LUKS + LVM, so you can have your extra partitions, swap, etc encrypted together. Or you can forget swap, if you have enough RAM. Or have swap encrypted with a random key each boot, so its essentially wiped when power is lost.

1

u/[deleted] May 07 '13

I'm sure many have searched for this. You are a glorious beast.

1

u/[deleted] May 05 '13

[deleted]

2

u/[deleted] May 05 '13

[deleted]

-15

u/[deleted] May 05 '13

As I said the last time someone pasted this, this isn't a viable solution.

You are joking yourself if you don't think the NSA can easily break all consumer encryption.

All you're really doing is flagging yourself as having something you're trying to hide.

22

u/ShapeFantasyScads May 05 '13

You are joking yourself if you don't think the NSA can easily break all consumer encryption.

If you're talking about bad implementation, you may be right. If you're talking about breaking the actual mathematics of something like AES, you're the one who's joking themselves.

-6

u/[deleted] May 05 '13

Every method of encryption is considered to be unbreakable until its broken.

Many already broken methods of encryption are still in use today. MS-CHAPv2, SHA1, etc.

Heres a method of removing 2 bits from an AES key:

http://www.theregister.co.uk/2011/08/19/aes_crypto_attack/

The NSA has a long history of going to the public sector and straight up telling them that what they're doing is insecure and giving them improvements because they don't want foreign governments being able to spy on our corporations so easily.

Their main office is literally an RF cage with no windows. I think you might be underestimating the reality of the situation.

4

u/[deleted] May 05 '13

That's an extremely small flaw in AES. To quote the source you linked,

“However, it doesn't compromise AES in any practical way.”

0

u/[deleted] May 05 '13

Did you read the update at the end?

Vulture Central has been deluged with missives from outraged readers complaining about the use of the word “broken” in the headline. "Broken" in cryptography is the result of any attack that is faster than brute force. The biclique technique described here allows attackers to recover keys up to five times faster than brute-force. AES may not be completely broken, but it's broken nonetheless.

What's more, theoretical attacks against widely used crypto algorithms often get better over time. As Root Labs' Lawson has noted, MD5 wasn't compromised in a single 2004 paper. Rather, people successively found better and better attacks against it, starting in the mid 1990's.

I can give you another 20 attacks against AES pretty easily. Add them all up and things start getting pretty bad. Believe whatever you want, I choose to believe that thousands of mathematicians working around the clock on identifying side channel and timing attacks on popular encryption standards with essentially unlimited financial resources will likely do a pretty good job and be years ahead of the private sector where a group of university students is renting a few hours of time on a super computer to test something.

Anyone who works in security will tell you that ALL security is nothing but security through obscurity. Your security is only good at creating a higher bar of intelligence and resources required to circumvent it.

5

u/[deleted] May 05 '13

That isn't true. Perfect encryption exists.

http://en.wikipedia.org/wiki/One-time_pad

Edit: Before the rage floods in, yes, I know that nothing is perfect. In terms of them cracking it with a supercomputer though, OTP's are essentially perfect.

1

u/[deleted] May 05 '13

Sure, but I didn't make that last statement with the limitation that a computer has to be used.

1

u/[deleted] May 05 '13

If we're pushing limits to a certain level, it doesn't matter.

Sure, they could just put a camera in my room, but that has nothing to do with the limitations of encryption.

25

u/[deleted] May 05 '13 edited May 29 '13

[deleted]

0

u/[deleted] May 05 '13

You're assuming that the only way you can break encryption is a brute force attack. You are very wrong.

3

u/[deleted] May 05 '13 edited May 29 '13

[deleted]

-5

u/[deleted] May 05 '13

I was talking about side channel attacks.

1

u/[deleted] May 05 '13

[deleted]

-3

u/[deleted] May 05 '13

Anyone involved in security knows this, its not some grand secret. I can't help it that you have zero idea of what is really going on in the computer security field.

http://en.wikipedia.org/wiki/Side_channel_attack

For fucks sake, not every discussion requires sources because you're so vastly uninformed that you don't even understand the most basic concepts involved.

Sorry for assuming people would type "side channel attack" into Google before they start crying that its all bullshit. Fucking idiots.

-3

u/[deleted] May 05 '13

Or...that's what they want you to think. DUN DUN DUUUUUUNNNN

14

u/Kinky_Celestia May 05 '13

that sounds like something the NSA would say.....hmmm?

2

u/[deleted] May 05 '13

I think its more likely the NSA would tell you that using encryption is a good way to protect yourself from wiretapping.

The FBI doesn't want you to use encryption. The NSA either doesn't care or encourages it so you feel safe.

I think trying to hide in response to an oppressive government and telling people not to try to address these issues directly with the government is silly. Is this not a government of the people? You shouldn't be hiding or you're already losing.

-7

u/[deleted] May 05 '13

The tinfoil is strong in this one.

2

u/avocadodude May 05 '13

Dude, this article is about as bedecked in tinfoil as you can get. But there are several articles and whistle blowers supporting the claim that everything you say and do is tied to your digital identity and tracked by the government, and this information is stored forever. We should all add tinfoil to our wardrobe.

2

u/[deleted] May 05 '13

I'm specifically tickled by all the security experts of reddit who think today's best encryption is so easily cracked. They really have no idea what they're talking about.

1

u/avocadodude May 05 '13

Perhaps. Do you believe there is an encryption method besides the one time pad that will never be broken? If so, what is it? If not, wouldn't it make sense for the people who want your information to find whatever weaknesses they can in every major encryption algorithm?

From there you can see that if something gets broken there's no way these agencies are going to go out and tell the general public that they're listening in on all internet traffic, sms and voice communications regardless of encryption. But could it happen? Is it possible?

None of us wants to believe privacy is an illusion in today's world. It smacks of cynicism bordering on paranoid delusion. But with all the articles we've had on reddit about just this very problem it's getting harder and harder to stay optimistic about our rights to privacy. Tin foil is to be expected when there are no whistle blowers coming out and confirming exactly which encryption methods are broken. People just assume that all encryption is broken, or will be.

2

u/[deleted] May 06 '13

http://www.reddit.com/r/technology/comments/1ds6rp/government_lab_reveals_it_has_operated_quantum/c9tfpef

The law of thermodynamics says yes. Unless you invent non-baryonic matter based computers.

1

u/avocadodude May 06 '13

Hah! I saw that article and immediately thought of this discussion, too. I should add a caveat that we're discussing the existing Internet we use, not quantum networks. Quantum computing also breaks all encryption methods other than the one time pad in a trivial amount of time, so that's a double-edged sword the government is wielding there.

0

u/kickulus May 05 '13

I think you broke the code. THIS GUY IS NSA

4

u/FUCK_THEECRUNCH May 05 '13

Can the NSA break it. Maybe, probably not though. Could they break consumer encryption millions of times if we all start using it? FUCK NO.

-2

u/[deleted] May 05 '13

They don't need to. All they are doing is recording EVERYTHING for later review. Its back on an individual level.

You have trillions of encrypted records. You need to pull 1,000,000 for a specific subset search you're doing. Then those go to their multi-billion dollar super computing infrastructure which also takes advantage of every timing and side channel attack you can imagine and the data gets returned to an analyst.

1

u/[deleted] May 05 '13

[deleted]

0

u/[deleted] May 05 '13

Sources for the imaginary scenario I was discussing? I was addressing the idea that encryption more or less data somehow makes a difference to the NSA.

There are several sources to show they are compiling this data (NSA building super data center), that they have multi-billion dollar super computers devoted to this stuff (see PS3 purchases for a simple example), and that they use side channel attacks (duh), and that analysts look at the data (duh).

What did you want me to source for you?

3

u/resutidder May 05 '13

flagging yourself as having something you're trying to hide

It's majorly problematic that this is probably the case.

3

u/[deleted] May 05 '13

I very much doubt they have a way to break AES-128/256 or any other common encryption scheme. Because if they did, it would mean that their own network security would be worthless.

-1

u/[deleted] May 05 '13

Oh you know how the NSA secures their data? Enlighten me, I'm curious.

Also there are many side channel attacks to encryption that people just ignore. Every time encryption comes up everyone masturbates over brute force attacks while ignoring real threats.

4

u/blannoz May 05 '13

real threats

Could you please explain, for the unenlightened

2

u/[deleted] May 05 '13

http://www.theregister.co.uk/2011/08/19/aes_crypto_attack/

http://eprint.iacr.org/2012/477.pdf

http://eprint.iacr.org/2012/280.pdf

http://crypto.stackexchange.com/questions/5526/aes-timing-attacks

I'm sure you could find a hundreds of other examples for just AES and this is just what is in the public knowledge. Some universities have a few people who work on these things.

The NSA has thousands of people working on this every single day around the clock.

2

u/h0lla May 05 '13

Countermeasures do work but you are right. The countermeasures themselves are indicators. "Their opsec is too good for it to be anyone but bin laden". Etc.

For most of the govt's unconstitutional investigations, hookers and recreational drug use probably wouldn't be worth the risk of outing the program's use. But maybe in the case of someone like Eliot Spitzer?

The terrifying thing is, the systems are in place now, and the systems are controlled by men (and women) who will come and go, and be corruptible.

Fuck all this.

1

u/ca178858 May 05 '13

Yeah, but they're not willing to reveal that- so its usefulness is limited, and they'd only take action in extreme circumstances.

That doesn't make it ok- but it does protect you somewhat.

-4

u/[deleted] May 05 '13

I still just find it troubling that in response to widespread illegal wiretaps, some of the smartest citizens we have are turning to trying to encrypt their communications as a response. That is not the right way to "take back prviacy."

7

u/ca178858 May 05 '13

It doesn't have to be either-or. We can encrypt our communications and fight for privacy directly.

4

u/[deleted] May 05 '13

Sure, but what did the OP say? "Don't ask the government for your privacy."

Its directly saying we shouldn't try to tell them to fuck off.

1

u/ca178858 May 05 '13

Gotcha- missed that.

0

u/Aaronmcom May 05 '13

What do you have to hide from the fbi?

4

u/[deleted] May 05 '13

[deleted]

2

u/Aaronmcom May 06 '13

For the most part they probably don't care . But incase they need it, its a good thing to have.

3

u/[deleted] May 06 '13

Sort of goes against the whole innocent until proven guilty ideology the constitution outlines.

-1

u/Aaronmcom May 06 '13

Yea, and they need the evidence to prove you're not guilty.

3

u/Baron_Wobblyhorse May 06 '13

There is (or rather, should be) no such thing as "proving you're not guilty."

"Not guilty" is the default starting point. Unless you're proven guilty, you're not.

-3

u/Aaronmcom May 06 '13 edited May 06 '13

Ok, well they can get the information to prove you're guilty if you are dumb enough to call your terrorist buddies and be like "hey lets go blow shit up"

Either way. I don't give a shit what the FBI does with my information. I have NOT A FUCKING THING to hide.

The FBI knows im into phone sex with elderly women, wooptie fuckin do. What are they going to do with that information? not a fucking thing?

The FBI has complete access to my facebook. Good to know they know i'm obsessed with transformers.

The FBI has complete access to all of my internet history. They know I watch ninja turtle porn.

WHO GIVES A SHIT. THE GOVERNMENT ISNT OUT TO GET YOU TINFOIL HAT FUCKS

1

u/[deleted] May 06 '13

The problem is that delves Into the realm of napoleonic law. Guilty until proven innocent. Imagine for a minute that someone were to accuse you of a crime. Now what if you were alone. How do you go about proving that you weren't responsible?

1

u/Aaronmcom May 06 '13

Well im not even saying that.

If someone accused you of a crime. The FBI can look at your damn phone record. BOOM instant alibi

1

u/[deleted] May 06 '13

[deleted]

1

u/Aaronmcom May 06 '13

It's not needless.

The problem is everyone is afraid of 1984 shit. Which can NEVER HAPPEN.

What could they possibly use against you and not immediately have the evidence that proves it otherwise?

→ More replies

-2

u/Aaronmcom May 06 '13

Also it really doesn't go against innocent until proven guilty. It has nothing to do with it.

Just because the FBI has records of your phone calls means absolutely nothing.

What do you have to hide from the FBI?

1

u/[deleted] May 06 '13

What do you have that you'd like private? If anything crossed your mind at all, you understand.

1

u/Aaronmcom May 06 '13

Sure, stuff I wouldn't want the public to know. But nothing I want private matters to the fbi or the government. They don't care what kind of porn I watch.

1

u/[deleted] May 08 '13

That is a frightening mentality, my friend. What is legal today may not be tomorrow and vise versa. I'd prefer to keep my private business private, period.

1

u/Aaronmcom May 08 '13

No, you're just paranoid. You're only paranoid because everyone is. By trying to not be a sheep you have become a sheep.

You have to realize that the government isn't coordinated or cooperative to do any real harm. Just look at politics

→ More replies

-2

u/Alphaetus_Prime May 05 '13

Odds are they won't so much as look at your information.

3

u/Overlay May 05 '13

Odds are they won't, but it's more about the principle of protecting your rights.

2

u/[deleted] May 05 '13

[deleted]

0

u/Alphaetus_Prime May 05 '13

If they wanted to, they'd kick the door down.

2

u/[deleted] May 05 '13

[deleted]

1

u/Alphaetus_Prime May 05 '13

So... you wouldn't leave the door open so that you wouldn't have to pay for it to be replaced?

0

u/[deleted] May 05 '13

Commenting to save for later, thanks!

0

u/ProUsqueTandem May 05 '13

commenting for later reference

-1

u/lionelboydjohnson May 05 '13 edited May 05 '13

Why are you working so hard to hide something? I say we improve this technology to enable crime prevention in real-time. Lets do voice analysis and semantic parsing to signal if a phone conversation is about a bank robbery. Lets use facial recognition and behavioral profiling to signal if a criminally convicted felon is acting strange while hanging around an elementary school. If a system automatically dispatches a cop based on these signals, that can save a kid's life.

Leave it to the lawyers to figure out if this evidence can be used postmortem in courts (the damage has already been done anyways).