Tuesday, July 24, 2012

5 Essential Privacy Tools For The Next Crypto War

By Jon Matonis
Thursday, July 19, 2012


The first crypto war revolved around the hardware-based Clipper Chip and coercing companies to deploy broken encryption with backdoors to enable domestic State spying. Fortunately, the good guys won.

The next crypto war is still a war of the government against its own citizens but this time enlisting the corporations, including social networks, as direct agents of the State. What some have dubbed Crypto Wars 2.0 manifests itself in the current litany of legislative acronyms designed to confuse and befuddle.

Sometimes I think legislative bills are named with a Twitter hashtag in mind. Although it doesn't always work out favorably for the  name deciders, hashtags do generally assist in the coalescing of Internet organizers around the world. Since passage of the Cyber Intelligence Sharing and Protection Act by the U.S. House of Representatives in April, #CISPA has been everywhere. Thankfully, twin legislative initiatives SOPA and PIPA were dropped in January. Also, let's not forget the gradual expansion of CALEA and the Lieberman-Collins Cyber Security Act and the NSA-centric McCain Cybersecurity Act.

Even the seemingly unpatriotic USA PATRIOT Act of 2001 is a garbled backronym that would make George Orwell proud: Uniting (and) Strengthening America (by) Providing Appropriate Tools Required (to) Intercept (and) Obstruct Terrorism Act.

The Electronic Frontier Foundation recently posted an FAQ arguing that CISPA would allow companies to review and then to hand over customers' personal information, logs, and email to the government. That is a fairly broad and comprehensive mandate.

What has gone largely unnoticed in this torrent of analysis, however, is that privacy tools for individuals already exist and they have so for many years! Quietly anticipating encroachment against basic Internet liberties, concerned cyber privacy advocates has been coding and releasing the tools that allow for private electronic communication and private web surfing. Proposed legislation like CISPA may or may not pass and become law, but if it does we have to understand the new landscape. Your privacy is up to you!

1. Email Privacy - Naked email is like a postcard for anyone to read. Pretty Good Privacy (PGP), an open source software program created by Phil Zimmermann in 1991, is the global standard for point-to-point encrypted and authenticated email. Hushmail is an OpenPGP-compatible web-based email platform that does not have access to your user password for decryption. Both products, when used correctly, offer subpoena-proof email communication.

2. File Privacy - Your files might be stored in the encrypted cloud but that doesn't mean that they're 100% safe for your eyes only. Free and open-source TrueCrypt allows you to encrypt folders or entire drives locally prior to syncing with Dropbox. BoxCryptor also facilitates local file encryption prior to cloud uploading and it comes with added compatibility for Android and iOS.

There is an alternative to the dual-application process described above. Although most cloud-based storage services transfer over an encrypted session and store data in an encrypted form, the files are still accessible to the service provider which makes the data vulnerable to court-ordered subpoena. In order to rectify this, two different zero-knowledge data storage companies provide secure online data backup and syncing - SpiderOak and Wuala. For obvious reasons, there is no password recovery and employees have zero access to your data.

3. Voice Privacy - Wiretapping will become more prevalent in the days and months ahead. From the creator of PGP, Zfone is a new secure VoIP phone software product utilizing a protocol called ZRTP which lets you make encrypted phone calls over the Internet. The project's trademark is "whisper in someone's ear from a thousand miles away." You can listen to Zimmermann present Zfone at DEFCON 15.

Also utilizing ZRTP, open-source Jitsi provides secure video calls, conferencing, chat, and desktop sharing. Because of security issues and lawful interception, Tor Project’s Jacob Appelbaum recommends using Jitsi instead of Skype.

Designed specifically for mobile devices and utilizing ZRTP, open-source RedPhone from Whisper Systems is an application that enables encrypted voice communication between RedPhone users on Android.

4. Chat Privacy - Encrypting your chat or instant messaging sessions is just as important as encrypting your email. Cryptocat establishes a secure, encrypted chat session that is allegedly not subject to commercial or government surveillance. Similar to Cryptocat, the older and more durable Off-the-record Messaging (OTR) cryptographic protocol generates new key pairs for every chat implementing a form of perfect forward secrecy and deniable encryption. It is available via Pidgin plugin.

5. Traffic Privacy - The final step in the process is geo-privacy, which refers to the protection of 'information privacy' with regard to geographic information. Virtual Private Networks, or VPNs, have been used consistently for anonymous web browsing and IP address masking. Just make sure that your VPN provider does not log IP addresses and that they accept a form of payment that does not link you to the transaction.

Additionally, the Tor Project provides free software and an open network for privacy-oriented Internet usage. Intended to protect users' personal freedom, privacy, and ability to conduct confidential business, Tor (The onion router) is a system that improves online anonymity by routing Internet traffic through a worldwide volunteer network of layering and encrypting servers which impedes network surveillance or traffic analysis.

I encourage everyone to become familiar with these basic tools for privacy. The important disclaimer is that in order to circumvent these privacy technologies, your password can be obtained in a variety of ways that are extremely intrusive and beyond the realm of casual day-to-day usage, such as hardware keyloggers or ceiling-mounted cameras. Furthermore, browser-based cryptography carries the added risk of spoofed applets being delivered to your desktop by court order or by malicious actors but this risk can be mitigated by maintaining trusted source code locally or by verifying compiled code against a digital signature. The mission statement from Tor Project advocate and developer Jacob Appelbaum still stands, "Make the metadata worthless essentially for people that are surveilling you."

[UPDATE:  I was previously affiliated with Hush Communications Corporation, the creator of Hushmail. This link further explains my stance on Hushmail strengths and weaknesses.]

For further reading:
"Review of Cryptocat", Vitalik Buterin, Bitcoin Magazine, June 15, 2012
"Paranoia About CISPA Is Justified", Conor Friedersdorf, The Atlantic, April 27, 2012
"Never Trust A VPN Provider That Doesn’t Accept Bitcoin", Rick Falkvinge, September 27, 2011
"PGP Creator Defends Hushmail", Ryan Singel, Wired, November 19, 2007


  1. Replies
    1. FellowTraveler,

      Good point. I have addressed financial privacy many times on these pages so I strayed away from bitcoin and digital bearer cash for a moment. It could also be considered a sub-category of file privacy and traffic privacy.

  2. Actually, Hushmail will keep your emails private from anyone who can't get a subpoena or warrant from a Canadian federal court or a court in the province of British Columbia (Hushmail is based in Vancouver, BC)

    Make no mistake, though, Hushmail can and will readily turn over anything you have done using their browser-based service to any law enforcement or lawyerlytypes who show up with a warrant or subpoena from the correct jurisdiction.

    It also now appears that there is some sort of backdoor in their java-based app that encrypts your emails on your own computer. They can, with more difficulty, deliver client-based material to warrant-bearers as well. See, for example:


    Fot the record, British Columbia's courts and Canada's current neoconservative federal government have a record of kowtowing to US extra-jurisdictional requests for information or extraditions. They even have a record of allowing US law enforcement officers onto Canadian territory to enforce US laws. This is even for activities that happen to not be illegal in Canada, but that displease the current powers that be who are more moralistic than previous politicians. see:


    Bottom line: your data is not safe from government intrusion with Hushmail, especially if you live in Canada or the USA. It's not even safe from private intrusion, if a lawyer is willing to travel to British Columbia and can convince a judge to issue a subpoena.

    MailVault is much more secure.