Air Force Launches Encrypted IM Service
nomrniceguy writes "U.S. Air Force's Print News Today announces a new instant messaging service for enlisted people stationed abroad to communicate with their families and loved ones. Users cannot send images, audio or other documents through the system. Messages are also encrypted to prevent unauthorized access."
sounds like stripped version of skype ... or Jabber over ssl ;)
Exercise caution when modding this message up: the author acts like a jerk when his karma is excellent.
Can't send pictures, huh?
Anyone have a copy of uuencode laying around for them?
You can never go home again... but I guess you can shop there.
This will protect their vital messages such as HeY SeXaY and WhAt R U N2?
B a11 U /an B, |_o|_
Users cannot send images, audio or other documents through the system uue or yenc?
Mongrel News all the news that fits and froths
$5 says someone leaks it out and regular people try to use it as an encrypted messenger.
WASTE - The Secure P2P
They should be more worried about soliders posting their digital camera photos to public sites than what could be hacked through instant messages...
This instant messaging service has been in use for a couple of years now. However it was limited to military and contractors. Now it's open to family members. The airman has to sponsor you by entering in your email address, and then you receive login instructions.
How am I supposed to fit a pithy, relevant quote into 120 characters?
No media, huh? I guess that means we can go back to using our imaginations to visualize the horrors reported back by our soldiers abroad.
On a lighter note, it's nice to see that they will have an easily surveilled method to connect with family from abroad.
Does it run on Linux?
"I assumed blithely that there were no elves out there in the darkness"
What's wrong with Jabber, AIM, MSN, or any other chat medium? Sure they might not have encryption (unless the Jabber server has SSL enabled), but then again, I'm sure there's some rule that says that the soldiers shouldn't be sharing secrets or mission critical information with anyone but themselves...
...right? So why the need for encryption to keep the "I hope I'll be home soon, how's the family?" messages private? Unless I'm missing something...
So they get a less usefull im client (no pics etc)
Sure they get encryption, but i think that a plugin to gaim exist that can do this too.
So what is the benefit for the soldiers there?
The only one i can see is that they can chat with there families - wich they could do just as well with the myriad of other IMs already in existens.
Freedom or George Bush
I wonder how long untill there is a Trillian plugin for this. *rolls eyes*
Text only, eh? To the multitudes, I present two functions, base64_encode and base64_decode.
:-p
Email is still all text and probably always will be
Colin Dean Go a year without DRM
Maybe I'm way off base, but... with no support for file transfer or audio, won't most families and soldiers continue using the regular Instant Messenging programs?
Xierox
I guess that rules out links, w3m, and lynx.
Think it works with Firefox or Mozilla?
It would be interesting to know how secure the encryption really is. Traditional 128-bit SSL? And does the Air Force get to censor the communication?
InDaSandbox32: 141ac5c0563fc690672ae868777b7f57fcab77
USAGurl2005: 770a8a5fcab77aa5fe04fcab770d4e3c3211f
InDaSandbox32: a2f7a57d35ff48fc7d0
InDaSandbox32: f7a55fcabd4e3c5ff48fce868777b7
USAGurl2005: 5af75db86cef4f9090
http://www.af.mil.nyud.net:8090/news/story_print.a sp?storyID=123009448
No more nasty torture pics form Iraq!!!!!!
How encrypted is this? Can military censors read this? What's to stop someone blabbing about deployments or positions?
Computers are useless. They can only give you answers.
-- Pablo Picasso
Anyone know why the AF would come up with their own system? Is it just to be able to backdoor it for security reasons?
Agile Artisans
And yet they have blogs.
They state in the article that initially the users could chat to people on other IM networks, but the functionality was removed because these networks allowed users to send&recieve files etc.
So why the hell didn't they just disable this feature and keep the gateways in??
So USA wants to listen on our conversations, but they don't want us to listen in on theirs.
Supplied by akamai.com ?
a l. download.akamai.com/11372/DoD%20Warning%20Statemen t.htm
See the links throughout
http://www.my.af.mil/
to, for example (Privacy Policy)
http://a248.e.akamai.net/7/248/7850/v001/ftptri
Stephan
http://stephan.sugarmotor.org
No matter what kind of encryption technology they have implemented for their IM; if the soldiers are going to use the webbrowsers in cybercafes in the foreign land. Then god help them. I have been here in KSA (Kingdome of Saudi Arabia) for six month now. All the MS-Windows systems in cybercafes are full of spywares, keyloggers and whats not. Most of these problems due to administratative rights given to all the clients who need just a browser. No matter what technology one uses over netwrok but its very difficult to get rid off key loggers. After experiencing all that crap I bought a dial-up internet connections cards (Nesma and Zajoul)... both the connections are pretty slow for me though.. compared to my home country dial-up.. Now I can browse through Firefox with antivirus and personal firewall on.... Pretty safe feeling now. I get atleast one incoming connection to my system from the external internet every five minutes. I suspect these are from other dailup users(probably infected) only. Withought a firewall and unpatched MS-Windows system you will be a deadduck in hour or so. I think they should give them secure client machines also. That will help them in better way. I read about the massive bandwidht they are enjoying in this IRAQ war. If they are routed through their own satellites then nothing like it.
...it's called Gaim Encryption. Add that to Jabber over SSL (overkill, probably) and I've got secure conversations with my friends and family.
I wonder why that imposed that restriction. Surely not to prevent images of our wonderful superior American military boys raping and beating the shit out of innocent prisoners getting leaked? That could never happen!
The Air Force also has a webmail service they encourage servicemembers to use, as well. They block most other web-based email services.
but it sure sounds like an improvement considering the second gulf war was coordinated though.... microsoft comic chat... no really, you cant make stuff like this up!.(search for "alien" in the text... I kid you not!)
IRC, the protocol voted "script kiddies choice" for ten years in a row, is what powered the critical communication infrasteructure. Combined with a microsoft client that adds comic characters. Also the database used for collecting and assigning ground targets for bombers.... access.
Maybe they should use Secure Internet Live Conferencing (SILC)...
It may just be my copy of Firefox, but the link at the bottom of that article (to the actual AF website) throws up a dodgy server certificate warning.
There goes any hint of faith I may have had in this being secure.
How many people can read hex if only you and dead people can read hex?
Why don't you stop supporting broken non-standardness and start hounding the GAIM guys (or someone else) to write an encryption plug-in or system that actually works with other Jabber clients? Hell, why don't you get the GAIM people to actually make their client understand Jabber resources.
Jabber has support in the protocol for encrypting messages, GAIM and its plug-ins don't do this; they go their own route just like the Trillian folk. Don't support a system that ignores the standards, it makes things worse for everybody.
Airforce AIM-y
Somehow I don't think that this is really encrypted. Well... encrypted so that enemies can't intercept it, yes... but not encrypted so that the Air Force itself can't read what's being transmitted. Somehow I doubt they'd leave the risk of transmitting sensitive data with no way to see what's happening completely open to the entire Air Force.
- dshaw
I am in the Air Force, a 2E251, job title is "Computer, Network, Cryptographic, and Switching Systems Journyman". here is how i can best explain why it is encrypted and why we cannot use regular IM products (aim, icq, etc etc...) It isn't that classified or top secret messages are being transmitted across this system, it's simply to keep the enemy from deducing simple things and protecting the members families. Think of it this way, if you have 100 people from the same network ID talking about hopping on a plane for a "Big Mission" the enemy might beable to figure out what's going on. another good reason for encryption is so that when members are like, "Boy, i can't wait to go home for christmas and go to grandma's so and so's house this year" what's to keep enemy's/Terrorists from taking from there grandma's name, finding out where she lives, and then kidnaps her to black mail you, or just out right kill her to hurt the morale of all troops in the sand box. also, due to AFI regulations, regular IM programs are not authorized for use on Air Force Systems, plain and simple, for those exact security reasons. i was in Iraq/Oman for a while back in the summer of 03, and i used this program alot. Thank you all, and i hope this was useful.
President Bush Supporter
soldierman: Hey honey, I hope you and the kids are doing ok.
:p
:P
:D
:( *sighs*
wifeofsoldier: we're doing fine....the kids are kinda wound up tonight.
soldierman: well, tell them daddy said to behave.
wifeofsoldier: I will, make sure you keep safe...I'm worried about you.
soldierman: hang on a second honey,I hear something. brb
wifeofsoldier: ok.
soldierman: oh shit, the iraqi's are attacking!! they just bombed the base...
wifeofsoldier: oh shit LOL
5 minutes goes by
wifeofsoldier: BUZZ!
nothing
wifeofsoldier: BUZZ! where did you go?!?
nothing
wifeofsoldier: helloooooooooooooooooooooo?
wifeofsoldier: lol is this a joke or something?
nothing
wifeofsoldier: oh well, I wasn't gonna tell you the bad news now..but I've been talking to this one guy online since you left and I'm gonna move in with him since he got me pregnant.
wifeofsoldier: so, good luck and stuff
wifeofsoldier: bye
5 minutes later
soldierman: wtf?!? I get back and I see this shit....
nothing
soldierman: are you still there????
nothing
soldierman:
*soldierman has signed out*
He's absolutely right, giving out such simple info about a "Big Mission" a hundred times in an hour can give our enemies a simplified picture of something coming up. The biggest threat to our operational security is the internet, we have to be extra careful 24/7...
even when we're just talking to mom.
Thanks to all the people at slashdot.org that support us.... Happy Holidays to everybody.
Oh, just to clear something up. In the article that describes the military using Microsoft Chat... it's still on a secure network. If we get hacked through there.. we have a WAY bigger problem than just a simple virus. Read the article at wired.com for a clear picture of our secure network. It's a lot better than people give us credit. It's actually pretty damn amazing...
its just that american air force whanted a better way to filter theyr solders chat thats all, encryption is the bait for the solders to start using it.
This far into the discussion and no one's made an "AIM High!" joke yet? C'mon, people.
As an oriface I can send anything I like.
The IM client is Java based and from Bantu systems (v. 3.0.1.25) - see http://www.bantu.com or http://www.pcmag.com/article2/0,1759,1358228,00.as p
I'm in the airforce and we've had this now for almost a year, nothing really great about it :-/
Yeah, right!
This
How about if someone comes to your house and takes your children and rapes your wife. If you call 911 and I see AC on the ticket then I will go get a donout first.
...Messages are also encrypted to prevent unauthorized access.
does anybody know if the IMs are moderated by a security team in a similar manner to written letters to prevent servicemen and women from accidentally releasing sensitive information?
now, don't get me wrong, censorship is almost always bad, but in the military it is a necessary evil to prevent a mole from leaking information. this information would only be useful to a terrorist and be used to put our enlisted men and women in harms way.
Encryption is useless if one of the people on either end blabs something they shouldn't. Sensitive information should not be transmitted to family members. Period. In other words, the whole encryption thing is a bit pointless...
-- If you try to fail and succeed, which have you done? - Uli's moose
I'm in the air force and I actually get deployed to the base that this client was beta tested. things are pretty restricted there. Here's a synopsis of what it is like.
being that going off base to go to cyber cafes and use the internet there is really not reaslistic to do everyday, maybe not even once a month, our only choice is to use the internet connection provided on base. Don't get me wront i think it's great for them to give us this luxury in a war zone, but we get the internet through the local internet companies and there is also this filter called "websense" which filters out half of the internet. most people who have a desk job have a computer thats hooked up to the internet. there is also a place where any joe blow airman can go to and use a computer for a timed 20 minutes (sometimes when it wasn't buisy the people there would let you stay on as long as you want).
There is another option which alot of people dread and thats to get internet in your room (trailer room really.) This sounds nice, however, the same restrictions that apply to the base apply to your computer in your room. Not only that but before you can get on the network you need to give up your computer (usually a laptop) for a week or so, so the computer guys can wipe your Hard drive clean and install windows xp, and set it all up so that you only have basic user rights.
So all the email from back in the states is blocked off, you can't install any programs, well you could but after you get your computer back from the computer guys it pretty much a government computer hooked up to a government system, and doing anything to comprimise security of the system would mean trouble for you, and I'm not talking about a letter from your ISP trouble either. I'm sure there's ways around this, i have a few ideas myself, but i would rather not ruin my carrer over this.
Anyways to make a long story short, the only i could get in contact with my girlfriend and family (besides my 2 15 minute phone calls per week) was through the Email that was given to me and goes through the base exchange server.
I tried using the email like a IM, the only thing is it is not very reliable, that is there would be some times where i would be talking away and nothing for a half and hour and then boom, like 20 messages all at once. not to mention times when the server is actually down. It got to be pretty flustering after a while.
I know that when I'm deployed I'm at war, and things like this make the air force pretty spoiled, and resented by the other services, but hey, That's why i joined the air force.
bottom line is I think this is a great service for us and I can't express how grateful i am for this. I hope that this will spread throughout all the military.
Actually, the reason they more likely had in mind was incidents like this.
Web-based, SSL encrypted system. I've personally used it and find it sub-par. It's not designed to compete with AIM, et al. It can't.
What it does have going for it is that the AF has tight control over its network. You can't install MSN messenger, AIM, YIM, Trillian etc. without getting picked up by the admins. And the ports are already blocked. Being a web-based client, it doesn't require an installation, nor does it take up any extra ports.
Regarding encryption and monitoring, the AF can monitor, but don't assume it does. There's enough going on without bothering to sort through every love not and chat conversation between Airman Snuffy and his girl. If there's reason to suspect espionage, it'll be watched. But if any info is going out through this hunk of dren called Bantu, I'd be surprised.
Honestly, it's no big news inside the AF. The Air Force Portal (my.af.mil) has enjoyed some success, but it's still a solution looking for a problem in some ways.
Essentially UNIX talk (or ntalk), over an SSH tunnel?
Kinda sad.
/~mikeg
The testing and certification process is so onerous and lengthy (up to 10 years) that a system can be hopelessly obsolete by the time it finally is certified, if it makes it. Then there's the abuse of the labels "classified", "secret", and so forth to cover up problems. Known flaws in security related software are often kept secret from everyone-- enemies, rival companies, critics and auditors and security experts, not to mention the users. Very convenient for the vendors and their sponsors. Diebold security anyone?
There is the paranoid refusal to use something just because it's from outside the US-- it might have malicious code. And there are the export controls that try to keep technology in the US, implicitly assuming the US is the leader in this area. Ironic that the effect is the loss of US leadership as experts set up elsewhere (OpenBSD in Canada, for example).
And if all that isn't bad enough, the military pushes this idea of responsibility, as in "held responsible" and possibly even sent to jail should any breach in security occur. That makes military base system admins very conservative and risk adverse.
Intellectual Property is a monopolistic, selfish, and defective concept. It is "tyranny over the mind of man"
Re-inventing the wheel at tax-payers' expense
is not my idea of frugal gov't use of tax $'s
I'd have jumped on the Skype bandwagon; it rocks for free!
http://www.jabber.com/index.cgi?CONTENT_ID=460 I reckon this is Jabber Incs technology which they licenced recently to USJFCOM. If it's not well I'll be wrong! Fairy
OS, Web Server and Hosting History for www.my.af.mil
http://www.my.af.mil was running AkamaiGHost on Linux when last queried at 24-Dec-2004 05:38:53 GMT
Will this new instant message service perhaps be named IcbM?
Yes, it's encrypted.
The actual conversation itself is encrypted, but the traffic passes through the AF central message server, where it's decrypted and read by analysis software. If any keywords pop up, *then* it will be flagged for an operator to examine and determine if they need to intervene or cut off the conversation.
The monitoring software and the hardware supporing it is incredibly fast. You never notice the delay.
Once the text is approved by the software at the central server, it's then passed to the NIPR servers and sent over the NIPRnet. The NIPRnet is passed to trunks encrypted using FASTLANES, but they're upgrading to TACLANES, which have a much higher capacity and more goodies, and can be trusted for use in a tactical environment, where equipment not only needs to be hardend, but electronically destroyed quickly and easily.
All NIPR trunks pass to a SATCOM link, which then gets passed to one of the three NCTAMS, DISA or other communications stations, where it's decrypted and passed to their internal networks. From there, all traffic is copied and the copied traffic sent to the spooks for analysis, while the original signals proceed to their destination.
ALL of it. Every single one and zero is monitored. As you can imagine, this level of monitoring engenders it's own problems, but understand that it *IS* monitored.
If you do something stupid, it may take a while before you're caught, depending on what you're trying to do. If you're stupid, you'll get balled out by your chain of command and lose your priviledges. If you're smart-or just THINK you are-then they will watch you in silence, monitoring your every single move, as well as everything being done by those you're talking to.
If you are *really* smart, you will stick to snail-mail. THAT is something they don't have the time or the manpower to read, and it all just passes through the system, mostly ignored. Occassionally, they will open a few hundred letters to make a stab at things, see if anyone is being blatantly obvious or trying to use some sort of cipher.
But because everyone is so keen on "instant communication", the chances of someone going for a written letter instead of instant gratification are low. They have the bait and know where to find the fish.
And it used to work. -- Alejandro Escalante Medina http://alexdinamo.homeip.net/weblog
This isn't about WWII type security. This is about GWII where unwanted pictures have spread around and appeared in newspapers. Very embarassing for both the military and the government.
See my journal, I write things there
anything that it can't decode in real-time (or in the future via archives) for any given use.
As for the suggestion to use UU en/decode or other binary-to-text converters: It's potential use was most probably thought of, which in turn would prompt the creation of a script that would scan through and moderate (or flag for review by IT personnel) those messages which contained headers for programs such as UUencode, PGP, etc.
Like every system, there will always be ways around its security measures. However, there should be no reason why the terminals being used by the soldiers can't be kept free of spyware, keyloggers, and the like (ie. re-imaging workstations at the end of the day.) Either way, the military brass will still have access to the information being sent by soldiers, but would severely limit access to information (and thereby its abuse) by those outside of the group charged with running the system.
God bless the men and women of the United States Armed Forces!!