BitTorrent's Bram Cohen Unveils New Steganography Tool DissidentX
Sparrowvsrevolution writes "For the last year Bram Cohen, who created the breakthrough file-sharing protocol BitTorrent a decade ago, has been working on a tool he calls DissidentX, a steganography tool that's available now but is still being improved with the help of a group of researchers at Stanford. Like any stego tool, DissidentX can camouflage users' secrets in an inconspicuous website, a corporate document, or any other, pre-existing file from a Rick Astley video to a digital copy of Crime and Punishment. But it uses a new form of steganography based on cryptographic hashes to make the presence of a hidden message far harder for an eavesdropper to detect than in traditional stego. And it also makes it possible to encode multiple encrypted messages to different keys in the same cover text."
deserves a medal.
Religous speak to God. Insane are spoken to by God. When all shut up, one can finally hear Shostakovich in peace
Svefg cbfg!
Come on guys! At least post a link to the project.
https://github.com/bramcohen/DissidentX
It's probably better to work on this kind of thing in silence until it's released...
"Baron Cohen Unveils New Steganography Tool DissidentX"
If you're a whistleblower and use proprietary software, you're braindead. Might soon all dead...
...If you're looking for a tool to protect your privacy from N*A, C*A, or any other A*holes monitoring teh Internets is that it would surprise me if they don't have automated tools to spot steganography. (i.e. They know exactly what the formatting of say a Word document should be, and should have the capability to automatically flag traffic which has nonstandard information in the headers or data.) And *that* will call their attention to you far more quickly than if you just store/send in clear.
So, that I post this with something like 46 75 63 6b 20 79 6f 75 20 4e 53 41 21 on a regular basis... I'll bet it's flagged for some human being's attention. And that information (the flow of the traffic) may be more important than the message proper.
Everyone has a new product out to stick it to the man. Not that the NSA scandal is anything to ignore, but a bunch of tinfoil hatters will buy some shit like this, money will be pocketed and the stuff will never really be used.
How about adding some anonymity and security to bittorrent?
01101110 01101111 00100000 01101101
01101111 01110010 01100101 00100000
01110011 01100101 01100011 01110010
01100101 01110100 01110011
People who want to increase the chances that something will stay secret? People who want to reveal the crimes of their governments?
Need is relative. Even if all i want to do is have my wife send me a note to pick up milk on the way home, its not the governments business. So in reality, *yes* i do have something to hide. It doesn't mean i'm a criminal. Its called personal privacy.
---- Booth was a patriot ----
People who live in a country with a security force that can make you disappear and torture you to death for posting the wrong message unencrypted.
If you can make the diff of the documents, you can demonstrate that something is hidden, and therefore you are broadcasting "i have something to hide". Does it matter really if the encryption is more obfuscated ? All you need is a good enough encryption. The rest are sprinkle on the cake. All the other side needs to know is that you have something to hide, and depending on the level of society you live on, water boarding, lead pipes, or court order to make you divulge what it is.
The whole code for the project is actually embedded in the Slashdot front page today.
This does not even have tests. Barely any project-like organization. Just a bunch of python scripts hobbled together. Seriously, this is barely v0.1 material.
Call it a proof-of-concept, an experiment, anything. But not a tool.
What is it with all the dinosaur porn lately? Stenography probably predates the first man-cave, and was probably responsible for early advances in inter-cave communication.
rewriting history since 2109
I think you are missing the point here. 1) You do not have a wife, & 2) Why are you letting her boss you around?
But it uses a new form of steganography based on cryptographic hashes to make the presence of a hidden message far harder for an eavesdropper to detect than in traditional stego.
I think steganography is far more likely to be used to track the people who leak information. When information gets out that was apparently available to multiple people, the leaker may not realize that his copy had a specific steganographic signature that identifies him as the source. It could be a pattern of extra spaces or line breaks in the code of document that he doesn't even see. The increased availability of the technology will likely mean smaller companies or government agencies will use it to suppress leaks.
I see it as more of a big "screw you" to the people who want to watch everything we do.
I'm not committing any crime, and you have no reasonable basis to believe I am. It's still my right to communicate and keep some things private.
But if you're going to insist on tracking everything we do, we're going to make your job harder.
Expect to see lots of products intended to give end-user security.
If you're willing to allow the government to spy on everything you do (clearly not the case since you posted as AC), that's your problem.
Since the whole planet is being spied on by the US, denying them the information is the best response.
Lost at C:>. Found at C.
I'd like to see someone come up with a steganographic RAID-ish storage volume. I'd like a driver that scattered encrypted data throughout my media files but presented that data as an updateable storage volume. It would need enough redundancy to survive the loss of some of the files (hence the RAID-ish part.) If I could hide writeable encrypted data throughout my iTunes, Photo, Video files and access/update it without actually changing the size, mod dates, etc of the files it would be very handy and reasonably hard to detect.
Suppose you were an idiot. And suppose you were a member of congress. But then I repeat myself. -- Mark Twain
XfiltratorX
You seem confused about which way you want to troll this one. I admire the thought that maybe you could embrace the power of AND and go both ways, but, sometimes that doesn't work out. This is one of those times.
Cue the NSA insisting that they need to examine every photo and video that passes over the Internet because terrorists might be using this.
Also cue some enterprising NSA employee convincing his superiors that terrorists might hide stuff on porn sites and he needs to examine those photos/videos very carefully and repeatedly.
My sci-fi novel, Ghost Thief, is now available from Amazon.com.
Not that I disagree with you. But posting AC only hides us from you.
But normal people do not need this - it's completely loony-tunes.
Normal people shouldn't need this. What's completely loony-tunes is that they do.
systemd is Roko's Basilisk.
Yes, but other than that ... and a run-away / out of control government, the USA is not so bad!
I just encode messages by changing the font of the letters in the hidden message to comic sans.
"A person is smart. People are dumb, panicky dangerous animals and you know it." - K
1) Whether he has a wife or not is the government's business. He notifies them every time he files taxes (married and filing jointly/separately)
2) She can request that he buys milk on the way home. It's a sign of working as a team.
I could also say that he is likely to do it because he enjoys being married, but I think that's a bit sensationalist.
I refuse to sign
Perhaps people who live in countries where information is censored by the government.
Yes, but other than that ... and a run-away / out of control government, the USA is not so bad!
Not so bad!?! They bribed Celine Dion away from us Canadians... the trigger happy Americans are wonderful! (There is a nudge nudge, wink wink somewhere in there...) :)
soylentnews.org Go there to enjoy the people!
He got you, didn't he? I'd call that a success.
Will it be closed like Bittorrent-sync?
Innocent People residing in a land with a security agency of questionable legality in its practices? In other words, 90+% of Americans?
Amen!
Christ! Spoiler alert please!!
Of course I didn't read TFA!
Will there be an effective way for cryptanalysts to know the number of separately encrypted messages that exist within a data object? If so, the deniability feature of this will be of little use. If the number is not known, then handing over the password to a relatively innocuous message might be sufficient to end the interrogation. If the number is known, the waterboarding will continue until all passwords are revealed..
Have gnu, will travel.
I'm pretty sure people in this thread are confused between cryptography and steganography. Either way, I thought we had the latter one covered with the rising popularity in the online meme images. Since they're expected to be doctored you have no way of detecting a hidden message under the obvious stupidity. Wow.
Hashes are *always* one way. So you can't ever decrypt something that you only have a hash from. The best you can do is compare the hash to a hash of something you have as well and see if the hashes are the same. Unless you've chosen an algorithm that is known to have a lot of collisions, you can be fairly certain that your original text is probably the same thing as the other person's original text if the hashes are identical. Encrypting something with hashes so others can read it therefor doesn't work and this can't be based on "cryptographic hashes"
I was promised a flying car. Where is my flying car?
its crackable and its not safe...period considering he works essentially for warner brothers...this is not even news its a joke on any that think it is
i have a tool like this as part of my hacker tools
its 12 years old time to sue warner borthers and brahm cohen
You know about those people who say: "indents must be 4 spaces", "no indents must be tabs".
Well I use both, I encode messages in the indentations of my source code.
I set tabs to be 4 characters wide. Then use the following encoding:
tab = 0
space tab = 1
space space tab = 2
space space space tab = 3
space space space space = 4
Each line can encode multiple quinary digits. It is best when you program to make large functions, and to have multiple levels of for and while loops and deep if statements.
This is really clever. It includes encoders that use tabs spaces at the ends of lines, and even Oxford commas. That is ridiculously cool. Nice work, Bram & co.!
Building Better Software
Today, that's pretty much all of them.
But normal people do not need this
You are not thinking creatively enough. I can see a dozen uses for this, some playful, some serious, some a bit geeky, some artistic.
Assorted stuff I do sometimes: Lemuria.org
They know exactly what the formatting of say a Word document should be
Yeah right, even Microsoft doesn't know that.
If you hide anything in a common piece of media content it will stand out against all the other versions.
You ARE the problem. You've been conditioned to believe this since 9/11 and it's wrong. Us old folks remember when our lives were private unless WE divulged the information. They've trained millennials to SHARE everything and quite a few of us older folks think we have to change with the times. Well, no. Fuck that.
Tell me what you believe...I'll tell you what you should see.
Just how old are you? America started spying on its citizens during the civil war by intercepting the telegraph, ramped it up during WWI when national security started to be used to justify removable of what were apparent rights such as free speech and not much later the rule of J. Edgar Hoover, based on having dirt on everyone, started.
https://en.wikipedia.org/wiki/Inverted_totalitarianism
Your argument is neutered by the fact the Internet now makes privacy impossible.
Or he fake trolled himself, the real troll, to get you?
I've still not finished "Gödel, Escher, Bach: An Eternal Golden Braid", so I don't know the answer yet.