Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Tuesday, August 23, 2016

Threema, a messaging app that cares about your privacy

Image courtesy of Dr. Motte at Flickr.com
Telegram is surely the app that we usually resort to in order to demonstrate how an app can offer a very high level of security and privacy to its users, with certain characteristics such as end-to-end encryption and secure chats that take to the next level the fact that we can feel safe when we take part in a conversation with sensitive information. The developers of Telegram have struck a chord with a need that came from millions of users after the events that took place with Edward Snowden and the NSA.

Now we have another application that follows this path and that presents itself as one of the most secure ones to stay out of reach from hackers, corporations and government agencies, and, once and for all, it can be used in a completely anonymous way.

The app is called Threema and we could say that it's the opposite to the ones that we use everyday -such as WhatsApp- in terms of security and privacy.


Security comes first


Telegram is a big bet, and so is Line with the implementation of end-to-end encryption. WhatsApp would later adopt this method, though a bit later than its competitors. If we want to jump to the next level, we’ll get to Threema. It's not a free app, something that some users may not like, but those who want to have access to certain privacy and security features will shortly find in it a great destination for completely anonymous conversations.

Threema is an app developed by a company in Switzerland that has been endorsed by the German government. The servers are located in Switzerland as well and we could say that it’s one of the countries that cares the most about users’ safety and privacy.


With that being said, these servers will only store the minimal amount of information, and the users’ devices will act as clients and servers. The Swiss servers will only act as intermediaries to transfer information from one device to the other. Said information, will be encrypted.


Anti-hacker encryption

Image courtesy of  Melina Sampaio Manfrinatti at Flickr.com

Without a doubt, announcing that it will be impossible for hackers to access your private information will be an attractive statement to them, but this is due to an encryption method based in the open-source library NACl (Networking and Cryptography library). This is why in order to impede copies of information or unauthorized backdoor accesses, the encryption keys are generated and stored securely in the devices of the users, as we mentioned before. 

Threema has stated that group subscriptions and contact lists are only managed from the user’s device. Once the messages have been delivered, they delete themselves so that the files that remain locally will stay, encrypted, within the smartphone or tablet.

The following are several of Threema’s features:

  • Text messages and voice messages 
  • Sending of all kinds of files: PDF, GIF, MP3, Doc, ZIP and so on.
  • Sending images and video and the ability to share your location.
  • Group chats in which new members can be deleted at any time.
  • ID verification of contacts through personal QR codes.
It’s also worth noting that Threema doesn't require the use of a phone number or an email address. Each user receives a random ID from Threema to identify themselves.

You may not find many of your contacts with it, but it's only a matter of time. It also has a specific function in terms of privacy which differentiates it completely from other apps.

The company that created Threema is made out of -you guessed it- three employees. The startup managed in just 24 hours to double the size of their user base and the app got to the first place in the charts of paid apps in Germany.

Threema combines components of social networking with some of them coming from messaging apps and, on the other hand, apps aimed towards customization. Anonymity is definitely a key factor around which the app revolves.

The German government endorsed the usage of alternative apps for private communications. The app also allows you to find other users by syncing your contacts, but this step is completely optional. You can also share information such as your location on a map, all without leaving the app. If you want, you can exclude individual contacts from the sync process, it features an internal image viewer, a contact list that can be classified according to your needs, blocking of individual contacts, quick switching between different chat conversations, custom nicknames for unknown contacts and several other useful features that will help you keep your conversations away from eavesdroppers.

Even though it doesn't feature the option of voice calling, users can send voice messages. It's available for iOS and Android, and it’s a little less expensive if you have a Windows phone.

Related content

Read Don Burns' "The importance of cryptography in points of sale"

Sunday, May 15, 2016

Encrypted Communication Popular in our Day

Image courtesy of brewbooks at Flickr.com
After the major cases of data leakage and hacking of information, more and more individuals, companies, and government entities are looking for solutions to protect their privacy and their deepest secrets. 

The truth is that encrypted communication has always been present. The romans, for example, used encrypted messages to protect information that dealt with military content and to communicate during battles. Caesar was the one to be acknowledged as the first user of this system. That encrypted method was called “Caesar cipher” and it consisted of a strategy where each letter in a message was replaced by another letter, which was changed some places forward in the alphabet. However, it is believed that before him encrypted communication by substitution had already been used.

Before, encryption was mainly exclusive for departments and people in charge of the defense of a nation. Nowadays, companies and individuals want to know more about this technology and start implementing it in their daily communicative exchanges.


Why is it important?

Any communication that takes place in the internet is unencrypted. This means that if there is a malicious user that wants to “spy” the communication between the sender of a message and its recipient, this user is able to access information from this communication, and know exactly what is being transmitted. This fact can have more relevance according to the level of exclusiveness or secrecy of the information. If we were checking out web pages about the latest hairstyles, that would be irrelevant to security. But if we were accessing or providing our bank account information, that is a different story. 
Image courtesy of EFF Photos at Flickr.com

To avoid these sorts of situations, there is a technical solution that protects communication through encryption. Any kind of information can be encrypted. From web pages access information, to e-mails, etc. Encrypting information nowadays is an area of expertise that protects information using mathematics, computer science and engineering approaches.

The benefits of encrypted communication should be used specially in those interactions that transmit sensitive data. These might include passwords, personal information, financial records, etc. Security in this context means to perform communication in ways that does not allow a third party to access, read or listen to the communication session. The ways to protect internet communication can take the following forms:
  • Protecting the content: hiding information or digital data.
  • Protecting individuals performing communication: anonymity
  • Protecting the communication environment: approaches to hide communication environment. 

The Case of WhatsApp

Recently, Whatsapp proved people its concern about protecting its users’ privacy. Its latest update informed the community about the implementation of a new technology where users can talk to friends, family and acquaintances and their communication will be encrypted. This unprecedented action stirred a desire in people to understand more about encryption and to be concerned more about their online privacy.

This newfound concern about online privacy on the web is valid for companies as well. There are many tools and encrypted technology systems for companies that allow organizations to take control over sensitive data, information access and communications policies.

Whatsapp case poses a question, if encryption should be applied to all communications. The truth of the matter is that it entirely depends on the nature of the information that is handled. Companies should identify their key issues and sensitive data that need to be protected and differentiated from trivial, harmless communication. Identification is key to developing policies and strategies for managing data. After the implementation of a communication action plan, raising awareness is crucial for educating personnel about the importance of handling information in a safe way, following the company policies.

Final Considerations

Encryption mechanisms have always existed and will continue existing, whether it is for companies, government agencies or individuals that want to protect valuable information. Recent cases of information leakage have raised awareness of the need for information privacy and protection both in public and private communications. Security in this sense means protecting information or digital data from any sort of attacking techniques, technologies or methods controlled by malicious users.

To sum up, advances in cryptography are offering strong enough protection for most of our e-mail communications, online transactions and valuable information, but the future is still uncertain in the changing face of technology because, when stronger cryptographic systems appear, new means to break them appear as well. The hope is that with the ongoing developments in this area, attacks and security breaking will be exponentially reduced if not eradicated. That is why more research and work needs to take place to take security measures one step further from malicious users and technologies against online privacy. The human factor is still critical in the effectiveness of all security applications and systems. The constant reinvention of online communications privacy still continues.

Monday, April 4, 2016

How to keep the privacy of your mobile communications

The apps that we use regularly on our mobile devices are not the most suitable channels for sharing sensitive information. If we want to protect the confidentiality of our communications, it is not recommended to use services like WhatsApp or plain old SMS.

Image courtesy of Chris Potter at Flickr.com
Users have recently become sensitized about the importance of the confidentiality of communications, and they have begun to consider the levels of privacy when choosing one service or another.

Google announced end-to-end encryption between Gmail users precisely to ensure the users of its service that their communications are safe. Following this path, browser extensions such as ShadowCrypt have emerged to encrypt messages, or projects like Dark Mail have been developed to implement a secure email system that is "immune" to espionage and unauthorized interferences.

If we consider that through regular phone conversations, or even through messaging services, we can exchange sensitive information, it makes sense that we take into consideration the privacy of our conversations and, therefore, we look for applications and services to ensure end-to-end encryption in the devices that we use daily.

Just because a service offers encryption between your phone and their servers, that does not guarantee the confidentiality of your communications. There must exist an "end to end" (from one terminal to another) encrypted channel, that is, our conversations should not be accessible on the servers of the service.

Another important detail is the possibility of auditing the services we use, if the source code is accessible, at least it can be reviewed by independent third parties to verify that the declared specifications are met and that there are no undeclared "hidden features".

Encrypted calls from your phone: Android and iOS


Fortunately, day by day there are more options available for both iOS and Android.

Signal is one of the products developed by Open Whisper Systems and it is designed to make secure phone calls between iOS devices, based on end-to-end encrypted communications.
Its usage is extremely simple: install the application and indicate your phone number. Then the application exports your address book to check which contacts use the service and, from there, you can call them.

If you have an Android device, the same company offers the RedPhone app, so you can also make voice calls over a secure communications channel, using your data plan or through a Wi-Fi network.

Signal and RedPhone are interoperable; therefore, from Signal you can make calls to RedPhone users and viceversa. In both cases, the app’s source code is available for audit and communications rely on the ZRTP secure protocol, so we can safely say it’s a reliable service.

Encrypted messaging on desktop and mobile devices


There are several options to protect our messages, some are very well known, such as Telegram, which has a secret chat mode and it offers end to end encryption, and with this option the conversations are not accessible from Telegram’s servers.

Another known and widespread option available on the market are Apple’s iMessage and FaceTime; available on OS X and iOS, these messaging and video calling services also provide end to end encryption but the source code is not available to third parties.

If we want to encrypt SMS, another alternative to communicate securely from Android is Text Secure, but it is only available for text messages.

On iOS, Signal includes both calls and text messages; but on Android you have to use two different apps: RedPhone for calls and Text Secure for text messages.

Image courtesy of Yuri Samoilov at Flickr.com
Another interesting service, which is also cross-platform, is CryptoCat. It is available for both iOS and desktop browsers, this text service allows you to encrypt messages that users exchange (they come out encrypted and are not decrypted until the information reaches the recipient) and it also is an open source project, so it can be audited to verify its functionality. In principle, the communication channel is safe, but the service is somewhat conservative and it clearly states that this is not an infallible tool that you should trust your life with.

BitTorrent has been developing a decentralized instant messaging system that does not depend on the cloud, making information flow directly between the users without having to go through intermediate servers. Bleep, which is the name of this service, intends to be a safe and decentralized alternative to WhatsApp or Telegram, offering end to end encryption and it is available on both iOS and Android.

The fact that communication takes place directly between the users and is also encrypted, place Bleep as one of the best options to consider when using an application to establish secure communications, since no intermediate servers are used.

Finally, users of Android devices should consider SureSpot, which is a sort of combination of WhatsApp and Snapchat with encrypted communications. The service allows you to exchange images, text or voice messages through a secure channel and the possibility to erase, at will, messages we have already sent, while maintaining control of the information we have exchanged. The SureSpot service relies on intermediate servers, therefore, that’s a factor to consider when evaluating its use.

Monday, March 14, 2016

Encryption Software at the Heart of Apple’s Battle with Government

A San Bernardino couple launched a deadly attack at a government rehabilitation center on December 2, 2015 that resulted in 14 deaths and more than 21 injuries. Aside from the firearms used, the cell phones of the suspects were the subject of intense law enforcement scrutiny. In order to determine a motive, investigators sifted through shipping records; interviewed co-workers, neighbors, and family; and even combed the suspects’ social media posts.

To date, federal investigators have been unable to get their hands on any information contained in the smartphone of suspect Syed Rizwan Farook due to Apple’s refusal to allow access to the server. The FBI issued a warrant for the data contained in Farook’s phone, but received a flat-out refusal from Apple. Apple cites privacy concerns that go beyond individual users and asserts that accessing data cannot be accomplished without potentially compromising the data security of millions of iPhone users.

How Apple Approaches User Privacy

In addition to the built-in encryption software, Apple has gone to great lengths to increase privacy from the user’s end. There is a two-step verification process that requires users to enter their Apple ID credentials for functions like making purchases, making account changes, or setting up a new device. In the event that an iPhone is lost or stolen, a user can access their iCloud account from another device and remotely lock the device to prevent information from being accessed. Remote Wipe allows users to completely erase data from the iPhone should it end up in the wrong hands.

Apple uses what are called tokens to transmit and store encrypted data on its iPhones. Tokens store information on the phone itself and on Apple’s servers, as well as in the cloud (Apple’s proprietary cloud software is called iCloud). The data is subject to high-level encryption that obscures credit cards stored in Apple Pay and passwords stored in Apple’s Keychain and emails, just to name a few.

These privacy features are so secure that Apple asserts that it cannot directly access the information stored on a user’s iPhone. While this eases fears of prying eyes accessing sensitive information, it presents a huge problem when law enforcement has a legitimate need to access phone data during an investigation.

Apple’s Encryption Software

Apple devices have been praised for their high level of security and the encryption in its devices. Although no device is 100% safe from unauthorized data access, Apple has gone to great lengths to protect user information. In fact, Apple’s encryption software is at the heart of the conflict with the FBI.

As details began to emerge about the San Bernardino shooters, officials attempted to access the data in Farook’s iPhone but thanks to encryption software it proved impossible. Apple’s software ensured that the phone’s data would be permanently erased after several unsuccessful password attempts. Once the FBI was made aware of how the data encryption software functions, it was compelled to request the data from Apple directly.

Apple CEO Tim Cook insists that the encryption software is so secure that the company itself cannot even access the information. Cook stated that in order to access data from any user’s phone, the code for the company’s encryption software would have to be completely rewritten. This would not only be a major undertaking for Apple, but it would essentially open the door to every iPhone owner’s personal information.

While this is certainly not the first time that Apple has been ordered by a court to unlock an iPhone, it is one of the first instances since the company rolled out the iOS 8 update in 2014. The update included encryption software that cannot be accessed by a third party or Apple. Previous iOS versions could be accessed in certain circumstances, especially when law enforcement requested the information. The update came on the heels of widely publicized iPhone data leaks – some of which involved celebrity photos – so Apple had a lot at stake and sought to quell criticism of its privacy protection efforts.

Current Issues

Although the company has cooperated with law enforcement in the past, Apple does not make it easy to access information, and each request is reviewed on a case-by-case basis, even if a search warrant is issued. According to the Apple website, “National security-related requests are not considered Device Requests or Account Requests and are reported in a separate category,” which may change the way that Apple handles requests similar to the ones related to the San Bernardino case.

Going forward, it’s uncertain if Apple will find a way to comply with the federal government’s request for information. The FBI is losing patience with Apple and has accused it of sympathizing with terrorists. In 2014, Cook said "[We] have never worked with any government agency from any country to create a backdoor in any of our products or services. We have also never allowed access to our servers. And we never will."

It appears Apple’s stance has not changed since then. Just last week, Los Angeles Court Magistrate Sheri Pym ordered Apple to allow the federal government access to Farook’s iPhone data. The order asks Apple to supply the federal government with software that would enable it to access data, but so far Apple is holding firm in its stance and has refused.