{"id":6893,"date":"2018-03-29T10:06:19","date_gmt":"2018-03-29T17:06:19","guid":{"rendered":"https:\/\/cldc.org\/?post_type=organizing_resources&#038;p=6893"},"modified":"2022-11-28T14:52:48","modified_gmt":"2022-11-28T22:52:48","slug":"direct-encryption","status":"publish","type":"post","link":"https:\/\/cldc.org\/hi\/direct-encryption\/","title":{"rendered":"Direct Encryption"},"content":{"rendered":"<p>End-to-End Encryption is the best security model for communications or online document storage, but the term is a bit of a mouthful that isn&#8217;t always clear (&#8220;the ends are me and the server, right?&#8221; &#8212; wrong!).\u00a0 So let&#8217;s try using a new term &#8212; <strong>Direct Encryption<\/strong> &#8212; meaning: the only people who can decrypt and read messages are those directly involved in a private conversation or project.\u00a0 Crucially, these are also the only people who control the encryption keys.\u00a0 Direct Encryption powers many of our recommendations: <a href=\"https:\/\/cldc.org\/hi\/gpg\/\">PGP\/GPG\u00a0<\/a><a href=\"https:\/\/cldc.org\/hi\/gpg\/\">(Thunderbird+Enigmail)<\/a>, <a href=\"https:\/\/cldc.org\/hi\/trustworthy-tech\/\">Wire<\/a>, <a href=\"https:\/\/cldc.org\/hi\/signal-activist-best-practices\/\">Signal<\/a>, and <a href=\"https:\/\/cldc.org\/hi\/trustworthy-tech\/\">Cryptpad<\/a>.<\/p>\n<p>(We chose this term in part because of philosophical parallels to <a href=\"https:\/\/crimethinc.com\/2017\/03\/14\/direct-action-guide\">Direct Action<\/a>, wherein groups often work to achieve their goals in the belief that powerful entities, like the State or large corporations, cannot be trusted.\u00a0 Also, good security culture practice means information is handled on a need-to-know basis.)<\/p>\n<p>Here are some pictures to illustrate why Direct Encryption is so important in private messaging. <a href=\"https:\/\/en.wikipedia.org\/wiki\/Subcomandante_Marcos\">Marcos<\/a> (left) is trying to get a message (Ursula K. Le Guin&#8217;s the Dispossessed) to <a href=\"https:\/\/en.wikipedia.org\/wiki\/Che_Guevara\">Ernesto<\/a> (right) using laptops and the Internet:<img decoding=\"async\" class=\"wp-image-6848 size-large alignleft\" src=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738-1024x516.png\" alt=\"\" width=\"1024\" height=\"516\" srcset=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738-1024x516.png 1024w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738-500x252.png 500w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738-700x353.png 700w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738-200x101.png 200w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738-300x151.png 300w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738-768x387.png 768w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738.png 1042w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>But the ghost of <a href=\"https:\/\/en.wikipedia.org\/wiki\/COINTELPRO\">mean old J. Edgar Hoover<\/a> haunts the infrastructure. The Man in the middle here is able to intercept, read, and change any unprotected message sent between our two heroes. Like so:<br \/>\n<img decoding=\"async\" class=\"alignnone wp-image-6849 size-large\" src=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118-1024x516.png\" alt=\"\" width=\"1024\" height=\"516\" srcset=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118-1024x516.png 1024w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118-500x252.png 500w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118-700x353.png 700w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118-200x101.png 200w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118-300x151.png 300w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118-768x387.png 768w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118.png 1069w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>(Edgar could also just read and send the message along unaltered).\u00a0 To make matters worse, saying that an app uses &#8220;encryption&#8221; (without being specific about who holds the keys) doesn&#8217;t guarantee that messages remain private and authentic.\u00a0 For example, if a server between the two comrades is managing the encryption keys, anyone with access to the server could read and modify all messages between them:<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-6850 size-large\" src=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764-1024x499.png\" alt=\"\" width=\"1024\" height=\"499\" srcset=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764-1024x499.png 1024w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764-500x244.png 500w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764-700x341.png 700w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764-200x97.png 200w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764-300x146.png 300w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764-768x374.png 768w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764.png 1100w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>If Direct Encryption (end to end encryption where only the comrades hold the keys) is used, there is no way for an adversary to see or alter the message.\u00a0 Hooray!\u00a0 Like so:<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-6946 size-large\" src=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10-1024x509.png\" alt=\"\" width=\"1024\" height=\"509\" srcset=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10-1024x509.png 1024w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10-500x248.png 500w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10-700x347.png 700w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10-200x99.png 200w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10-300x149.png 300w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10-768x382.png 768w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10.png 1100w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>How do you know whether an app is using Direct Encryption?\u00a0 There will be some way to manually verify encryption keys &#8212; <a href=\"https:\/\/signal.org\/blog\/safety-number-updates\/\">Signal makes this super easy with safety numbers<\/a> and <a href=\"https:\/\/support.wire.com\/hc\/en-us\/articles\/207692235-How-can-I-compare-key-fingerprints-\">Wire uses traditional fingerprints<\/a> that will be familiar to anyone who&#8217;s used GPG.\u00a0 Wire uses a unique key for each of your devices, so verifying fingerprints can get cumbersome if your friends each use multiple devices.\u00a0 The advantage, though, is that with Wire or GPG it&#8217;s easy to post your fingerprints in multiple public places &#8212; like social media or your organization&#8217;s website &#8212; and ask friends to copy\/paste\/find to verify them.\u00a0 Also, <a href=\"https:\/\/support.wire.com\/hc\/en-us\/articles\/207859855-How-can-I-manage-my-devices-on-Wire-\">if a device is lost or stolen<\/a> you can remotely invalidate its key so the compromised device can no longer be used to read or send encrypted messages.<\/p>\n<p>Remember, it&#8217;s crucial that any Direct Encryption app is open source, so that its security features can be verified, and its security and usability can be publicly criticized then improved.<\/p>\n<p>Another way to reduce exposure to a malicious interloper is through peer-to-peer messaging, where it is commonly said that there is &#8220;no server&#8221; used to relay your messages.\u00a0 This approach can certainly help, especially if it means moving away from Google or Facebook as your chat server.\u00a0 On the other hand, the argument about removing &#8220;the server&#8221; from your conversations can be misleading: there is a ton of Internet infrastructure in between you and your friends, it&#8217;s just invisible to most users and apps.\u00a0 But this infrastructure is precisely what the State exploits to conduct suspicionless, mass surveillance.<\/p>\n<p>Stay safe out there!<\/p>","protected":false},"excerpt":{"rendered":"<p>End-to-End Encryption is the best security model for communications or online document storage, but the term is a bit of a mouthful that isn&#8217;t always clear (&#8220;the ends are me and the server, right?&#8221; &#8212; wrong!).  So let&#8217;s try using a new term &#8212; Direct Encryption &#8212; meaning: the only people who can decrypt and read messages are those directly involved in a private conversation or project. <\/p>","protected":false},"author":1,"featured_media":4536,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[12],"tags":[203,237,265],"class_list":["post-6893","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-digital-security","tag-fundamentals","tag-trusted-tech"],"acf":[],"_links":{"self":[{"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/posts\/6893","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/comments?post=6893"}],"version-history":[{"count":0,"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/posts\/6893\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/media\/4536"}],"wp:attachment":[{"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/media?parent=6893"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/categories?post=6893"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/tags?post=6893"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}