Sinisterly
Charon's Encryption & Anonymity guide! - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Computers (https://sinister.ly/Forum-Computers)
+--- Forum: Networking (https://sinister.ly/Forum-Networking)
+---- Forum: Anonymity (https://sinister.ly/Forum-Anonymity)
+---- Thread: Charon's Encryption & Anonymity guide! (/Thread-Charon-s-Encryption-Anonymity-guide)

Pages: 1 2 3 4


RE: Charon's Encryption & Anonymity guide! - yokai_old - 05-29-2013

(05-29-2013, 06:36 AM)Foulplay Wrote: Good guide and I think the entire community can build upon it and update it as it needs so that we can compile a educational and thorough guide.
One suggestion is to add a section for secure removal/deletion of a file.

What is there to know, do you want him to write a guide on data retention, that is so extensive it would take thousands of pages lol. When in doubt, shred -fuvzn 69 file.jew. LOL @ the butt hurt rep, I can be arrogant if I want, how about you challenge me buddy.

(05-29-2013, 06:25 AM)Der Anarchist Wrote: I think you're speaking of Mcrypt? Tongue

Not mcrypt, this is just a better replacement for tc; I found it btw..."tcplay" is what it's called.


http://jasonwryan.com/blog/2013/01/10/truecrypt/
also: https://code.google.com/p/zulucrypt/


RE: Charon's Encryption & Anonymity guide! - w00t - 05-29-2013

(05-29-2013, 06:22 AM)better_than_you Wrote: you never know, truecrypt could be backdoored (loll), tho it's open src, it hasn't really been re properly, and the details about the devs is unknown (possible cia agents, rofl)

Truecrypt is open-source, no RE is needed to point out obvious flaws( backdoors in something implementing crypto are pretty obvious )

That's not even true. Use this, search for #925625, or mark containing Truecrypt. Has an address, and a name.

(05-29-2013, 06:22 AM)better_than_you Wrote: you should be fine, if you use TC, use whirlpool because we all know the NSA backddored ur sha512


always use pgp nigga

The irony should be clear here. You claim that the NSA backdoored SHA-512, which would mean PGP signing would be broken. Not to mention that, same as truecrypt, it's open source, which would make all mistakes glaring mistakes.

It's also funny because it demonstrates your lack of knowledge of how Truecrypt works. The hashing algorithm's security makes no difference in security. The hash is used to determine if your key seems correct before attempting to decrypt with it. Obviously if your key is common enough to be found in a database of hashes, you're in trouble, but past that it really doesn't matter.


EDIT:
better_than_you Wrote:When in doubt, shred -fuvzn 69 file.jew.

All fine and well unless you use a filesystem newer than ext2.


RE: Charon's Encryption & Anonymity guide! - yokai_old - 05-29-2013

(05-29-2013, 07:57 AM)w00t Wrote: Truecrypt is open-source, no RE is needed to point out obvious flaws( backdoors in something implementing crypto are pretty obvious )

That's not even true. Use this, search for #925625, or mark containing Truecrypt. Has an address, and a name.


The irony should be clear here. You claim that the NSA backdoored SHA-512, which would mean PGP signing would be broken. Not to mention that, same as truecrypt, it's open source, which would make all mistakes glaring mistakes.

It's also funny because it demonstrates your lack of knowledge of how Truecrypt works. The hashing algorithm's security makes no difference in security. The hash is used to determine if your key seems correct before attempting to decrypt with it. Obviously if your key is common enough to be found in a database of hashes, you're in trouble, but past that it really doesn't matter.


EDIT:

All fine and well unless you use a filesystem newer than ext2.

I thought the way I was talking would make it obvious I was being sarcastic.."cia agents", file.jew? I don't know, maybe I won't attempt it anymore, and uh last time I checked, stuff like DBAN is pointless, and yes the shred thing was a joke. What I do know is that no one should rely on ssds, file recovery is extremely easily, I've read papers and conducted a few trials of my own, lol. But I don't like the truecrypt license, it isn't true open source, but that can be debated. I know quite thoroughly how truecrypt works lol..and I wouldn't rely on plausible denials because

1. headers
2. incase I store in memory, eh..
3. if I was to open a textfile or something, recent files /media/mytotallynothiddenparttition/test/lol.txt then that would be hard to explain
just in general you have to be careful with it, just like if you were using a vpn you'd want to setup iptables to make sure incase your connection drops nothing gets routed


RE: Charon's Encryption & Anonymity guide! - w00t - 05-29-2013

It's pretty open source. It isn't free software, in the sense that it doesn't adhere to a GNU-esque license that allows anyone to modify it and redistribute it.

Plausible deniability encryption is pretty pointless, seeing as it's not really plausibly deniable to have encrypted bytes in a specific part of a HDD.

Yes, open source software gets exploited all the time. The wonderful thing about encryption is the only exploits that would matter would be the encryption functions themselves, and how they are used, and since those are both standardized, it's trivial( and common ) for cryptologists to audit the standard routinely.


EDIT: Found the exploit. That's just sad.


RE: Charon's Encryption & Anonymity guide! - yokai_old - 05-30-2013

TC license is and probs always will be a nigger


RE: Charon's Encryption & Anonymity guide! - Complibur - 07-30-2013

Wow great guide man. Read the whole thing and it is amazing!


RE: Charon's Encryption & Anonymity guide! - Oni - 09-13-2013

(05-21-2013, 09:37 PM)Unmasked Wrote: Very good guide and yes Tor is the most unsafe thing you can possibly use if doing anything bad as anyone can make exit nodes and the FBI has quite a few of them.

That would only be if the data you are sending is sensitive, they can't verify the sender (if I'm not mistaken).


RE: Charon's Encryption & Anonymity guide! - w00t - 09-13-2013

You would be correct, if you're sending things without https or other forms of encryption, the exit node knows what you're sending. What the exit node does NOT know is who you are.


RE: Charon's Encryption & Anonymity guide! - Complibur - 09-13-2013

Nice guide man. Although I think this just got bumped up. I didn't check the date.


RE: Charon's Encryption & Anonymity guide! - Ghost - 09-13-2013

Thanks for the share i know alot of people are going to like this!