Re: [liberationtech] What I've learned from Cryptocat

2012-08-07 Thread Maxim Kammerer
ng order (and as has been already mentioned, Google is a multinational corporation, subject to a multitude of jurisdictions, and is known to bend over for whoever is in charge). -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ liberatio

Re: [liberationtech] Wired's response to Soghoian's criticism of their Cryptocat article

2012-08-08 Thread Maxim Kammerer
ccusing Soghoian of sexism, of all things! I think that this transitive white-knighting qualifies as ironic. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ liberationtech mailing list liberationtech@lists.stanford.edu Should you need to chang

Re: [liberationtech] archives public

2012-08-09 Thread Maxim Kammerer
the list, not to the individual sender. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte ___ liberationtech mailing list liberationtech@lists.stanford.edu Should you need to change your subscription options, please go to: https://mailman

Re: [liberationtech] archives public

2012-08-09 Thread Maxim Kammerer
from the list unnecessarily exposes subscribers' email addresses. > When the reply-to is the list, it becomes more > annoying to reply just to the sender. Any decent mail client has a “Reply to Sender” button — no idea why GMail doesn't (or I didn't look hard enough). --

Re: [liberationtech] CryptoParty Handbook

2012-10-04 Thread Maxim Kammerer
q 20); do cat x x > x1; mv x1 x; done cp x /media/... && sync shred -u /media/... && sync cp /dev/sd... image LC_ALL=C grep -wc test_string_123 image The result was 0 in both cases. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, o

Re: [liberationtech] CryptoParty Handbook

2012-10-05 Thread Maxim Kammerer
tion, or by flashing the drive > with custom firmware. Did you try a bigger file? -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] CryptoParty Handbook

2012-10-09 Thread Maxim Kammerer
ends on the algorithm used for wear leveling — see [1, §2.3.1]. [1] “Algorithms and data structures for flash memories”, http://dx.doi.org/10.1145/1089733.1089735. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] best practices - roundup

2012-10-09 Thread Maxim Kammerer
t for all installation types (USB, CD, OVF), and is also the first Linux distribution to use Secure Boot as a trusted boot chain mechanism. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman

Re: [liberationtech] best practices - roundup

2012-10-09 Thread Maxim Kammerer
intermediate certificate, or embedding one's keys in firmware (Ubuntu). If you forgo the requirement of complete boot transparency, which I think is reasonable for a special-purpose live distribution, using an own certificate is an obvious choice. -- Maxim Kammerer Liberté Linux: http://dee.su/liber

Re: [liberationtech] Security / reliability of cryptoheaven ?

2012-10-10 Thread Maxim Kammerer
and does not pay too much attention to computer security, besides some simple guidelines. Then, his country deploys the most sophisticated individual surveillance technology money can buy against him, and he is beaten and/or killed after being confirmed as a danger to the regime. Maybe if he knew this co

Re: [liberationtech] safegmail-is-a-simple-way-to-encrypt-messages-in-gmail

2012-10-23 Thread Maxim Kammerer
ly doesn't attract attention. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Large amounts of spam

2012-10-31 Thread Maxim Kammerer
from a hijacked account. Are you sure the spam comes via the list? Or does Google Apps delete spam with malware attachments altogether (i.e., skipping the Spam folder stage)? -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mail

Re: [liberationtech] Bitcoin and The Public Function of Money

2012-11-02 Thread Maxim Kammerer
full burkas here > so their school mates don't recognise them when they're out on a date." You are quoting her as an example of Muslim humor, right? Not sure how this is related to different varieties of freedom and liberty, though. -- Maxim Kammerer Liberté Linux: http://dee.s

Re: [liberationtech] Bitcoin and The Public Function of Money

2012-11-05 Thread Maxim Kammerer
tion transfers, shortened life expectancy, and all other complete opposites of an utopia. Contradiction? Only if one doesn't use religious faith to reason about economic reality. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change

Re: [liberationtech] issilentcircleopensourceyet.com

2012-11-06 Thread Maxim Kammerer
cly acknowledge the currently primary use of hidden services in fear of losing authorities goodwill and funding sources. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] issilentcircleopensourceyet.com

2012-11-07 Thread Maxim Kammerer
permail/tor-talk/2012-August/025151.html [2] https://lists.torproject.org/pipermail/tor-talk/2012-November/026354.html -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] MJM as Personified Evil Says Spyware Saves Lives Not Kills Them

2012-11-12 Thread Maxim Kammerer
ccomplished. And I find it very hard to believe that any sizable proportion of his acquaintances or dating pool care about the details of the software that he produces or who is it sold to. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password

Re: [liberationtech] issilentcircleopensourceyet.com

2012-11-12 Thread Maxim Kammerer
ature because it might be misinterpreted by whoever brings politics into the project. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Comments on Internews new "information security guide"

2012-11-14 Thread Maxim Kammerer
56.html (English, summary) -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Bitly Safety (was Stanford Bitly Enterprise Account)

2012-11-16 Thread Maxim Kammerer
interface. It is possible to restore the link automatically in a browser plugin, as was attempted, e.g., here: https://c0rrupt.net/forum/web-application-development/396-t-co-no-make-firefox-plugin.html -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change pas

Re: [liberationtech] Censorship hardware - BLUECOAT IN SYIA

2012-12-05 Thread Maxim Kammerer
3411}.log.gz [2] http://reflets.info/bluecoats-presence-in-syria-finally-uncovered/ -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Quantum computation & communication

2012-12-19 Thread Maxim Kammerer
QC, assuming it's actually resistant to classic computing as well (which is generally seen as a much stronger assumption than, e.g., assuming that factoring is hard). Caveat emptor: not my field, inb4 hate from QC people. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscrib

Re: [liberationtech] Why Skype (real-time) is losing out to WeChat (async)

2012-12-24 Thread Maxim Kammerer
rings. > Should we try to turn Gibberbot into a more-secure > WhatsApp/WeChat clone? You can try, but I doubt that anyone except a minority of security enthusiasts will use it instead of established solutions. Best regards, Maxim -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Travel with notebook habit

2012-12-28 Thread Maxim Kammerer
t your laptop is not a bomb (given the limited training they receive on the subject). The situation that you describe looks more like the latter than the former (although clearly there might be omitted details). -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to

Re: [liberationtech] Google Bows Down To Chinese Government On Censorship

2013-01-09 Thread Maxim Kammerer
ey probably considered complete block of Google by GFC too real a possibility, and were too afraid to lose market share. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Google Bows Down To Chinese Government On Censorship

2013-01-10 Thread Maxim Kammerer
ou have to give them the benefit of the doubt when they face Chinese experts. [1] [1] http://www.contextis.com/files/Targeted_Attacks_Whitepaper.pdf -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Google Bows Down To Chinese Government On Censorship

2013-01-10 Thread Maxim Kammerer
g much more primitive yet working by the same principle). -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Google Bows Down To Chinese Government On Censorship

2013-01-10 Thread Maxim Kammerer
Google search.” [2] [1] http://www.wired.co.uk/news/archive/2013-01/04/google-china-anti-censorship-fail [2] http://techcrunch.com/2013/01/04/google-quietly-removes-censorship-warning-feature-for-search-users-in-china/ -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, c

Re: [liberationtech] Google Bows Down To Chinese Government On Censorship

2013-01-12 Thread Maxim Kammerer
rust GreatFire's judgement on the matter, because it took them a month to notice the change, which goes contrary to claims about user experience getting worse. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Tragic News: Aaron Swartz commits suicide

2013-01-13 Thread Maxim Kammerer
d “I am not publishing in closed-access journals” one). -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Tragic News: Aaron Swartz commits suicide

2013-01-13 Thread Maxim Kammerer
(no need for external links, just keep the articles / book on-site). Implementers: no newbies. I think it would be a good project, with tremendous impact (read the article above). -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change passwo

Re: [liberationtech] Removing watermarks from pdfs

2013-01-16 Thread Maxim Kammerer
ore. Restrictions > apply." I have removed such lines in the past via a simple “pdftk uncompress | sed | pdftk compress” filter. IIRC, file size needs to stay the same. I guess this approach applies to all added extra text. Added pages can be removed using pdftk just the same. -- Maxim Kamm

Re: [liberationtech] Skype letter strategy

2013-01-17 Thread Maxim Kammerer
ort for the criminal complaint against Dmitry Sklyarov” in 2001. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Why Al-Qaida Hates the Internet: Trust Problems on Jihadi Discussion Forums

2013-01-23 Thread Maxim Kammerer
ive than prevention of hostile behavior (e.g., via catching wannabe terrorists). -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Chromebooks for Risky Situations?

2013-02-12 Thread Maxim Kammerer
On Tue, Feb 12, 2013 at 10:01 AM, Andreas Bader wrote: > So why not create a own OS that is really small because of its security? http://dee.su/liberte-build -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: ht

Re: [liberationtech] Iceland leading the way towards a ban on violent online porn

2013-02-18 Thread Maxim Kammerer
st likely view mostly vanilla porn, and people living in passive-aggressive societies who are bored with their fat wives go after the hardcore variety. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Fwd: [g...@pryzby.org: Ubuntu, Dash, Shuttleworth and privacy]

2013-02-20 Thread Maxim Kammerer
So, for the record, there are at least *two* examples why Debian sucks security-wise. [1] http://www.vervest.org/foswiki/bin/view/HTP/DownloadC -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Fwd: [g...@pryzby.org: Ubuntu, Dash, Shuttleworth and privacy]

2013-02-20 Thread Maxim Kammerer
or all you know the author of HTpdate may not be telling the truth, that s/he > didn't contact any 'Debian security administrator' - I've never heard of such > a > role. Maybe, maybe not. All certificates and other key material produced between 2006–2008 on Debian was w

Re: [liberationtech] Fwd: [g...@pryzby.org: Ubuntu, Dash, Shuttleworth and privacy]

2013-02-20 Thread Maxim Kammerer
remember it not being able to even install properly somewhere in the 90's. I just quoted the developer verbatim, FWIW. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Unsubscribe, change to digest, or change password at: https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] Mexico's most vulnerable reporters lack digital security skills

2013-02-27 Thread Maxim Kammerer
ty of communication methods that they use, even when provided with necessary information. Common sense and numerous examples point to the contrary. [1] http://dee.su/cables -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by

Re: [liberationtech] Mexico's most vulnerable reporters lack digital security skills

2013-02-27 Thread Maxim Kammerer
d by The Grugq: https://groups.google.com/d/forum/opsec-discuss -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at compa...@stanford.edu or changing your settings at https://mailman.stanford.edu/ma

Re: [liberationtech] Here Come the Encryption Apps

2013-03-10 Thread Maxim Kammerer
mplex, and would not use it in my projects unless it was proven correct with something like SPIN model checker, but suum cuique. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at compa...@stanford

Re: [liberationtech] Here Come the Encryption Apps

2013-03-15 Thread Maxim Kammerer
table communication channel for people on the ground who actually do things (good or bad). -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at compa...@stanford.edu or changing your settings at

Re: [liberationtech] list reply-all

2013-03-20 Thread Maxim Kammerer
email twice) - Reducing both the strain on the server and the risk of triggering spam filters So no new information has been brought in this thread. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at c

Re: [liberationtech] list reply-all

2013-03-20 Thread Maxim Kammerer
On Wed, Mar 20, 2013 at 11:48 AM, Michael Allan wrote: > Maxim Kammerer said: >> ... Any decent mailing list uses reply-to-list as a default. ... > > Pardon me, but that's not true. GNU Mailman is a decent list server > and it ships with reply-to-sender. I wrote “mail

Re: [liberationtech] Vote results on "Reply to" Question

2013-03-30 Thread Maxim Kammerer
sn't mean that everyone will comply. Don't assume that you are smarter than everyone else just because you are better versed in technical aspects of some issue. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change passwor

Re: [liberationtech] I-Power : Using Crowd Support, Not Bribes, to Redress Public Grievances

2013-03-30 Thread Maxim Kammerer
ipedia.org/wiki/Демократор I have no experience with it, so can't comment further. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at compa...@stanford.edu or changing your settings at htt

Re: [liberationtech] SUBSCRIPTION

2013-04-03 Thread Maxim Kammerer
On Wed, Apr 3, 2013 at 3:23 PM, Griffin Boyce wrote: > My suggestion is to remove the dash-dash-space that precedes the > unsubscribe notice. Should I remind that this was *also* the result of a vote on 21.8.2012? 3. Eliminate signature, modify, or leave as is? a. Eliminate 20.7% b. Modify 62.1%

Re: [liberationtech] Here Come the Encryption Apps

2013-04-18 Thread Maxim Kammerer
thing, I would expect a boost in use of circumvention methods (such as mesh networks) in places where such shutdowns do become an obstacle. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at compa...@s

Re: [liberationtech] And right on cue, the flush our civil liberties down the toilet boys rear their ugly heads

2013-04-19 Thread Maxim Kammerer
y breath, since asking such questions will require forgoing the usual calming excuse of a “disturbed individual” any time a Muslim in a Western country takes Jihadist preachings too close to heart, but I do believe the incompetence exposing approach could be effective in this case. -- Maxim Kammere

Re: [liberationtech] Liberte Linux

2013-04-26 Thread Maxim Kammerer
I saw her email, but was abroad during the week, sorry — will send her some pointers tomorrow. There is also a build-time issue with the outdated kernel, will try to update it by then as well. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to di

Re: [liberationtech] Liberte Linux

2013-04-26 Thread Maxim Kammerer
builds are probably possible, but the devil is in the details, especially for a distribution image that contains many packages inside. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at compa...@sta

Re: [liberationtech] Boundless Informant: the NSA's secret tool to track global surveillance data

2013-06-10 Thread Maxim Kammerer
een the case, it would mean that your military-industrial complex is not that powerful, which would imply that you are not special anymore, which, ironically, rejects the original premise. Hopefully someone else can appreciate the irony as well (hence writing this). -- Maxim Kammerer Liberté Linux: htt

Re: [liberationtech] U.S. Agencies Said to Swap Data With Thousands of Firms

2013-06-14 Thread Maxim Kammerer
ces to recruit disgruntled lower-ranking managers to provide the same information, as well. Should be easy, since no treason / classified information is involved. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by emailing mo

Re: [liberationtech] PrivateCore and secure hosting

2013-06-22 Thread Maxim Kammerer
Execution Technology (TXT) for more info how this > works. Does TXT provide any benefit over UEFI Secure Boot? I remember looking into integrating TXT, and it seemed like something not too well-supported, and essentially superseded by better-established standards like Secure Boot. -- Maxim Kamm

Re: [liberationtech] DecryptoCat

2013-07-06 Thread Maxim Kammerer
” [1] during the related time period. So introductory-level programming course mistakes are right out. [1] https://blog.crypto.cat/2013/02/cryptocat-passes-security-audit-with-flying-colors/ -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to diges

Re: [liberationtech] DecryptoCat

2013-07-07 Thread Maxim Kammerer
to implementing everything from scratch himself, and thoroughly comparing the implementations. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at compa...@stanford.edu or changing your settings a

Re: [liberationtech] DecryptoCat

2013-07-08 Thread Maxim Kammerer
ce agency, would you still proceed to lecture me on my thinking processes, and on best software practices? -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at compa...@stanford.edu or changing your settings at https://mailman.stanford.edu/mailman/listinfo/liberationtech

Re: [liberationtech] DecryptoCat

2013-07-08 Thread Maxim Kammerer
is negligible. [1] https://www.torproject.org/about/jobs-coredev.html -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at compa...@stanford.edu or changing your settings at https://mailman.sta

Re: [liberationtech] DecryptoCat

2013-07-09 Thread Maxim Kammerer
27;s POV). > Writing secure software is much, much harder than simply writing > comments, writing tests and coding defensively. This is a thread about Cryptocat. Cryptocat is a web frontend for a couple of protocols. Yes, it is that easy. -- Maxim Kammerer Liberté Linux: http://dee.su

Re: [liberationtech] Cables! (was Re: DecryptoCat)

2013-07-10 Thread Maxim Kammerer
onment for cables communication (even before developing cables), but got carried away somewhat. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at compa...@stanford.edu or changing your s

Re: [liberationtech] In his own words: Confessions of a cyber warrior

2013-07-10 Thread Maxim Kammerer
//abcnews.go.com/Technology/pentagon-cyber-command-unit-recommended-elevated-combatant-status/story?id=16262052 -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at compa...@stanfo

Re: [liberationtech] In his own words: Confessions of a cyber warrior

2013-07-10 Thread Maxim Kammerer
re not bought to deny them to the enemy. They are > bought for integration into things like stuxnet. Which had four 0-days. With the outstanding importance assigned to the project, I would expect them to lose count of 0-days stuffed inside if they really had “tens of thousands” of those. -- Maxim

Re: [liberationtech] In his own words: Confessions of a cyber warrior

2013-07-10 Thread Maxim Kammerer
and manuals for sensitive equipment certainly wouldn't contain schematics for the modules inside? Does the writer have any idea how rare it is for someone to be really good at both hardware and software hacking? Or how unlikely it is for a high-school dropout to be able to break even the simplest freq

Re: [liberationtech] DecryptoCat

2013-07-11 Thread Maxim Kammerer
, Chinese attacks are being mentioned all the time, but even those seem to rely on spearfishing attacks. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at compa...@stanford.edu or changing your set

Re: [liberationtech] DecryptoCat

2013-07-11 Thread Maxim Kammerer
hing it — I can understand that. So, where are the answers to these questions? Why am I reading useless apologies and expressions of support instead? [1] https://mailman.stanford.edu/pipermail/liberationtech/2012-September/004854.html -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too man

Re: [liberationtech] DecryptoCat

2013-07-11 Thread Maxim Kammerer
problem with bug hunting is that, in virtually all cases, the reward for an exploitable bug is orders of magnitude lower than what can be fetched on the open market. So it is not a replacement for a thorough review by experts. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Too

Re: [liberationtech] Ether Rag: Duck Duck Go: Illusion of Privacy

2013-07-14 Thread Maxim Kammerer
d by Verizon and upon which the SSL decryption > key is installed. They don’t need continuous access, 30 seconds is > all that would be necessary to copy the cert. Someone already pointed out PFS in comments, and, as expected, the author tries to hide his ignorance. -- Maxim Kammerer L

Re: [liberationtech] Freedom Hosting, Tormail Compromised // OnionCloud

2013-08-06 Thread Maxim Kammerer
eedom Hosting by those OpDarknet clowns two years ago: http://pastebin.com/qWHDWCre -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech list is public and archives are searchable on Google. Too many emails? Unsubscribe, change to digest, or change password by emaili

Re: [liberationtech] Freedom Hosting, Tormail Compromised // OnionCloud

2013-08-06 Thread Maxim Kammerer
Mike and I can't even begin to find it funny in the > least. Though I'll take your point that it is rich with awful irony. > I don't think anyone took those guys seriously back then (or anyone whose opinion matters, at least). -- Maxim Kammerer Liberté Linux: http://dee.

Re: [liberationtech] Google confirms critical Android crypto flaw

2013-08-15 Thread Maxim Kammerer
it, but it wasn't registered as SHA1PRNG that people used? Did Google implement its Java standard library subset from scratch (i.e., not based on GNU Classpath or similar)? [1] http://android-developers.blogspot.com/2013/08/some-securerandom-thoughts.html -- Maxim Kammerer Liberté Linux:

Re: [liberationtech] Google confirms critical Android crypto flaw

2013-08-15 Thread Maxim Kammerer
ats-buggy-prng/ Nadim, I understand that you continue posting this link due to its impressive visualizations of trivial math, but do you have any evidence that the probability skew bug in question meaningfully affected the security of CryptoCat? -- Maxim Kammerer Liberté Linux: http://dee.s

Re: [liberationtech] Google confirms critical Android crypto flaw

2013-08-15 Thread Maxim Kammerer
P800-90A's Hash_DRBG [2, p. 40] resembles nothing of the sort. [1] http://dx.doi.org/10.1007/978-3-642-36095-4_9 [2] http://csrc.nist.gov/publications/nistpubs/800-90A/SP800-90A.pdf -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is a public list whose ar

Re: [liberationtech] Google confirms critical Android crypto flaw

2013-08-15 Thread Maxim Kammerer
nel/git/torvalds/linux.git/log/drivers/char/random.c -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is a public list whose archives are searchable on Google. Violations of list guidelines will get you moderated: https://mailman.stanford.edu/mailman/listinfo/liberationt

Re: [liberationtech] Google confirms critical Android crypto flaw

2013-08-15 Thread Maxim Kammerer
ert Love Rusty Russell Sam Ravnborg Serge E. Hallyn Stephen Hemminger Tejun Heo Theodore Ts'o Thomas Gleixner Tony Luck Yinghai Lu -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is a public list whose archives are searchable on Google. Violations of list guidelin

Re: [liberationtech] Google confirms critical Android crypto flaw

2013-08-20 Thread Maxim Kammerer
On Thu, Aug 15, 2013 at 3:38 PM, Maxim Kammerer wrote: > On Thu, Aug 15, 2013 at 2:34 PM, Nathan of Guardian > wrote: >> The best description is here: >> http://armoredbarista.blogspot.ch/2013/03/randomly-failed-weaknesses-in-java.html > > Unbelievable… It seems that

Re: [liberationtech] Bradley Manning's sentence: 35 years for exposing us to the truth

2013-08-21 Thread Maxim Kammerer
s/comments/1kszc9/bradley_manning_sentenced_to_35_years_in_jail/cbsg58x -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is a public list whose archives are searchable on Google. Violations of list guidelines will get you moderated: https://mailman.stanford.edu/mailman/listin

Re: [liberationtech] Open Whisper Systems' neat asynch FPS "pre-keying"

2013-08-22 Thread Maxim Kammerer
does it really matter if the protocol is asynchronous to begin with? [1] http://dee.su/cables [2] https://github.com/mkdesu/cables/blob/master/doc/cable.txt -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is a public list whose archives are searchable on Google. Viola

Re: [liberationtech] Deterministic Builds Part One: Cyberwar and Global Compromise

2013-08-23 Thread Maxim Kammerer
nd installed in a different path in /nix/store so it doesn’t > interfere with the old version. mean that upgrading a library due to e.g. security fixes requires recompiling all packages that depend on it? -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is a pu

Re: [liberationtech] Scramble.io, Round Two

2013-08-28 Thread Maxim Kammerer
hereas DH peer keys are signed with a lower-level certificate's private key, which may have different lifetime. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is a public list whose archives are searchable on Google. Violations of list guidelines wi

Re: [liberationtech] scrambler

2013-08-30 Thread Maxim Kammerer
laintexts are same or different given 2n bits in ciphertexts — cryptanalysis would be much trickier, although in the end you would probably be able to extract the same amount of information (ignoring correlation differences) for a given (repeating) key length. -- Maxim Kammerer Liberté Linux: http://dee.su/li

Re: [liberationtech] Other distros like Ubuntu Privacy Remix?

2013-09-03 Thread Maxim Kammerer
http://www.debian.org/releases/stable/i386/ch05s03.html -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is a public list whose archives are searchable on Google. Violations of list guidelines will get you moderated: https://mailman.stanford.edu/mailman/listinfo/libera

Re: [liberationtech] Recommend consultant to discuss pen test?

2013-09-05 Thread Maxim Kammerer
On Thu, Sep 5, 2013 at 4:48 AM, Tom O wrote: > Veracode will gladly pwn you. https://blog.crypto.cat/2013/02/cryptocat-passes-security-audit-with-flying-colors/ http://tobtu.com/decryptocat-old.php -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is a public list wh

Re: [liberationtech] Open Letter To US Customs

2013-09-05 Thread Maxim Kammerer
at the agents for 9 hours? It's certainly less exhausting than answering silly questions of some failures equipped with a crash course on basic interrogation techniques? -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is a public list whose archives are searchable o

Re: [liberationtech] Open Letter To US Customs

2013-09-05 Thread Maxim Kammerer
; This has nothing to do with the linked article. That's why I referred to a "common theme", please pay attention next time. [1] http://www.legislation.gov.uk/ukpga/2000/11/schedule/7 [2] http://www.legislation.gov.uk/ukpga/2000/11/section/40 -- Maxim Kammerer Liberté Linux:

Re: [liberationtech] NYTimes and Guardian on NSA

2013-09-06 Thread Maxim Kammerer
breaking the cryptosystem in question. [1] https://en.wikipedia.org/wiki/Dual_EC_DRBG -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is a public list whose archives are searchable on Google. Violations of list guidelines will get you moderated: https://mailman.

Re: [liberationtech] Recommend consultant to discuss pen test?

2013-09-06 Thread Maxim Kammerer
27;s all fine, I guess — just make sure something like that is in the next contract. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is a public list whose archives are searchable on Google. Violations of list guidelines will get you moderated: https://mailman.stanford.e

Re: [liberationtech] Random number generation being influenced - rumors

2013-09-06 Thread Maxim Kammerer
intel.com/en-us/articles/intel-digital-random-number-generator-drng-software-implementation-guide [2] http://csrc.nist.gov/publications/nistpubs/800-90A/SP800-90A.pdf [3] http://software.intel.com/en-us/articles/intel-sha-extensions -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberat

Re: [liberationtech] getting past that first turtle

2013-09-06 Thread Maxim Kammerer
tech/2013-July/009774.html -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is a public list whose archives are searchable on Google. Violations of list guidelines will get you moderated: https://mailman.stanford.edu/mailman/listinfo/liberationtech. Unsubscribe, change

Re: [liberationtech] Random number generation being influenced - rumors

2013-09-07 Thread Maxim Kammerer
all the specs are open and accessible; when I mentioned that the AES block size in CTR_DRBG is not even specified, I received no response (of course). Also, proponents of feeding RDRAND directly into /dev/[u]random ignore the AES-reducibility of any cryptosystem that uses RDRAND in that fashion. -- M

Re: [liberationtech] Linux distribution on encrypted USB?

2013-09-12 Thread Maxim Kammerer
delay. https://code.google.com/p/cryptsetup/wiki/DMVerity -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is public & archives are searchable on Google. Violations of list guidelines will get you moderated: https://mailman.stanford.edu/mailman/listinfo/liberationtech. Unsub

Re: [liberationtech] The battle for your digital soul

2013-09-12 Thread Maxim Kammerer
gain. Well, that was awkward, almost like a beauty pageant. Also, someone should tell this guy that Charlie Miller is ex-NSA. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is public & archives are searchable on Google. Violations of list guidelines will

Re: [liberationtech] Random number generation being influenced - rumors

2013-09-20 Thread Maxim Kammerer
On Sat, Sep 7, 2013 at 6:21 PM, Maxim Kammerer wrote: > Personally, I wouldn't trust an embedded engineer to > implement bubble sort correctly, and see no reason to trust them with > security-critical implementations, even if one assumes no malice or > subversion of production

Re: [liberationtech] NSA-GCHQ meeting on Tor (with slides!)

2013-10-04 Thread Maxim Kammerer
r Button and Tor Browser Bundle existed in 2007. https://gitweb.torproject.org/torbrowser.git/commit/4633a99 https://gitweb.torproject.org/torbutton.git/commit/74cd0da -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is public & archives are searchable on Google. Vio

Re: [liberationtech] NSA-GCHQ meeting on Tor (with slides!)

2013-10-04 Thread Maxim Kammerer
On Fri, Oct 4, 2013 at 7:20 PM, Griffin Boyce wrote: > I didn't mention the browser bundle ;P It is referenced in slide 7, together with Torbutton. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is public & archives are searchable on Google. Violati

Re: [liberationtech] NSA-GCHQ meeting on Tor (with slides!)

2013-10-04 Thread Maxim Kammerer
t the global passive interception infrastructure is not suitable for correlation-based deanonymization, so NSA/GCHQ need “access to nodes”. But that was 6 years ago. On Fri, Oct 4, 2013 at 7:23 PM, Maxim Kammerer wrote: > On Fri, Oct 4, 2013 at 7:20 PM, Griffin Boyce wrote: >> I didn

Re: [liberationtech] NSA-GCHQ meeting on Tor (with slides!)

2013-10-04 Thread Maxim Kammerer
. [1] https://lists.torproject.org/pipermail/tor-talk/2012-August/025254.html -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is public & archives are searchable on Google. Violations of list guidelines will get you moderated: https://mailman.stanford.edu/

Re: [liberationtech] NSA-GCHQ meeting on Tor (with slides!)

2013-10-06 Thread Maxim Kammerer
his work didn't strike me as particularly impressive. Which is my point. -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is public & archives are searchable on Google. Violations of list guidelines will get you moderated: https://mailman.stanford.edu/mailm

Re: [liberationtech] RiseUp

2013-10-18 Thread Maxim Kammerer
itical systems, or that one of them could be recruited at some point under a suitable ideological pretense — compromising the service in either case. [1] https://www.riseup.net/en/social-contract -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is public & archives are sear

Re: [liberationtech] dark mail alliance

2013-11-01 Thread Maxim Kammerer
does not need SMTP interoperability (let's call this innovative concept “Email 3.0”) can use cables communication [1], which is serverless. [1] http://dee.su/cables -- Maxim Kammerer Liberté Linux: http://dee.su/liberte -- Liberationtech is public & archives are searchable on Google. Violatio

  1   2   >