Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Security wisdom from years ago

No comments:
The security of a signal is inversely proportional to the distance between the sender and receiver.

There are only two fundamental ways to control a signal: control the box or control the pipe. Clever encryption schemes make controlling the pipe impossible - therefore there will be economic and political pressure to control the box.





A clever hack to determine which sites you've visited

No comments:
Aza Raskin has done it - he's written a piece of javascript that exploits a bug in CSS to determine where you've been on the web. He is positioning it as something useful, to show users only the social networking sites that they've visited to avoid "badge blindness". And it is useful. But it's also an invasion of privacy.

First, how it works. Basically, if you read the script he creates a new iframe, writes a bunch of URLs into it, setting some style attributes if it has or has not been visited. He then checks the style of each URL node. Pretty simple. Ordinarily you cannot tell what the style is of a visited link, because it would be a privacy concern. But Aza got around it.

Second, how to defeat it. The bottom line is that the only way is to disable your browser history. You could specifically defeat this script with a bit of Greasemonkey, but a) most people won't bother and b) even if they did it would be easy to counteract.

I would guess that we'll be seeing a patch from the browser vendors soon.

An interesting side-effect of web-based mail: non-repudiation

No comments:
The thing about web-based mail is that you can't mess with the data. If you run you're own mail server, you can mess with the data. This is actually a very good reason to use webmail, even if you have the skill and desire to run your own webserver. Indeed, if you get in the habit of sending signed messages, it's even better.

Of course, privacy is very good reason to NOT use webmail.

There is an elegant solution that allows one to have both: encrypted web mail. FireGPG is a wonderful little plugin that modifies the gmail interface so that you can sign, encrypt, or sign & encrypt outgoing email.

The only drawback is that your recipient has to know how to deal with such messages, which is a nontrivial problem. (even with nice tools like GnuPG, FireGPG it's a tough row to hoe. PKI (public key infrastructure) is difficult for people because not only does it require the installation of special software, but it absolutely requires that they have some bits with them (their private key) and remember a password (to unlock the private key). There can be no "I forgot my password" function in the system (at least, AFAICT).


P.S. Solving the PKI adoption problem is bound to be more social than technical. However, one could go a long way by a) pre-installing PKI tools in operating systems and web interfaces, b) offering hosted private keys (very safe if password is strong), and c) reducing the number of passwords people have to remember to 1 and making sure that they never forget it (which really helps achieve b), too).

Idea: secure webmail proxy

No comments:
Ok, so it's well-known that travellers of the world are being keylogged and hacked big time. Additionally there are growing concerns about webmail privacy.

Solve both problems with a private secure webmail proxy that does two things: defeat key loggers with a graphical challenge response credential check, and defeat eavesdropping by making encryption easy to use with webmail.

The system consists of some host on the internet - preferably one that's stable and owned by the user. E.g. a home server. (This minimizes some risks, but maximizes others...) That system provides a web interface that can be accessed world wide (unfortunately most consumer ISPs block port 80, and some internet cafes block alternate ports...). The system contains your username password for gmail, for example, and prompts you with a fancy graphical clickable scheme to verify who you are. It then logs into your webmail, and provides you with content.

This is enough to defeat keyloggers (although there are easy tricks to do that), but since we're proxying, why not go one step further and make PKI services easy to use? The basic idea is that a small piece of software on the proxy will be looking for encrypted content and unencrypt it for you. It could be presented as text, but it would be even cooler to present it as an image, making it that much harder for someone to eavesdrop assuming they have complete control over the client machine.

This addresses one of the severe usability flaws of modern PKE software - it's too easy to mess up. It's easy to loose your private key; it's easy to forget your private key decrypt passphrase. It's hard to install the correct software and use it properly, on all the systems you might want to use it on. In this system the private key file is stored on your (presumably secure) home system, and the proxy has the ability to decrypt the private key.

Because of the nature of this sort of software, it basically must be open source. Ironically, as it becomes more popular so the countermeasures will become more popular as well. However, it's like those red bars people put in their cars - they are possible to remove, but if presented with two cars one with and one without, why bother?

A "not too shabby" variation is to use something like FireGPG, which is a Firefox plugin that at least eases the integration woes between GPG4Win and the browser. Frankly I think my idea is better. :)