Slashdot Mirror


Safeguarding Data From Big Brother Sven?

An anonymous reader writes "Now that the Swedish government (in its infinite wisdom) has passed a law allowing them to monitor email traffic, a question that I think a lot of people are asking (or at least should be asking) is: 'What can I do to improve my privacy?' The answer is not obvious. So, what are the best solutions for seamless email encryption, search privacy, etc? What are your experiences with PGP vs GPG vs ...? In this day and age, why is the use of this type of privacy technologies still so limited? Why isn't there a larger movement promoting the use of privacy tools? Also, what is in your opinion the largest privacy concern? Search tracking? Email transfer? I believe this is an interesting question not only for Swedes, but for everyone. Lots of traffic is passing through Sweden, but more importantly, the Swedish government is not alone in using this type of surveillance." Reader j1976 writes with a related question: "For most users with email addresses within large organizations, implementing their own email encryption scheme is not feasible, partly because of the technological aspects, but also since users in organizations often do not have administrative access to their workstations. What can an organization do, centrally, to lift the burden of encryption from the users? Are there any transparent schemes for email encryption which could be installed for the organization as a whole?"

20 of 345 comments (clear)

  1. Secure tunnels by Gandalf_the_Beardy · · Score: 5, Interesting

    Many of the financial service companies I contracted for have only been sending sensitive mail to maybe a half dozen clients. It's reasonably easy if the two IT departments get together to establish secure tunnels at the organisation level for transferring mail between them. Doesn't protect the mail outside these of course but it's a reasonably quick solution and effective if enforced with policies within the workgroup about what is and isn't permissible in an email. Requires no extra software and is easy to set up and manage.

  2. SMTP over SSL by Skapare · · Score: 4, Interesting

    One of the things we need to add is SMTP over SSL. It won't prevent all snooping, but at least between 2 people that trust each other, no snooping happens on the path between.

    --
    now we need to go OSS in diesel cars
    1. Re:SMTP over SSL by Z00L00K · · Score: 5, Informative
      That part is actually relatively easy - and you have to remember to also implement IMAPS and POP3S - and close the IMAP and POP3 services.

      I have already implemented SMTPS, IMAPS and POP3S a few years ago. And it's actually not really necessary to buy a certificate if you are doing this for a closed group. Just use OpenSSL and generate your own certificate.

      To send emails to others both ends have to buy an email certificate, like from Verisign.

      And then some of those who voted for this law thought that encryption is very easy to crack - so easy that it doesn't matter if an email is encrypted or not. The problem with cracking encryption is that you first have to figure out which one it is - and the history is full of encryption techniques.

      So in the end - this law will be a good promotor for encryption more than anything else and the monitors can continue to search with Google and not get a bit of useful information from the real criminals and terrorists.

      --
      If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
  3. On NPR... by Illbay · · Score: 4, Insightful

    ...(Of all places) there was a pretty good segment this morning regarding email encryption, even including a short interview with Phil Zimmerman. What was VERY interesting about it, to me, was the attitudes of the "man / woman in the internet cafe'" interviews they did, and how most people just "didn't care" about privacy issues regarding email. One fellow naively stated "I try to live my life in such a way that no one would have an issue with what I do." In my opinion, though, what YOU or I might consider innocuous might garner unwanted attention from government. As we are headed seemingly toward a more "European" philosophy here in the USA where the government assumes the duties of "personal watchdog" over your "lifestyle," what you eat, what you drink or smoke, what you teach your kids, etc., this would seem to be a foolhardy attitude.

    --
    Any technology distinguishable from magic is insufficiently advanced.
    1. Re:On NPR... by bsDaemon · · Score: 4, Interesting

      The rest of his comment implies that he tends to the right of center -- an area of the political spectrum where NPR is not exactly loved and any information which backs up their preconceived notions, no matter what the topic is, is viewed as being "out of place."

      Of course, I used to be one of those people, too. I started out listening to NPR because I liked classical and jazz music... eventually the news wore on me and I realized that I had been sort of a dick prior. Now I really like NPR news.

    2. Re:On NPR... by k1e0x · · Score: 5, Interesting

      That is absolutely right.

      The 4th Amendment was written in response to the Stamp Act. Under the Stamp Act of 1765, all documents in your possession required the kings stamp on them to be legal. You had to by the stamps so this was in effect a tax.. the really ugly part of this law that people do not seem to know is that under the Stamp Act, British soldiers could come into your house any time they wanted to check your documents with what was known as a "writ of assistance". This is in effect a search warrant that British soldiers could write themselves. (It is akin to the NSA's National Security Letter as well..). Upon rummaging through your home, if you could not also prove that you paid taxes on other items such as your furniture or even your tea and your rum, they could arrest you.

      Privacy is a property right, you are in your right not to show your property to anyone. This becomes all the more dangerous in a society of data mining and government provided "universal health care" because the government may decide you do not work out enough or your diet is not proper.

      Don't think it can't happen.. In Japan the legal wast size is 33.5 inches. http://www.nytimes.com/2008/06/13/world/asia/13fat.html?_r=1&em&ex=1213588800&en=b5472f5ba2e31e50&ei=5087%0A&oref=slogin Anything over that and you may be sent to "re-education". If you deny "re-education" you may even be arrested for being fat.

      --
      Bringing liberty to the masses. - http://freetalklive.com/
  4. Re:Someone please remind me... by Anonymous Coward · · Score: 4, Insightful

    Because no matter what country you live in some of your Internet traffic is likely to pass through Sweden. They snoop and tell your government about your stash of __________ (insert your own illegal/grey market goods etc. here). Wala - your government has "proof" you are engaged in illegal activity and busts down your door. Moreover, you apparently haven't been watching the news regarding the change in behavior people exhibit when they know/think they are being watched.

  5. Sweden's just being honest about it by Hektor_Troy · · Score: 4, Interesting

    I think we're rather naïve if we believe, that Sweden is the only country in the Western world to do this. They're just (one of) the first to be honest about it.

    As the submitter points out, you cannot be sure where your data is being sent on the route between you and your recipient. For all you know your "Dear Mom" email might go through Sweden, the US, the UK, Denmark, Russia and China even though you live within 50 km of eachother.

    And your Skype call? Well, that's likely to do the same thing with its routing feature.

    Your SSL connection isn't any safer from snooping - not sure about MitM attacks, but if you're just listening in, do you really need to be a MitM?

    --
    We do not live in the 21st century. We live in the 20 second century.
  6. Why can't it be simple. by k1e0x · · Score: 4, Interesting

    I use s/mime and gpg. I have for years.. but I believe this is too much of a hassle for people who can't even figure out Yahoo Mail or tell the difference between Internet Explorer and Firefox.

    Some time ago I suggested someone write a thunderbird extension that was a "one click" encryption setup. On clicking "encrypt" it would create a gpg key > send the pub key to a key server > and if it does not have someone elses key it can suggest thunderbird and itself to that person.

    I know this is not a good way to do this, but I can't see people using pgp/gpg it any other way.

    --
    Bringing liberty to the masses. - http://freetalklive.com/
    1. Re:Why can't it be simple. by ahugenerd · · Score: 5, Informative

      You have it backwards. Your public key is used to encrypt messages that are being sent TO you, which you can then only decrypt with your master key. The idea is that you (Alice) would send your message encrypted with Bob's public key to Bob. Since only Bob has his own master key (since it doesn't get posted to the server), then only Bob can decrypt it. Bob would then reply to you by encrypting his message with your public key. And so on.

    2. Re:Why can't it be simple. by Godji · · Score: 4, Informative

      The public key server only holds your public key - the one that was meant for anyone to see. Your private key, which is the only one that can be used to decrypt messages addressed to you, stays with you. Nobody other than the parties involved in the communication ever holds one or the other's private keys.

      The "public" in "public key server" means BOTH that the key server is public AND that it is a server for public keys. The most anal-retentive name for it would be a "public public key server".

      See http://en.wikipedia.org/wiki/Public-key_cryptography for all the details.

  7. Too complex by croftj · · Score: 4, Insightful

    It's too complex for most. If it were as simple as me putting code on my machine and sending encrypted emails to my family and friends I would do it. Sadly, I have to step them ALL though putting GPG or PGP onto their machines, creating a pair of keys then sending my and all of their friends their public key. Want to place bets how many of them would send their private key themselves?

          If MS would simplify it and make all of this just happen. I bet that there would be a big gaping hole for the gov't to make use of. Not to mention the security holes that would go along with it as well.

    --
    -- Many men would appreciate a woman's mind more if they could fondle it
  8. Why not make the government's job easier by bigtrike · · Score: 4, Funny

    And CC all of your email to the everyone in charge of this agency. Any good patriot should do this, just be sure the nation is secure even if the email monitoring system goes down.

  9. Seamless, no. Pretty darn close, yes. by querist · · Score: 4, Informative

    There is no "seamless" encryption method that will give you enough protection. Sorry.

    However, there are plenty of options if you're willing to do just a little work.

    Install GPG or PGP. I use GPG because I can give it away legally to my friends who are less technically saavy and it works on Linux, OS X, and Windows.

    Enigmail will integrate nicely into Mozilla's emailer and automate nearly everything once you have the person's public key. It will even notice who your recipient is and automatically pick the correct key.

    There is something similar for the OS X Mail application (and I have it installed) but I don't remember the name of the application. It's not as bright as Enigmail and won't figure out who the recepient is automatically and pick the correct key.

    FireGPG is a plug-in for FireFox (and it works for "Mozilla" because the web browser _is_ FireFox) that will allow you to use GPG with GMail.

    I have an email account in which _all_ of the traffic is encrypted because I use these tools. I never send anything unencrypted on that account.

    It's not seamless, but it's not that hard and it is not very intrusive.

    I do not know if I should pity you because of your government reading your emails or if I should at least feel happy for you that they are honest enough to admit it (supposedly) before starting. Either way, I doubt things are any better here in the USA.

    I find it amusing that the CAPTCHA is "incided", as in this new law inciting a riot.

  10. Well as Phil Z. has said.. by X86BSD · · Score: 4, Insightful

    The reason PGP, and GPG as well, fail is because PKI is just too difficult to setup and maintain. I'm sure some nerd who lives in his mom's basement is going to contest this but the fact remains it's too difficult to do in most corporations let alone end users. Making a key, remembering the password, managing keys, revoking keys, it's all just a total pain in the ass. If you truly want secure email for the masses it has to be transparent. This is just a given. People are not going to do PKI. This is the main reason we don't have mass adoption of PGP encrypted email.

    The second reason and it's to a lesser extent but still a strong motivator IMO for the lack of secure options for communication are that corporations and governments don't WANT secure applications being adopted. How else can the government spy on you or corporations steal secrets from each other if things are encrypted. This isn't paranoid fantasy land I live in. I don't think any intelligent person today doesn't know especially over the last 8 years that the governments are doing everything they can to spy on you, record you, monitor you and track you. Wether its the TSA, DHS, warrant-less wiretapping whatever we are living in a 1984'esqe society. Seamless and mass adoption of strong encryption and anonymity by the masses would *seriously* curtail their ability to spy on you and find dissidents and evil doers who read catcher in the rye. So IMO these are the two strongest compelling reasons we don't have encryption for the masses yet. Phil's ZFone project is a good step in the right direction though.

  11. encryption is irrelevant by TheGratefulNet · · Score: 5, Insightful

    I'll go out on a limb and predict that in 5 yrs or less time, encryption will be a 'self admission of guilt' to ALL governments.

    I really hope I'm wrong. but the trend is there if you just look.

    we already have people saying 'if you are not a terrorist, you should have nothing to hide'. this is just a half step away from saying 'if you DO use encryption, you MUST be hiding something that we should see'.

    mark my words.

    you may think that you are out-smarting the governments but they have the money, the guns and all the power. and they're NOT about to give this bit of power (over the people) up.

    if you encrypt a laptop and pass thru customs, you are FORCED to reveal your password or at the least, 'open' the disk for them to view the contents of. so tell me, how did encryption help here?

    don't give me that crap about truecrypt, either. how long will it take before their border people know how to detect this? ....so depressing ;(

    --

    --
    "It is now safe to switch off your computer."
    1. Re:encryption is irrelevant by Skal+Tura · · Score: 4, Interesting

      As for passing customs, add in the hidden volume provided by truecrypt. I bet most would eat answer "there is none" ;)

      on the "public" portion, have semi-private personal pics, ie. your gf about naked, some sex stories from web and change them like they would be your experiences, love letters same thing, and other personalish data like that.

      That "GF" doesn't be even YOUR gf, just grab some package of amateur pics of some website X)

      Social engineering!

      2nd solution: Public torrent based encrypted "backup" service, goes through the borders easily. Could be somekind of torrent & truecrypt mashup.

      Could work if say you want to "backup" 5 gigs, you got to host atleast 10gigs. Gigantic waste of HDD space, Gigantic waste of bandwidth, no live usage, but have good key, and you are golden :)

      In theory could work, anyone attempting something like this?

  12. Re:Someone please remind me... by sm62704 · · Score: 4, Interesting

    They snoop and tell your government about your stash of _blackjack-playing, postmoking hookers_ (I'm in the US). Wala - your government has "proof" you are engaged in illegal activity and busts down your door.

    Although I agree with your comment, just putting in an email, slashdot comment, or even one of my journals can't get the FBI and DEA and whatever anti-prostitution agency to break down my door. Otherwise it seems they already would have, as although I'm no gambler, my slashdot journals often feature potsmoking and hookers. Maybe I should add some blackjack.

    However, adultery is NOT against the law. Do you want your wife to find the email you sent to your girlfriend because Sweden seems to be as anti-freedom as America?

    (OT but related; why is it legal for me to fuck my congressman's wife, but illegal for me to pay her for it?)

    --
    mcgrew's razor: Never attribute to stupidity that which can be explained by greedy self-interest
  13. Re:Here is what you do by Anonymous Coward · · Score: 4, Interesting

    17 is a cussword in Swedish. Incidentally, so is 1000. It's true, ask anyone from Sweden. In Sweden, 17 is also the most random number. If you need to make up statistics, it's traditional to use 17. Much like if you need a name for a method when discussing programming, you use "foo". I've seen university level math exams where every answer was 17. The professor had a wonderful sense of humor.

  14. Re:Someone please remind me... by Mr2001 · · Score: 4, Insightful

    I believe you may already know but, because if you pay for it: then pimps step in and abuse girls to do it. That's a result of prostitution being illegal, not a cause. When an industry is legal, workers can freely move from one employer to another, and disputes can be resolved with words in open court instead of a gold-tipped cane in a dark alley.
    --
    Visual IRC: Fast. Powerful. Free.