					                 Privacy and Data Integrity

               Alexander Zangerl (

                             Bond University

Privacy in a Public World?
      ”Privacy, discretion, confidentiality, and prudence are
      hallmarks of civilization.”

Mark Zuckerberg about his very willing sheep
      Mr. Facebook in an IM discussion about his access to lots of
      personal details of his users:
      ’People just submitted it.
      I don’t know why.
      They "trust me".
      Dumb fucks.’

Privacy on a Public Network?!?
      ”sure. that’s what encryption and authentication were
      invented for.”
      unfortunately, the reality is a bit less simple.

privacy versus the law
       claim: ”privacy means the law can’t catch child porn and
       rebuttal: while most people wish that child pornography and
       terrorism did not exist, humanity should not be deprived of
       their freedom to communicate just because of how a very
       small number of people might use that freedom.
       also restricting privacy does not eradicate illegal activity!
              prohibition in the USA in the 1920s

Key Escrow and The Inevitable Outcome
      "Mary had a little key,
      She kept it in escrow
      And everything that Mary sent
      The Feds were sure to know."
      source: Sam Simpson

Privacy vs. Confidentiality
       obverse sides of the same coin
       privacy: keeping /personal/ information secret
       confidentiality: keeping information secret because of
       obligation owed to other party, law etc.
       both are issues mostly centered around access control

     cousin of privacy
     harder to accomplish than just keeping communication private
     but at least as important!
     think censorship, ’political correctness’,

Threats against Privacy
             Rampant Data Collection
             Retention and Feature Creep
             Traffic Analysis
             Software Bugs/Design ”Features” the lead to data leakage
             Web Bugs

Rampant Data Collection
             google sniffing wifi’s when trolling streets

Retention and Feature Creep
      the originally stated usage of your data is a promise that is
      always violated.
             upcoming Oz driving licences

Software Bugs/Design ”Features” the lead to data leakage
      example mis-feature: CSS :visited pseudoclass

      cookies are nice for keeping state during web ”session”,
      but long-term cookies are bad:
      no technical reason
      only good for statistic analysis,
      marketing, advertisement-tracking,
      customer analysis...

Web Bugs
     almost ”invisible” piece of information
     empty images, empty web page
     tracks who is accessing web pages, from where, what browser,

Unwelcome Facts re Confidentiality
      disclosure, controlled or not, permanently relinquishes any
      control over the data
      once data is disclosed it’s out there, forever - especially bad
      for privacy
      (2008: google is estimated to have a few petabytes of data)
      access control is, in the end, the only tool available
      ...but with active components everywhere in our computer
      interaction leakage is hard to control
             having to enable javascript for sites, service using
      overall, privacy policies aren’t worth the non-paper they’re not
      printed on anyway.

Anonymous Proxies
      web proxies that do not keep logs
      some of them actively strip certain headers (referrer,

Anonymous P2P Systems
     not (only/necessarily) for filesharing
     not really anonymous, but hard to trace
     idea: comms in a mesh with messages routed through
     multiple nodes
            mixmaster anon remailers, anon web proxies, anonymous
            electronic money

Anonymous Remailers
      specialized kind of email server
      remailer software strips clean outgoing eamil of any identifying
      remailer operator does not know you, nor wants to
      does not keep logs
      remailers can and should be chained

anon remailer software
      two common kinds of software
             Cypherpunk Remailers
             Mixmaster Remailers

Cypherpunk Remailers
      also called ”Type I” remailer
      accepts messages encrypted with its PGP key.
      specific message format must be followed
      message is then sent in clear to intended recipient

Mixmaster Remailers
      ”Type II” remailer
      accepts messages in the Mixmaster format, not PGP but
      something similar
      messages are multiply encrypted, sent through chains of
      each remailer peels off one layer of encryption
      final one sends out email to recipient
      makes traffic analysis much more difficult!
      also makes messages all the same size (28.1kb), reordering,

(pseudo)nyms and anon remailers
      after remailers done: email has no from anymore
      (well, doh! that’s what anonymity is all about...)
      -> nobody can reply
      solution: use remailers plus nym servers
      nym servers provide anonymous email boxes
      other nym servers allow posting of messages into
      problematic operation nowadays, not many such servers left

Onion Routing
      provides flexible communications infrastructure, resistant to
      eavesdropping and traffic analysis
      application talks to onion proxy, builds anon connection
      through several other onion proxies to the dest
      one layer of encryption for each onion proxy
      each onion proxy removes ”its” encryption layer
             traffic looks different everywhere
             traffic analysis hard to impossible
      real-time and bi-directional communication

The Onion Router
      general-purpose ”onion-routing” system
      similar to remailers but for any TCP-based communication
      visible as SOCKS proxy to client
      traffic is sent using a virtual circuit (chain) made up from
      multiple TOR peers
      each peer only knows the previous and next chain peer, each
      unwraps one layer of encryption
      eventually an ”exit node” sends data in clear to the final
             initial release 2003, then US Naval Res Lab sponsored
             since then supported by EFF, now non-profit organization
      large-scale peer-to-peer network
      pools the power of peers to create a virtual information store
      network is built first and foremost with anonymity in mind
      communication is encrypted and are ”routed-through” other
      makes it difficult to determine who is requesting the
      users contribute bandwidth and data store, no control over
      what is stored, encrypted storage

     decentralised, secure and private p2p networking system
     is an anonymous, distributed, reputation based network
     main appl: censorship-resistant file sharing
     allows anonymous censorship-resistant file-sharing
     effort to ensure anonymity: much higher latency than WWW
     linklevel encryption, anonymity, traffic dispersal
     peers form and use ”opinion” on nearby nodes for request
     contribute to the network -> rewarded with better service
     is leech resistant, uses trust-based economic model

Mixmaster for Anonymous Publishing
      mixmaster is an anonymous email remailer system
      supports onion-routing for email
      one application: anonymously published blogs
      2008: this blog provider unfortunately defunct

Disposable Email
      control the leakage by following the data flows
      use ephemeral, short-lived email addresses
      use MANY different ones, ideally one per not-quite-trusted
      once attracting spam: cancel address, blacklist leaker
      cheap, simple but quite effective
      (my personal setup: one subdomain with list of who got what
      addy, and leaked it when/where)

      most essential tool for keeping leakage in Firefox browsers
      together with ”no cookies, period”, excepting only explicitely
      whitelisted sites
      and not using evil black box tech like flash, silverlight

A Bruce Schneier Quote
      "Trying to make digital files uncopyable
      is like trying to make water not wet."

Unwelcome Facts re Data Integrity
      anything beyond pencil+paper requires trust in the tool
      anything that only computers can do: requires full trust in a
      generally very untrustworthy entity
             physical security, tampering with the hardware, circumventing
             access control etc.

Tamper Resistance
      real tamper resistance for mass-market devices: forget it
             way too costly and cumbersome to mass market
             crypto co-processors like IBM 4758, cheap stuff like iButtons...
             Smart cards like GSM SIM cards...
      practically all of them hackable, as an environment if not
      directly at the hardware level
      best practical outcome: Tamper Evidence (HW) rsp.
      detection of tampering (Data)

A John Gilmore Quote
      "Be very glad that your PC is insecure - it means that
      after you buy it, you can break into it and install
      whatever software you want. What YOU want, not what
      Sony or Warner or AOL wants."

