Login Register


Charon's Encryption & Anonymity guide! filter_list
Author
Message
Charon's Encryption & Anonymity guide! #1

Charon's Encryption & Anonymity guide!



I didn't see any anonymity guide on Sinisterly and I thought it would be a good idea to make one. So here we go! Smile


Table of Contents

1 - Encrypting, and what is a better OS for encryption(Windows versus Linux)
2 - Secure communications
3 - The Browser
4 - Hiding your IP address
5 - The DNS and the WiFi


Encrypting, what is a better OS for encryption, Windows or Linux?

The debates about Linux versus Windows, they'll never stop. Personally I dislike windows for anonymity simply because you make yourself really vulnerable.
Now you're probably wondering why Windows makes you vulnerable? The answer is simple Windows is backdoored, I am not going to explain here how and stuff you can look that up yourself.
But don't let yourself down, there's a solution: Linux! Linux users are much safer and it's not backdoored except for Ubuntu 11.04 and up,spyware has been found in there.
So if you want to use Ubuntu you should recompile the source of ubuntu, find the back door and remove it. So I really won't be covering Windows much in this tutorial.

Encryption and Secure communications
A very important thing to begin with anonymity is within your own system and the way you communicate. There is something you have to understand anonymity and Security are two different things. They are alike but fundamentally different.
How? Anonymity like I stated before is the state of being anonymous and security prevents thing from being exploited.

The Encryption
Let's start with some basic encryption. Since we are using Linux/Unix based systems all the programs we will be using will have to do with these Operation systems.

Programs:
Truecrypt: Truecrypt is mostly seen on Windows but it is also compatible with Linux.

-LVM2
LVM is suitable for:
Managing large hard disk farms by letting you add disks, replace disks, copy and share contents from one disk to another without disrupting service (hot swapping).
On small systems (like a desktop at home), instead of having to estimate at installation time how big a partition might need to be in the future, LVM allows you to resize your disk partitions easily as needed.
Making backups by taking "snapshots".
Creating single logical volumes of multiple physical volumes or entire hard disks (somewhat like RAID 0, but more similar to JBOD), allowing for dynamic volume resizing.
You can find it more info and installation here:
http://sourceware.org/lvm2/

New Kali Linux has LVM install for setup when you first install it on your PC or etc.

-cryptsetup(LUKS)
LUKS is the standard for Linux hard disk encryption. By providing a standard on-disk-format, it does not only facilitate compatibility among distributions,
but also provides secure management of multiple user passwords. In contrast to existing solution, LUKS stores all setup necessary setup information in the partition header, enabling the user to transport or migrate his data seamlessly.
You can get it here:
http://code.google.com/p/cryptsetup/

Data Encryption(OTP)
The next part will be data encryption. I recommend to only encrypt important/dangerous files, so don't encrypt everything. A good and the uncrackable method of data encryption is called One-Time Pad(OTP)
" is a type of encryption which has been proven to be impossible to crack if used correctly. Each bit or character from the plaintext is encrypted by a modular addition with a bit or character from a secret random key (or pad) of the same length as the plaintext, resulting in a ciphertext. If the key is truly random, as large as or greater than the plaintext, never reused in whole or part, and kept secret, the ciphertext will be impossible to decrypt or break without knowing the key. It has also been proven that any cipher with the perfect secrecy property must use keys with effectively the same requirements as OTP keys. However, practical problems have prevented one-time pads from being widely used. "
[Image: 310px-One-time_pad.svg.png]

Secure communications

If you want to be really anonymous, you need to be anonymous in the virtual world but also somewhat in the real world. If not doxing could happen, and your really don't want your real identity compromised.
Here I'll list some things that can possibly compromise your identity:
• Social networking (Your Facebook, Twitter)
• Your E-mail(For example someone could send $0.01 to your PayPal's email and have your full name and address)
• Pictures
• Webcam(Obviously)
• IM

Now I'll tell you how to prevent these things.

Social Networking:
If you want to have 100% anonymity then don't even use this, especially Facebook.

E-mail:
If you want 100% anonymity then do not use Gmail, Yahoo, Hotmail they're not safe. If you do any suspicious they will just tell the feds.
Email services like Tormail, Privacybox are secure. Even though if you really want to stay secure and anonymity, you will need to use PGP(Pretty Good Privacy) which I will explain later.

Pictures:
Picture's have EXIF data, that can reveal some things such as where you took the picture, with what etc. To prevent these remove the EXIF data from it.


IM(Instant messaging)
Now almost everyone uses IM. Skype, Jabber, ICQ etc.
This can be dangerous if you do not know how to configure it properly. For example Skype you should use a proxy/VPN because someone could just resolve your Skype and have your IP.
Jabber is secure and good for anomymity. But in my opinion IRC is the best.
You can have your IRC private and it allows spoofed connection.

Some other ways to secure communication:
Steganography

Steganography
Hiding a message inside a image.
[Image: 9GB7FM1.jpg]
http://en.wikipedia.org/wiki/Steganography

Hiding your IP address
Hiding your IP is something almost everyone with a brain can do, but just opening TOR or a VPN is not enough. I will explain it to you why.
TOR is really vulnerable if not using correctly, and it has been proven multiple times.
VPNs can also be really vulnerable if your DNS is leaking. Flash will also always give away your real IP. Now you're probably wondering how to prevent this. You can prevent this by using JonDo.
Jondo is like TOR but it encrypts everything and does not relay on exit nodes. The second thing would be using sock5(SSH tunneling) Or use a RDP.

Check the links at the end of the tutorial why TOR is vulnerable and where to download JonDo.
Also remember programs will always keep logs no matter what.

The Browser:
Alright to start of, if you want 100% anonymity you don't want to use Chrome, Firefox, Internet Explorer, Safari, Opera.
I still do use Firefox because I really do not need that much anonymity.
But here are some good lightweight browsers, and do not safe any passwords in your browser.

1- Uzbl http://uzbl.org/
2- Midori http://twotoasts.de/
3- IceCat http://www.gnu.org/software/gnuzilla/


These 3 browsers are all open source.

If using Firefox:
You should disable JavaScript or install Noscript. I also recommend not to use too much plugins. The more the plugins the more vulnerable you are. You also want to disable cookies and history and use incognito mode.
You also want to install NoScript.



Search Engines:
-IxQuick/StartPage - https://www.ixquick.com/
-DuckDuckGo - https://duckduckgo.com/
-Yippy - http://yippy.com/


The DNS and the WiFi
Your DNS and WiFi can be really a risk, especially by the feds. For WiFi you can encrypt your connection or to go public places(Starbucks etc).

Now for the DNS, you really do not want your DNS leaked(If you're using a VPN or something)
You can check that here: http://www.dnsleaktest.com
The best thing to do would be to change your DNS, here are some secured DNS's for you.
-OpenDNS http://www.opendns.com/technology/dnscrypt/
- OpenNIC - http://www.opennicproject.org/
- ValiDOM - http://validom.net/blog/2009/04/21/freie...n-validom/




Links:
http://www.youtube.com/watch?v=bI_1qlcwfE0 (TOR vulnerabilities)
https://anonymous-proxy-servers.net/en/jondo.html (JonDo)
http://sourceware.org/lvm2/ (LVM2)
http://code.google.com/p/cryptsetup/ (Cryptsetup)
http://www.dnsleaktest.com (Test if your DNS is leaking)
[Image: bAMEI93.jpg]


Jabber: charon@exploit.im

[+] 1 user Likes Charon's post
Reply

RE: Charon's Encryption & Anonymity guide! #2
Great guide! Will definitely be doing some upgrading on my anonymity.
kawaii~desu

Reply

RE: Charon's Encryption & Anonymity guide! #3
Glad you liked it Silica!
[Image: bAMEI93.jpg]


Jabber: charon@exploit.im

Reply

RE: Charon's Encryption & Anonymity guide! #4
This is a very good tutorial Charon, I can't wait for more.

Reply

RE: Charon's Encryption & Anonymity guide! #5
I had this big post typed up but I accidently closed the window, so I'll summarize.

Tor is secure. The underlying network has yet to be broken. It's up to the user whether they stay anonymous.

OTP is pointless on the internet. If a connection is secure enough to send the key, why not just send the message?

PGP is less secure than OTP encryption. That being said, if you use a large key of a secure cipher, you should be fine.

Reply

RE: Charon's Encryption & Anonymity guide! #6
(05-21-2013, 12:55 AM)w00t Wrote: OTP is pointless on the internet.
This guide is online and offline.
[Image: bAMEI93.jpg]


Jabber: charon@exploit.im

Reply

RE: Charon's Encryption & Anonymity guide! #7
Very nice share, Charon. It will be very useful.
[Image: tenor.gif]

🍫  🍬 🎀

Reply

RE: Charon's Encryption & Anonymity guide! #8
(05-21-2013, 01:06 AM)Charon Wrote: This guide is online and offline.

I don't know why I specified online. If you have a secure way to communicate the key, you may as well give the message instead.

Reply

RE: Charon's Encryption & Anonymity guide! #9
(05-21-2013, 01:50 AM)w00t Wrote: I don't know why I specified online. If you have a secure way to communicate the key, you may as well give the message instead.

This is true, however people prefer to communicate with PGP keys.
[Image: bAMEI93.jpg]


Jabber: charon@exploit.im

Reply

RE: Charon's Encryption & Anonymity guide! #10
Very good guide and yes Tor is the most unsafe thing you can possibly use if doing anything bad as anyone can make exit nodes and the FBI has quite a few of them.

Reply







Users browsing this thread: