Protecting IM From Big Brother
holden writes "Ian Goldberg, leading security researcher, professor at the University of Waterloo, and co-creator of the Off-the-Record Messaging (OTR) protocol recently gave a talk on protecting your IM conversations. He discusses OTR and its importance in today's world of warrant-less wire tapping. OTR users benefit from being able to have truly private conversations over IM by using encryption to obtain authentication, deniability, and perfect forward secrecy, while working within their existing IM infrastructure. With the recent NSA wiretapping activities and increasing Big Brother presence, security and OTR are increasingly important. An avi of the talk is available by http as well as by bittorrent and a bunch of other formats."
Its time to implement encryption of ALL traffic from ALL applications. Perhaps even IPC encryption incase you have some sort of 'tap' installed on your computer.
Sure, it eats resources, but do you want others reading your information? I dont. Not even when its "we are out of milk, please pick some up on the way home", as its NONE OF THEIR BUSINESS.
---- Booth was a patriot ----
This is a good step, and I wish that more people would use encrypted messaging systems. This includes IM, e-mail, and voice.
However, while encryption can protect against "big brother", you can never eliminate the risk from the other end of the line. What happens if the person you are talking to has a rootkit, or prints out the conversation, or otherwise compromises the data? There's no real way to protect your entire conversation.
--
Educational microcontroller kits for the digital generation -- great gift!
Fine, let me get those chips out for you. Bring the back after you get the information off of them.
Quote: "With the recent NSA wiretapping activities and increasing Big Brother presence, security and OTR are increasingly important."
The real problem is U.S. government corruption. See this example from Cooperative Research, a complete 911 Timeline of 3962 events: U.S. Government corruption TimeLines.
The government should serve the people, not spy on them.
Isn't EVERYONE very upset that we need these types of applications these days? Why does it seem reasonable that EVERYONE needs to hide their communications from their own governments? Shouldn't we be more upset that things have gotten so out of hand?
Except that it's completely untrustworthy because it's non-free software. If a major feature of the software is that you can trust it to keep your secrets or protect your privacy, you should be able to trust that it's only going to do what you want it to do. Non-free software inherently doesn't work this way, so none of it is useful for encryption. This program disallows modification, so if you discover that it doesn't do what you want you have no permission to make it do what you want. Forget about helping your community by distributing improved versions of the program: distribution is only allowed gratis and if one distributes the software they distributed to you in its original (software) packaging.
The license for the program is so over-the-top in its restriction it's laughable. It claims to prohibit talking about the software (section 3.a.iv). Users are prohibited from any translation or localization of the software as well (section 3.a.i), so if the interface isn't in your language you're out of luck.
The solution is simple: use only free software, relish your software freedom, help your community by distributing free software, and encrypt your communications to your heart's content. This way only your limitations keep you from fully understanding what your computer is doing with your data and you can draw on the talents of other trustworthy people to help you whenever you need their assistance.
Digital Citizen
I have four sets of keys on my machine--keys for SSH, for PGP, for WASTE and for OTR. Why does every app using encryption insist on using its own wrappers for public keys? What's wrong with the infrastructure already present in the OpenPGP standards?
Laws do not persuade just because they threaten. --Seneca