Showing posts with label encrypted communications. Show all posts
Showing posts with label encrypted communications. Show all posts

Tuesday, August 23, 2016

Threema, a messaging app that cares about your privacy

Image courtesy of Dr. Motte at Flickr.com
Telegram is surely the app that we usually resort to in order to demonstrate how an app can offer a very high level of security and privacy to its users, with certain characteristics such as end-to-end encryption and secure chats that take to the next level the fact that we can feel safe when we take part in a conversation with sensitive information. The developers of Telegram have struck a chord with a need that came from millions of users after the events that took place with Edward Snowden and the NSA.

Now we have another application that follows this path and that presents itself as one of the most secure ones to stay out of reach from hackers, corporations and government agencies, and, once and for all, it can be used in a completely anonymous way.

The app is called Threema and we could say that it's the opposite to the ones that we use everyday -such as WhatsApp- in terms of security and privacy.


Security comes first


Telegram is a big bet, and so is Line with the implementation of end-to-end encryption. WhatsApp would later adopt this method, though a bit later than its competitors. If we want to jump to the next level, we’ll get to Threema. It's not a free app, something that some users may not like, but those who want to have access to certain privacy and security features will shortly find in it a great destination for completely anonymous conversations.

Threema is an app developed by a company in Switzerland that has been endorsed by the German government. The servers are located in Switzerland as well and we could say that it’s one of the countries that cares the most about users’ safety and privacy.


With that being said, these servers will only store the minimal amount of information, and the users’ devices will act as clients and servers. The Swiss servers will only act as intermediaries to transfer information from one device to the other. Said information, will be encrypted.


Anti-hacker encryption

Image courtesy of  Melina Sampaio Manfrinatti at Flickr.com

Without a doubt, announcing that it will be impossible for hackers to access your private information will be an attractive statement to them, but this is due to an encryption method based in the open-source library NACl (Networking and Cryptography library). This is why in order to impede copies of information or unauthorized backdoor accesses, the encryption keys are generated and stored securely in the devices of the users, as we mentioned before. 

Threema has stated that group subscriptions and contact lists are only managed from the user’s device. Once the messages have been delivered, they delete themselves so that the files that remain locally will stay, encrypted, within the smartphone or tablet.

The following are several of Threema’s features:

  • Text messages and voice messages 
  • Sending of all kinds of files: PDF, GIF, MP3, Doc, ZIP and so on.
  • Sending images and video and the ability to share your location.
  • Group chats in which new members can be deleted at any time.
  • ID verification of contacts through personal QR codes.
It’s also worth noting that Threema doesn't require the use of a phone number or an email address. Each user receives a random ID from Threema to identify themselves.

You may not find many of your contacts with it, but it's only a matter of time. It also has a specific function in terms of privacy which differentiates it completely from other apps.

The company that created Threema is made out of -you guessed it- three employees. The startup managed in just 24 hours to double the size of their user base and the app got to the first place in the charts of paid apps in Germany.

Threema combines components of social networking with some of them coming from messaging apps and, on the other hand, apps aimed towards customization. Anonymity is definitely a key factor around which the app revolves.

The German government endorsed the usage of alternative apps for private communications. The app also allows you to find other users by syncing your contacts, but this step is completely optional. You can also share information such as your location on a map, all without leaving the app. If you want, you can exclude individual contacts from the sync process, it features an internal image viewer, a contact list that can be classified according to your needs, blocking of individual contacts, quick switching between different chat conversations, custom nicknames for unknown contacts and several other useful features that will help you keep your conversations away from eavesdroppers.

Even though it doesn't feature the option of voice calling, users can send voice messages. It's available for iOS and Android, and it’s a little less expensive if you have a Windows phone.

Related content

Read Don Burns' "The importance of cryptography in points of sale"

Thursday, August 11, 2016

What Is Encryption And How Can It Work For Me?


Image courtesy of Intel Free Press at Flickr.com
We truly live in an era where information has become one of the most traded commodities available. Is it possible to ensure that the information we send, receive, create and store in our devices stays safe and accessible only to those you want to share it with?

The use of encryption software has been associated with paranoid conspiracy-theory enthusiasts who believe the government is out to get them and wants to steal their information. However, as ridiculous as it may sound, they are not entirely wrong. Your information can be at risk but not exactly the way you think. Identity theft, hacking, state-sponsored snooping and even advanced steps of social hacking may take place by violating your electronic privacy accessing your files, pictures and personal computer content.

You’ve probably heard the word “encryption” many times before but are unsure of what it means exactly, how it works and what can you do to take advantage of its benefits.

First of all, encryption is a method of protecting information in a way so that only those intended by you are able to access it. Using encryption is not something new, and the basic concept of it remains the same even if the tools available to encrypt have changed. Rudimentary forms of encryption have existed since the times of the Old Kingdom of Egypt when non-standard hieroglyphics were carved in monuments. It wasn’t until around 800 AD when Al-Kindi invented a frequency-analysis technique for breaking mono-alphabetic substitution ciphers, something that proved to be the most fundamental cryptanalytic advanced until WWII.

Encryption uses algorithms to jumble data into a string of code that is complete gibberish to those who do not have permissions to see the information. Those permissions come in the form of an encryption key that decodes the information and rearranges characters and code so it can be read the way it was meant to and without the key it is impossible to decrypt the data.
Data can be encrypted in transit, meaning when the information is traveling towards its destination; or at rest, when the data is stored at a terminal or server. End-to-end encryption for communication platforms is considered the most secure. If messages are end-to-end encrypted, only the people who are having the conversation have the keys to decrypt what’s being sent.

Software for encryption is very easy to use nowadays and it doesn’t take much to get started. Here you can see a very easy info-graphic showing you all the necessary steps to do basic encryption for folders in different operative systems. 

It is important to choose an encryption key length that is strong enough to withstand any attacks or attempts to decrypt your data. An AES 128-bit encryption key is considered suitable for your security needs as it can have more than 300,000,000,000,000,000,000,000,000,000,000,000 key combinations.  
Encryption software gathers random data before encrypting your files, also known as entropy. The password you use will be part of this random data gathered to cipher the files, this is why it is very important that you choose a long passphrase, in addition, you should not use any dictionary words to avoid brute force attacks. A brute force attack consists of an automatic process where all of the dictionary words are quickly input at the password login window. As computers have become increasingly faster this can be done in a matter of hours or less using cloud computing.

Here are some tips to follow:
Image courtesy of Kevin Spencer at Flickr.com
  • Always choose an encryption program that uses a standard cipher that has been approved and tested by experts, like AES for example.
  • Do not use common dictionary words as your password, use a long passphrase made up of capital and small letters with punctuation signs and numbers that will remember and try not to write it down anywhere
  • Do not use the passphrase you use to encrypt your data for anything else like your email, Facebook or any other computer password.
  • Never trust a third party service to store your encryption keys or carry out the encryption implementation, if you store data online encrypt it yourself in your computer before uploading it.
  • Watch out for key-loggers and malware in your computer that could capture your keystrokes and your secret passphrase, use an antivirus and firewall and always keep it up to date.
  • Never reveal to anyone your password, not even to a support department whose staff could be outsourced overseas or could be impersonating someone else. Always verify personnel before giving out any of your information over the phone
All of your information is valuable and should be protected, so take the necessary steps and get in the positive habit of encrypting your files and your communicated over the web.

If you want to learn more about encrypted communications and more advances in telecommunication technologies, be sure to check out our many articles at our blog at Don Burns’ Blogspot.

Monday, August 8, 2016

Anonymity on the Internet: which is better, VPN or Tor?


Image courtesy of Blue Coat Photos at Flickr.com
Complete anonymity on the Internet is impossible and, in the best of cases, a particular phenomenon unfeasible of being maintained for extended periods of time. However, both the VPN and Tor networks help hide the user's identity from third parties. But which one of them is better? Let’s take a look at the similarities, differences, advantages and disadvantages of using VPN and Tor.

Online privacy has become a growing concern for millions of users worldwide, either due to the fact that they’re sharing all kinds of personal information with third parties such as Facebook, Google or Twitter; or to prevent possible attacks by cybercriminals; monitoring by government agencies like the NSA or to limit access to certain websites.

Even though some still believe that surfing the Internet is an anonymous activity, reality is stubborn. The incognito mode or private browsing offered by browsers like Google Chrome, Mozilla Firefox and others is not an effective method of maintaining your anonymity on the Internet, which is why more users are choosing to use a VPN or connecting through Tor.

Both are two methods of transport to surf the Internet. However, the differences between Tor and VPN networks are considerable: a VPN could be likened to an ultralight aircraft, pretty fast but also expensive; whereas Tor, could be compared with a bus, available to anyone, but much slower.


Advantages of using Tor


The purpose of Tor (The Onion Router) is anonymity when surfing the Internet. To do this, the user’s information bounces between different nodes before reaching its destination, so the last server is unable to know the location and private information such as the IP address of the source.

We said at the beginning that there’s no such thing as complete anonymity, and Tor is no exception. Although it’s one of the best systems to surf anonymously, the network’s end node decrypts the data to access the required destination by the initial user, opening the door to possible vulnerabilities. It is hard, but not impossible.

If you browse via Tor, it is essential for you to be aware of the fact that it is not a bullet-proof system. The security level is very high if you use secure connections (HTTPS), but otherwise it’s low.

To maintain your anonymity it’s essential that you avoid sending unencrypted personal information such as your email address, location or mobile phone.


Advantages of using a VPN

Image courtesy of PhOtOnQuAnTiQuE at Flickr.com
In simple terms, VPNs (Virtual Private Networks) add a private network -tunnel- on the main network of the user. Basically, a VPN grabs your connection, encrypts it and sends it to another server. Instead of your computer going directly to Google, it first accesses an intermediate server and, from there, it goes to Google.

Using a VPN is recommended, for example, when browsing within a public Wi-Fi network because otherwise you’ll be at risk of third parties seeing everything you do online. When using a tunnel, only your connection to the intermediate server will be visible, which is the one that actually makes the requests to Google, Facebook and other sites.

Another advantage of using a VPN versus the usual navigation is that you can “fool” the rest of the world about your location: if you are in New York and the VPN server you use is in London, all of the websites that you visit will believe that you are a user from England, which opens the possibility of skipping geographical limitations in all types of content.


When is it best to use Tor? And a VPN?


Although there are some providers of free services like Hola, most VPN services -the most powerful ones- are paid. By contrast, the Tor network is free by definition, because it employs the user’s connections to establish the nodes.

Anonymity in a VPN network is in any case relative, given the fact that even though they promise not to store information about their users, it is difficult to think that they can keep their promise if a court order comes.

Tor guarantees a higher level of online anonymity, as long as the the user takes some precautions, but it’s not as impenetrable as the NSA has tried to show in recent years. The biggest disadvantage of Tor is that browsing speed is very limited.

When to use a VPN? If you are an intermediate user concerned about online privacy and the use of your data by third parties the recommended option is a VPN. You will have a considerable latency, but the speed of your connection will be enough to play HD videos on sites like YouTube or Netflix.

When to use a Tor network? This system is used in situations that require a high level of anonymity, especially with the threat of governments or intelligence agencies. It’s reliable, for instance, for journalists working with sensitive documents and leaks, but the biggest disadvantage is that the connection speed is quite slow.
Recent contents

Read Don Burns’ “How The Evolution of Sensors On Smartphones Makes Life Easier”

Tuesday, August 2, 2016

Learn how to defend against the MITM attack

Image courtesy of Blue Coat Photos at Flickr.com
The Man in the Middle attack is also known as a bucket-brigade attack, or Janus attack in cryptography. As its name explains, the attacker keeps himself between two parties, making them believe that they are talking directly to each other over a private connection, when actually the entire conversation is being controlled by the attacker. In a previous article, Don Burns explained all about the Man in the Middle attack, now you can learn about the defense. Since MITM attack can succeed only when the attacker can impersonate each endpoint to the satisfaction of the other, the two crucial points in defending against it are authentication and encryption. A number of cryptographic protocols include some form of endpoint authentication specifically to prevent these attacks. For example, Secure Sockets Layer (SSL) can authenticate one or both parties using a mutually trusted certification authority. However, SSL is still not supported by many websites yet. Fortunately, there are three effective ways to defend against a man-in-the-middle attack even without SSL.


Virtual Private Network


A VPN extends a private network across a public network, e.g., the Internet. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network while benefiting from the functionality, security and management policies of the private network. You can start creating a virtual private network (VPN) by establishing a virtual point-to-point connection through the use of dedicated connections, virtual tunneling protocols or traffic encryptions, such as PPTP (Point-to-point Tunneling Protocol) or Internet Protocol Security (IPsec). All data transmission is encrypted so that even if being intercepted, the attacker will have no idea about the content of the traffic. As a transfer station, the safety and reliability of the VPN server are very crucial to the security of your whole communication system. So, if you do not have a dedicated VPN server yourself, you are advised to only choose well-famed VPN server provider.
After establishing a remote VPN server, either manually or using some reliable online tool, you can follow these steps to create a Point to Point connection: First, Click “Control Panel” in the startup menu. Then, select “Network and Internet”. Go to “Network and Sharing Center” and Click “Set Up a new connection or network”. Once in the “Set Up a new connection or network” dialog, select “Connect to a workplace” and then press “Next”. In the “Connect to a Workplace” dialog, click “Use my Internet connection (VPN)”. Then, input the IP address of the VPN server and press “Next”. You will have to input your username and password, then press “Create”. And finally, Click “Connect Now”. After following these steps, all data transmission is encrypted so that even if being intercepted, the attacker will have no idea about the content of the traffic.

Proxy Server with Data Encryption

Image courtesy of Defence Images at Flickr.com

Use a reliable proxy server and encrypt the transmission between you and the proxy. If you only want to conceal your IP address for a specific amount of time and are not concerned with the security and performance, go for the free web based proxy services. But if you have the necessity to hide IP address on a regular basis, need high security and performance, go for paid VPN services like HideMyAss VPN (one of the most popular and trusted VPN service that allows people to easily conceal IP address and protect their online privacy) or VyprVPN (world’s fastest VPN services that allows people to easily conceal their real IP)

If you want to make sure your IP is changed, type “my IP address” on Google before and after using any of the above services. Just compare both the IP addresses and make sure they are different. If yes, that means you have successfully changed your IP address.


Secure Shell Tunneling (Linux/Unix)


SSH tunnel consists of an encrypted tunnel created through SSH protocol connection. SSH tunnel can be used to transfer unencrypted traffic over a network through an encrypted channel. You can use SSH tunnel to securely transfer files between an FTP server and a client even though the FTP protocol itself is not encrypted. SSH tunnels also provide a means to bypass firewalls that prohibit or filter certain internet services.

SSH is typically used to log into a remote machine and execute commands, but it also supports tunneling, forwarding TCP ports and X11 connections. A Secure Shell (SSH) tunnel consists of an encrypted tunnel created through an SSH protocol connection. Users may set up SSH tunnels to transfer unencrypted traffic over a network through an encrypted channel. Using a tool like OpenSSH on a Linux/Unix system you can tunnel all of the traffic from your local box to a remote box that you have an account on. SSH tunneling can be thought as a poor-man’s-VPN. It is handy in situations where you would like to hide your traffic from anybody who might be listening on the wire or eavesdropping. You can use such tunnel between your computer and your Unix/BSD/Linux server to bypass limits placed by a network.

Saturday, July 23, 2016

Beware the man in the middle attack

Image courtesy of Charis Tsevis at Flickr.com
MITMA is an attack where a user gets between the sender and receiver of information and sniffs any information being sent. In some cases, users may be sending unencrypted data, which means the man-in-the-middle (MITM) can obtain any unencrypted information. The attacker secretly intercepts and relays messages between two parties who believe they are communicating directly with each other. The attack is a type of eavesdropping in which the entire conversation is controlled by the attacker. Sometimes referred to as a session hijacking attack, MITM has a strong chance of success when the attacker can impersonate each party to the satisfaction of the other. Man-in-the-middle attack is also known as a bucket brigade attack, or sometimes Janus attack in cryptography. One way that an attacker can pull-off a MITM attack in a place where public Wi-Fi is available is to create a fake Wi-Fi hotspot, which uplinks to the public place´s Wi-Fi. Then, the attacker can use a tool to intercept SSL connections. To protect against a MITM attack, the client should check that the server's certificate. This can be done by way of certificate pinning.

MITM attack could involve distributing malware that provides the attacker with access to a user’s Web browser and the data it sends and receives during transactions and conversations. Once the attacker has control, he can redirect users to a fake site that looks like the site the user is expecting to reach. Online banking and e-commerce sites are frequently the target of MITM attacks so that the attacker can capture login credentials and other sensitive data.

Don Burns found this clear illustration of a MITM attack:

There are 3 characters in this story: Mike, Rob, and Alex. Mike wants to communicate with Rob. Meanwhile, Alex (attacker) inhibit the conversation to eavesdrop and carry on a false conversation with Rob, behalf on Mike. First, Mike asks Rob for his public key. If Rob provides his key to Mike, Alex intercepts, and this is how “man-in-the-middle attack” begins. Alex then sends a forged message to Mike that claims to be from Rob, but including Alex’s public key. Mike easily believes that the received key does belong to Rob, when actually that’s not true. Mike innocently encrypts his message with Alex’s key and sends the converted message back to Rob.

In another common MITM attack, the attacker uses a Wi-Fi router to intercept user’s communication. This technique can be work out by exploiting a router with some malicious programs to intercept user’s sessions on the router. Here, the attacker first configures his laptop as a Wi-Fi hotspot, choosing a name commonly used in a public area, such as an airport or coffee shop. Once user connects to that malicious router to reach websites such as online banking sites or commerce sites, attacker then logs user’s credentials for later use.

An attacker can also exploit vulnerabilities in a wireless router’s security configuration caused by weak or default passwords. For example, a malicious router, also called an evil twin, can be setup in a public place like a café or hotel to intercept information traveling through the router. Other ways that attackers often carry out man-in-the-middle attacks include Address Resolution Protocol (ARP) spoofing, domain name system (DNS) spoofing, Spanning Tree Protocol (STP) mangling, port stealing, Dynamic Host Configuration Protocol (DHCP) spoofing, traffic tunneling and route mangling. When we need to pass information along to someone, different things help us verify with whom we’re speaking. To verify the identity, you can follow some of this precautions:

Image courtesy of Sarah at Flickr.com
SSL creates this virtual trust and establish a secure communication between devices. The idea behind SSL is to protect the communication between the sender and receiver in order to prevent eavesdropping. To achieve this, the parties must be able to validate that the remote party to which they are connected is the intended party. After this validation, the parties create a key that’s used to encrypt all data between them for the session.

Web and non-web applications use certificate validation to establish trust. Unfortunately, some applications skip validation and end up as easy targets for MITM attacks. The primary reason validation is skipped is that the host does not have a signed certificate from a trusted CA. These service credentials are typically used to authenticate the user but could also be used to validate the service. We can use the certificate to create a fingerprint and package this along with both a random and fixed magic number and then encrypt this package with the user’s password. The encrypted file is sent to the server, which can use the stored password to decrypt the file, validate the magic number and check the fingerprint against its certificate. If the fingerprint matches, the server increments the random number and sends that to the client along with the peer certificate’s fingerprint.

Sunday, May 8, 2016

Where can you get more privacy when messaging?


Image courtesy of 3RI at Flickr.com
Are you wondering whether you should be using BlackBerry or WhatsApp Messenger? If you care about your privacy, you should seriously consider using BlackBerry. Right now it is a much safer and reliable alternative to keep your conversations private than WhatsApp. In 2013, new versions of instant messaging system for iOS and Android mobile devices were launched, and a week after that, BlackBerry Messenger had added 20 million people more, making the platform reach 80 million monthly visits. There is clearly evidence of a great interest.

BlackBerry Messenger was one of the first differential services of the company and security and privacy are two of the key features they focus on. It operates on the private network owned by the company. A large number of government security agencies have tested and approved this platform. They actually use it as well as banks and other multinational companies given that all messages sent by BlackBerry Messenger are encrypted. They are exchanged crossing the infrastructure of the company which has interconnection with a high number of carriers worldwide. This is important because it means that your message has to travel through less points to reach its recipient. So, you will see that the risk of third parties intercepting your message is highly reduced. The relationship BlackBerry has had with many telecommunications companies for so many years has led to the creation of this strategic advantage.

However, many users identify “BlackBerry” with the past; they tend to imagine plastic phones with keyboards that would allow you to check emails and send messages. Evidently, it is true. This company is one of the pioneers in the “revolution” of smartphones. In spite of the big effort in recent months to meet competition standards, this brand does not seem to achieve breaking off completely from the image they have of last century technology. However, it does not mean that their products and services are also out of date.

So, if BlackBerry Messenger offers the security and reliability that you should demand from any communication platform and WhatsApp has been proved to have so many security problems such as anyone can read your conversations, why is it more popular and has more users?

Image courtesy of Johannes Marliem at Flickr.com
WhatsApp is a simple communication cross-platform that works at a very low cost; one dollar per year. It came along at the perfect time with versions for all popular operating systems at the moment which were iOS, BlackBerry, Symbian –believe it or not- and Nokia S40. It became popular quite soon given that these type of applications were basically new and there were no many competitors which favored its position as leader. Shortly afterwards, versions for Android and Windows Phone were finally launched. Nowadays, it has millions of users and everyday it attracts more and more people around the world.

The model of this app is brilliant but the implementation is not, especially when it comes to privacy issues. There are still many questions regarding security, such as:

  • Does WhatsApp save conversations? If it does, for how long?
  • What happens to the messages from the moment they are sent until the recipient gets it?
  • Why has WhatsApp taken so long to implement encryption in the chats?
  • Why does it allow to access the system without a safer process that require a password to login? It is understandable that it makes things easier, but that is not a real justification to risk privacy.
  • What does WhatsApp do with phone numbers besides using it as a user in the system?
  • Why are WhatsApp efforts minimal for general security?
It is difficult to find answers to the questions and doubts about the company behind the service. What it is known for sure is that WhatsApp is not observed, in any way, by any government around the world which is curious because they are in charge of regulating telecommunications companies. Doesn’t it make it more dangerous?

In conclusion, it seems to be a good idea to replace WhatsApp by BlackBerry Messenger. It does not require annual subscriptions that appear by surprise because it is free. It has a multi platform -except for Windows Phone- and the most important aspect is that it is really safe. You might think that you do not need a safe platform because you don’t think you exchange interesting information.

However, you never know when you will end up talking about someone with your friends, or discussing sensitive work matters and even sharing documents, pictures or videos that can be used to harm you. The security system of BlackBerry Messenger is not perfect but you can trust in it. Some people keep saying that BlackBerry is so last century… Well, you might find interesting that Apple was founded 18 years earlier and it is still a company leader in the field of telecommunications. It is just a matter of perceptions.

Thursday, April 28, 2016

Here are the tools Snowden used to encrypt his communications

Image courtesy of danjo paluska at Flickr.com

1. Tor

Formerly known as "The Onion Network", Tor is a free software to enable online anonymity. Tor redirects Internet traffic through a global network of volunteers consisting of more than three thousand relays that hide the activity or location of the user to anyone who is performing network surveillance or traffic analysis.

When Edward Snowden decided to take all the information he could and leak it to the media to publicly denounce atrocities against individuality and the right to private information, he focused on using his knowledge about encryption to make communications impossible to track or filter to his superiors or even other governments.

Snowden used a series of tools that anyone can access, which says a lot about security available to anyone.

We now see the importance of an open source project that is poorly funded. In the same way that projects like OpenSSL should have been supported, these are some projects that should also be funded:

2. Tails

Tails is certainly one of the tools that people who handle sensitive information should definitely use. It is a Linux distribution based on Debian Live and whose focus is security and anonymity.

Unlike other operating systems, Tails is designed to be used from a USB and so it never leaves any traces of usage in the memories of the computers you use to log in. It is the great strength of Tails, you do not need to have a PC, any PC that you find with a USB port and the option of booting from a USB drive, you can use it to have your own secure communications environment.

Tails uses Tor to anonymize your Internet connection, but not just web browsing: all communications are routed using this network, blocking any application that attempts to connect using a network other than Tor.

You can download Tails from the project’s site and install it on any USB drive.

3. Tor + Tor Browser

As we mentioned before, Tails is always connected through the Tor network. Tor Browser is the solution for those who want to surf the web without leaving any trace. First, because it is connected using a P2P network of Tor users anonymously and safely. Second, because the browser does not store any data, preventing passwords to be saved in the browser’s memory.

Tor is an anonymous and secure network, which is used both for good and for bad things. We know of famous sites like Silk Road that have given a bad name to this network, but it is clear that like any other tool, you can use it with good or bad intentions.

4. GPG and PGP

PGP stands for Pretty Good Privacy and it’s an application created by Phil Zimmermann, which allows to encrypt contents based on public key cryptography. This means that, in order to read an email encrypted with PGP, the sender has to have a key to encrypt and the recipient must have another key to decrypt the message.

PGP has proven to be quite safe to share information via email. It is the system that Snowden used to communicate with Laura Poitras and journalist Glenn Greenwald of The Guardian.

PGP is quite easy to use in your communications. If you use Gmail, Yahoo Mail, or Outlook.com, you can use Mailvelope. For Windows users there is a plugin for Outlook 2010 and 2013 along with Gpg4win. Yahoo already encrypts the content of your messages even between servers.

5. Lavabit

Lavabit was the secure email service used by Snowden. Created and maintained by Ladar Levison, he decided to shut down the service and the company in August of 2013 due to the pressure of the US government. US Congress laws made Lavabit unable to share what was happening while they became accomplices in crimes against the United States.

Snowden used an email address with a lavabit.com domain to communicate with the media while in the Moscow airport. Nevertheless, the service was forced to close due to pressure by the US government.

Lavabit offered a webmail service with a focus on safety. They used advanced cryptographic methods to encrypt communications and emails in order to make them impossible to break into. In mid-2013, Lavabit had over 400,000 users with free and paid services, depending on the required storage space.

Today we can find many email services focusing on security, such as Hushmail or Resistemail.

6. Other tools

Image courtesy of Simon Waldherr at Flickr.com
All you have to do is search for a while to find many solutions that claim to be secure and encrypted for all types of communications. There are complete operating systems, email management solutions, mail encryption and secure web navigation. But there are many other services that can be used to ensure private communications.

Especially when it comes to instant ​​messaging, it is easy to find solutions with encryption. In the area of ​​mobile messaging, there are dozens of applications that claim to be safe. WhatsApp recently became one of those safe options, since they started implementing end-to-end encryption. BlackBerry Messenger is another safe alternative to hold encrypted, multiplatform conversations.


Friday, April 15, 2016

WhatsApp: the most secure instant messaging service… Finally.

Image courtesy of Luis at Flickr.com
Some of you may have noticed a sign pop up in your WhatsApp messages recently stating that your messages are now secured with end-to-end encryption. They had been working on this integration for the past year and a half and finally last week it went live making it the most secure instant messaging service out there. It ties into a huge debate occurring right now about encryption, which has been even more controversial since the FBI sued Apple for not aiding them in entering the phone of a San Bernardino shooter. So, what does the integration mean for WhatsApp and the rest of the encryption debate.

What users are now experiencing is a strong security system designed by Open Whisper Systems. Some have even speculated that this same encryption will be spread to other messaging services in the hopes to offer users maximum safety.

What is encryption?

In today’s technological world most of our communication is handled via email, social media or messaging services, which leads to a scary thought, can people eavesdrop and take a peek at your private either personal or corporate messages. Even though encryption has been around for a very long time, it has now become relevant as a means to protect your information in this digital age. Encryption is the best way out there to secure your data. Once a file is encrypted it can only be opened and read if you have access to the key or password that will allow you to decrypt it. If it is encrypted it is referred to as a ciphertext, whereas if it’s unencrypted it is known as plain text.

What’s been the news on encryption lately?

It was all over the news for weeks as Apple fought against the FBI in an effort to defend their constitutional rights, and even though the case was dropped because the government was able to unlock the San Bernardino shooter’s phone without Apple’s assistance, the debate is definitely not over. Just today they are appearing before the congressional committee once again to continue to debate on encryption. You can even tune in to the live hearing on April 19 at 10am ET. In the middle of all of this heated debate WhatsApp decides to go and introduce new measures to protect even more the content on our digital conversations.

Image courtesy of The Wild Blogger at Flickr.com

Why did WhatsApp make this move?

WhatsApp, a Facebook-owned instant messaging service, faced an embarrassing public moment when they in May 2011 it was discovered that they had a security flaw. This flaw gave way to the possibility of user’s accounts being hijacked and this way gaining access to all of their incoming messages and traffic. Although they release a new app this was not a solution to the problem, since everything was still sent in plaintext. The image of having one of the most important and used instant messaging apps coined as having poor security was in definite need of attention. Despite rising popularity of the app the problem persisted in 2012 with a hacker posting information of another major hack that allowed them to change any user’s status. In response, they launched later that year a cryptographic method replacing the plain text, which ended up being broken. This brought on even more criticism. In late 2013 a university student identified yet another flaw demonstrating that they decryption method was weak since it used the same encryption key on both sides of the conversation. So basically this meant if someone with basic technical knowledge on decryption wanted to take the time to try to decrypt your messages, they still could. Finally, in 2014 WhatsApp was found to have a two out of four on the Electronic Frontier Foundation’s secure messaging scorecard. It lost points due to all of the issues it has had over the years with encryption, not having a way to identify the user and not having a well-documented security design.

In November 2014, the new owner of WhatsApp decided to take cards in the matter and made a partnership with Open Whisper Systems who planned on using TextSecure to enable this end-to-end encryption. TextSecure is a service that uses a cryptographic key that will make it unique in each device this way being the best way to protect its users.

Now

Image courtesy of El Taller del bit at Flickr.com
After launching this new encryption, especially during the debate on encryption occurring in the United States between private communication companies and the government, WhatsApp did comment saying: "While we recognize the important work of law enforcement in keeping people safe, efforts to weaken encryption risk exposing people's information to abuse from cyber criminals, hackers, and rogue states,"

On the FBI’s side there has been no comment on the WhatsApp new system, but they have said this in general about their position on encryption: "We must ensure both the fundamental right of people to engage in private communications as well as the protection of the public. ...We are seeing more and more cases where we believe significant evidence resides on a phone, a tablet, or a laptop -- evidence that may be the difference between an offender being convicted or acquitted. If we cannot access this evidence, it will have ongoing, significant impacts on our ability to identify, stop, and prosecute these offenders."

Tuesday, April 12, 2016

How to encrypt all your communications without being a security expert

Image courtesy of Christiann Colen

at Flickr.com
We live in an ever-connected world. Today we can access almost any service from our smartphones, desktops or laptops, in the comfort of our own home. And we do it casually, usually regardless of who we share the network with or if data is transmitted securely. So today we will take a look at how to encrypt all your communications without being a security expert.

We must combine two issues here: the first one is safety, and the second is usability -that is, the fact that something is simple to use, that it does not involve a delay in our communications and so on. The objective is to make communications secure in a transparent manner for the average user.


 Secure connections that are already encrypted even if you don’t know it

In many cases we are already using secure connections, where the traffic between one point, for example our computer, and another, such as the website of our bank, is already encrypted. We are talking about https connections that guarantee that the information is exchanged safely.

Normally those are the connections used by banks, but also by the servers of many email services to ensure that, even if the traffic between your computer and the server of the page that you entered to make any sort of query is intercepted, no one will have access to the information that was exchanged.


 VPN connections, a guarantee for our security

But not all pages use this communication protocol and often we want to maintain the privacy of our Internet communications. In these cases we can use a Virtual Private Network (VPN). Put simply, we could say that it is useful to connect two points safely, be it connecting to the Internet or accessing remotely to another computer.

To use it we have free and paid alternatives, going from services that only require a registration to use a VPN, to others in which we have to install an application, which is the most common practice in order to create the tunnel through which data will be transferred securely.

Once the application has been installed or the service has been accessed, navigation for users is the same as usual. This can be very interesting if you are connected to a public WiFi network where we share it with a lot of people and we want to keep our data safe.

Another use for VPNs is to access services that have a territorial restriction. For example if we want to access Netflix, Hulu other streaming sites from a foreign country. The connection is made between our device and the VPN servers, which are responsible for sending connection requests to these services, so the request is made from the place where they are located, thus avoiding territorial restrictions. This is very useful if you have to travel to a country that censors Internet access.


 Encryption of messages and voice calls

Not only must we protect Internet communications, but in some cases we may want our messages and voice calls to be encrypted as well. In these cases we can also do it very easily with applications such as Seecrypt, which is available for Android and iOS.

To use it, it is necessary that both users have the application installed in order to talk or exchange data, which greatly reduces the usability of the application. Anyway these apps slightly exceed the scope of an average user.


 Encrypting files easily

Sometimes we don’t mind the communications not being encrypted, but we do want to exchange protected files. In this case you can use encryption apps on a folder on your computer or mobile phone. Most operating systems today offer some encryption options and, if not, you can always resort to third party apps.

One of those apps can be run directly from a USB stick and it is called Toucan. Besides encrypting, it also allows us to create backups or synchronize folders between two devices. One advantage is that even if you access remotely to an online encrypted folder, running Toucan from a USB drive you can decrypt files by simply typing your password.


 Safe spaces in mobile devices

Image courtesy of Kārlis Dambrāns at Flickr.com
If you need to carry certain important files on your smartphone, such as a scanned copy of your ID or Social Security Number, you can create an encrypted folder in your SD card, for instance.

Depending on the type of smartphone that you have, you’ll be able to do this from the operating system itself, which is the case with certain Samsung devices. You can choose to encrypt a folder or even the entire device. The greatest part of this is that when it comes to using the phone, it will behave as if the files were not encrypted, but if you lose the phone it will not be accessible without a password.
As you can see, it is not necessary to be a security expert to have secure connections, it is enough with having the appropriate apps or access services that can provide a reliable connection, which give you peace of mind while surfing the web.

Monday, April 4, 2016

How to keep the privacy of your mobile communications

The apps that we use regularly on our mobile devices are not the most suitable channels for sharing sensitive information. If we want to protect the confidentiality of our communications, it is not recommended to use services like WhatsApp or plain old SMS.

Image courtesy of Chris Potter at Flickr.com
Users have recently become sensitized about the importance of the confidentiality of communications, and they have begun to consider the levels of privacy when choosing one service or another.

Google announced end-to-end encryption between Gmail users precisely to ensure the users of its service that their communications are safe. Following this path, browser extensions such as ShadowCrypt have emerged to encrypt messages, or projects like Dark Mail have been developed to implement a secure email system that is "immune" to espionage and unauthorized interferences.

If we consider that through regular phone conversations, or even through messaging services, we can exchange sensitive information, it makes sense that we take into consideration the privacy of our conversations and, therefore, we look for applications and services to ensure end-to-end encryption in the devices that we use daily.

Just because a service offers encryption between your phone and their servers, that does not guarantee the confidentiality of your communications. There must exist an "end to end" (from one terminal to another) encrypted channel, that is, our conversations should not be accessible on the servers of the service.

Another important detail is the possibility of auditing the services we use, if the source code is accessible, at least it can be reviewed by independent third parties to verify that the declared specifications are met and that there are no undeclared "hidden features".

Encrypted calls from your phone: Android and iOS


Fortunately, day by day there are more options available for both iOS and Android.

Signal is one of the products developed by Open Whisper Systems and it is designed to make secure phone calls between iOS devices, based on end-to-end encrypted communications.
Its usage is extremely simple: install the application and indicate your phone number. Then the application exports your address book to check which contacts use the service and, from there, you can call them.

If you have an Android device, the same company offers the RedPhone app, so you can also make voice calls over a secure communications channel, using your data plan or through a Wi-Fi network.

Signal and RedPhone are interoperable; therefore, from Signal you can make calls to RedPhone users and viceversa. In both cases, the app’s source code is available for audit and communications rely on the ZRTP secure protocol, so we can safely say it’s a reliable service.

Encrypted messaging on desktop and mobile devices


There are several options to protect our messages, some are very well known, such as Telegram, which has a secret chat mode and it offers end to end encryption, and with this option the conversations are not accessible from Telegram’s servers.

Another known and widespread option available on the market are Apple’s iMessage and FaceTime; available on OS X and iOS, these messaging and video calling services also provide end to end encryption but the source code is not available to third parties.

If we want to encrypt SMS, another alternative to communicate securely from Android is Text Secure, but it is only available for text messages.

On iOS, Signal includes both calls and text messages; but on Android you have to use two different apps: RedPhone for calls and Text Secure for text messages.

Image courtesy of Yuri Samoilov at Flickr.com
Another interesting service, which is also cross-platform, is CryptoCat. It is available for both iOS and desktop browsers, this text service allows you to encrypt messages that users exchange (they come out encrypted and are not decrypted until the information reaches the recipient) and it also is an open source project, so it can be audited to verify its functionality. In principle, the communication channel is safe, but the service is somewhat conservative and it clearly states that this is not an infallible tool that you should trust your life with.

BitTorrent has been developing a decentralized instant messaging system that does not depend on the cloud, making information flow directly between the users without having to go through intermediate servers. Bleep, which is the name of this service, intends to be a safe and decentralized alternative to WhatsApp or Telegram, offering end to end encryption and it is available on both iOS and Android.

The fact that communication takes place directly between the users and is also encrypted, place Bleep as one of the best options to consider when using an application to establish secure communications, since no intermediate servers are used.

Finally, users of Android devices should consider SureSpot, which is a sort of combination of WhatsApp and Snapchat with encrypted communications. The service allows you to exchange images, text or voice messages through a secure channel and the possibility to erase, at will, messages we have already sent, while maintaining control of the information we have exchanged. The SureSpot service relies on intermediate servers, therefore, that’s a factor to consider when evaluating its use.