Tuesday, October 17, 2017

Google Advanced Protection

 
 
Google has today launched a free, opt‐in program aimed at users who believe their Google accounts - such as Gmail, Drive, YouTube etc. - to be at particularly high risk of targeted online attacks. The Advanced Protection Program currently consists of the three main elements: defending Gmail and Google account users against phishing attacks by requiring 2FA via a token generated by a hardware security key; locking down the risk of malicious applications grabbing sensitive data by automatically limiting full access to Gmail and Drive to just Google apps (for now); and reducing the risk of hackers gaining access to a Gmail account via impersonation by adding more steps to the account recovery process.
 
 
 


Monday, October 16, 2017

Governments Call for Breakable Encryption

 
 
 
Well, this is nothing new... but it is still concerning as the government continues to demand access to private communications. Now you may believe that the government's argument has merit, and that it should be able to access private communications with the appropriate legal process leading to a warrant issued by an impartial judge. However, that doesn't solve the problem because strong encryption is already available from sources outside the United States, such as JavaScrypt: Browser-Based Cryptography Tools (https://www.fourmilab.ch/javascrypt/), ProtonMail (https://protonmail.com/), and GnuPG (https://www.gpg4win.org/), just to name a few.
 
As with calls for gun control, calls for encryption control simply limit the ability of people who are committing no crimes, and pose no threat to national security. Groups of people using encryption to engage in organized crime or terrorist activities are not going to limit their use of strong encryption just because the United States government thinks that they should.  
 
Of course the United States government is not the only one looking to prevent its citizens from having access to strong encryption:
 
"In a statement released recently by Australian Attorney General George Brandis and the Minister for Immigration and Border Protection Peter Dutton, the two officials called for weakening encryption standards and for increased sharing of surveillance between Five Eyes countries." (Deep Dot Web, July 2017)
 
"In an interview with the BBC, Home Secretary Amber Rudd called the use of end-to-end encryption communications offered by tech companies and used by terrorists as a "completely unacceptable" situation. Rudd insists organizations behind encrypted messaging systems should not "provide a secret place for terrorists to communicate with each other." (Apple Insider)
 
"A leaked document reveals the UK government has drawn up yet further, disturbingly dystopian draft bulk surveillance powers, which would give authorities carte blanche to monitor citizens' live communications, and effectively illegalize encryption. A cybersecurity expert told Sputnik this has terrifying implications not merely for internet privacy. The rules would compel all communications companies — including phone networks and ISPs — to provide real-time access to any named individual's full content within a single working day, as well as any "secondary data" related to that individual, including encrypted content." (Sputnik News)
 
"After being threatened with a ban, it looks like Telegram is playing ball with Russia's government. Russian communications regulator Roskomnadzor confirmed in a statement [in June 2017] that Telegram, an app with over 100 million users globally, had submitted all required data and now works within the country's legal framework. The announcement comes after Russian authorities put pressure on the company on Monday to register itself with the government as an "organiser of information dissemination," saying the messaging app allowed terrorists to communicate secretly, with "high degree of encryption." Failure to do so would cause Telegram to be banned, authorities had threatened." (CNET)
 
The question is one of whether governments have a compelling interest in weakening encryption in the name of national security, or in order to fight organized criminal activity. Will preventing you and I from having strong encryption to safeguard our own privacy make us safer from criminals and terrorists? Government seems to think it will...  do you? 
 



Sunday, October 15, 2017

End-to-End Encrypted Messenger Apps

 
 
According to an article on BGR, “Just about anyone can read your private conversations if you use SMS”, and USA Today has said “Your texts are not as secure as you think”.  Simply put, standard text messages are not secure, they can be intercepted and read by other than the addressee (your intended recipient).

Your cellular service provider also has the ability to intercept, store, and read your text messages. PC Magazine published an article “How Long Does Your Wireless Carrier Retain Texts, Call Logs?” that discussed the data retention policies of the major cellular service providers.
 
In order to protect the content of your “text messages” you should be using an end-to-end encrypted messenger. In order to send end-to-end encrypted messages, everyone with whom you communicate must have the same encrypted messenger.  One of the most popular end-to-end encrypted messengers is WhatsApp (https://www.whatsapp.com). As of July 2017, WhatsApp had an estimated 1.3 Billion active users. Because so many people use WhatsApp and because of its easy-to-use interface I recommend that you include WhatsApp among your messaging tools.

My personal favorites for end-to-end encrypted messengers are Wickr (https://www.wickr.com/) and Signal Private Messenger (https://signal.org). Other encrypted messengers that may be of interest are ChatSecure for iOS (https://chatsecure.org), Cyphr (https://www.goldenfrog.com/cyphr), and CoverMe (http://www.coverme.ws/en/index.html).
 
There are other encrypted messengers available, such as Telegram (https://telegram.org) and Viber (https://www.viber.com), and the one you choose is going to be tied to what others with whom you are communicating are currently using, or what you can get them to use. As you research the various messenger apps, be sure that you only use those apps that use end-to-end encryption. Almost all apps encrypt your messages in transit, but if the app does not provide end-to-end encryption then it is likely that your messages are stored in plaintext on the messaging server.
 
Facebook Messenger offers the ability to turn on end-to-end encryption using its Secret Conversation mode. I am not particularly a fan of the Secret Conversation mode, because it is not turned on by default and thus you must remember to select it at the start of every conversation. Still if you are going to use Facebook Messenger, you should make it a point to always use it in Secret Conversation mode.
 
If you use an iPhone, then your iMessages and FaceTime chats are end-to-end encrypted with other iPhone users. However, if the person with whom you are communicating is not using an iPhone (i.e. they have an Android or Windows phone) then your messages are just unsecure text messages; and of course, FaceTime is not available to non-iPhone users.
 
Now it is important to understand that while end-to-end encryption protects the content of your messages, it does not necessarily protect the metadata of those messages. Someone who is able to monitor your cell-phone might be able to tell with whom you are communicating, but end-to-end encryption would keep them from knowing what you were saying.
 
Do a bit of research. Talk with friends and family with whom you regularly communicate by text message, and get everyone to use an end-to-end encrypted messenger. You may think that you have nothing to hide, and maybe this is true. But, saying that you don’t care about secure communications because you have nothing to hide, is kind of like saying that you don’t care about freedom of speech because you have nothing to say.
 
 
 


Saturday, October 14, 2017

Why You Should Have Protonmail

 
 
 
When you communicate with others via e-mail, the content of your messages may be read or scanned by someone other than your intended recipient (the addressee). It should be no secret by now that many of the major e-mail providers scan the content of your private e-mail to provide targeted advertising to you, the user. E-mail services can be, and often are, hacked. The recent Yahoo e-mail hack is just one example (See: "Every single Yahoo account was hacked - 3 billion in all" CNN Money Oct 3, 2017) And for some there may be the concern of your e-mail being accessed through legal discovery, or search warrant.
 
Now while you may not care about some of the content of your e-mail being exposed, you no doubt have personal e-mail content that you don’t want shared with anyone other than the intended recipient. To protect your personal and private communications with close friends and family, it is important to get everyone to communicate through an end-to-end encrypted e-mail service. For this, I recommend that you get everyone to sign up for and use a ProtonMail account.
 
ProtonMail is an end-to-end encrypted email service founded in 2013 at the CERN research facility in Geneva, Switzerland. ProtonMail uses client-side encryption to protect email contents and user data before they are sent to ProtonMail servers, in contrast to other common email providers such as Gmail and Hotmail. The service can be accessed through a webmail client or dedicated iOS and Android apps.  
 
When communicating on the ProtonMail network all your communication between ProtonMail accounts is encrypted using PGP. You also have the ability to send encrypted e-mail to users of other services if you have a shared message password; but having all of your close friends and family using the ProtonMail network is a much more secure option.  
 
  • ProtonMail is incorporated in Switzerland and all our servers are located in Switzerland. This means all user data is protected by strict Swiss privacy laws.
  • All emails are secured automatically with end-to-end encryption. This means even ProtonMail cannot decrypt and read your emails. As a result, your encrypted emails cannot be shared with third parties.
  • No personal information is required to create your secure ProtonMail account. By default, ProtonMail does not keep any IP logs which can be linked to your anonymous email account.
 
 
 

Friday, October 13, 2017

Free Privacy & E-Security Books

 
 
In 1999, I published my first book Privacy for Sale. The following year, I published The Complete Guide to E-Security, and then in 2002, I published The Privacy Handbook. All three of these books were published by Paladin Press in Colorado. Unfortunately, Paladin Press will close its doors at the end of the year (2017) and these three books are no longer in print.
 
I am making a PDF copy of each of these books available for free to readers of my blog, Chesbro On Security. Just follow the links and download a copy from my Google Drive.
Some of the information in these books is outdated, some of my ideas at the time were well... pretty bad (although perhaps valid at the time); but much of the information in these books is still valid and applicable to personal privacy and security today. At a minimum, you can read my thoughts on privacy and e-security from 15-20 years ago, and compare it to my thoughts in this blog currently.
 
 



KeePassXC Password Manager 2.2

 
 
 
KeePassXC (KeePass Cross-Platform Edition) is a community fork of KeePassX, the cross-platform port of KeePass for Windows.
 
The database is encrypted with the industry-standard AES (alias Rijndael) encryption algorithm using a 256 bit key. And it is compatible with KeePass Password Safe.
 
KeePassXC features include:
  • Auto-Type on all three major platforms (Linux, Windows, OS X)
  • Twofish encryption
  • DEP and ASLR hardening
  • Stand-alone password and passphrase generator
  • Password strength meter
  • YubiKey challenge-response support for strengthening your database encryption key
  • a generator for time-based one-time passwords (TOTP)
  • a diceware password generator
  • a command line interface (CLI)
  • CSV database import
  • true portable mode with the config file residing in the same directory as the application
  • automatic database locking when you lock your desktop session
 
 


Thursday, October 12, 2017

SnowHaze for iOS



 
SnowHaze is a powerful private browser developed to fully protect your data on the Internet. You can use SnowHaze on Apple iPhone, iPad and iPod Touch running iOS 9.2 or later. I use SnowHaze and recommend it as a replacement for the Safari browser.
 
Apple devices come with the Safari pre-installed, and you generally are not able to completely uninstall Safari from your iOS devices. You can however disable the Safari Browser by following these steps:
 
1: From your device's home screen, click  the Settings app
2: Scroll down and select General
3: Select Restrictions
4: Enter (or create) your restrictions passcode
5: Switch the toggle next to Safari to the OFF position

From the SnowHaze web-site... (https://snowhaze.com/en/)
 
"You are most probably not selling guns to Yemen over the Internet. However, already very basic information about you can be very harmful if it lands in the wrong hands. Your health data could be sold to an insurance company, which could deny selling you insurance. You could see more expensive flight tickets on the internet than your neighbor does because the site that is selling you the tickets already knows where you want to go. There are tons of more examples and the technology to analyze collected data is evolving at an incredible pace! While all popular browsers (Safari, Firefox, Chrome, etc.) offer functions that claim to protect your data ... well, they don't really. They erase your local data, but the much more harmful part on the internet stays there, easily accessible for everybody. This is why it is so important to protect your data. No browser entirely hides your activities on the internet (even TOR and SnowHaze do not), but we do everything to protect your data as well as we can. The technologies that SnowHaze uses are not new. But until now, it was too hard to set up, the interfaces were just ugly and the pages would not even load correctly. This is why we created SnowHaze - The first easy to use browser that really protects your data. Let us know what you think; we would love to hear your opinion!"