{"id":6893,"date":"2018-03-29T10:06:19","date_gmt":"2018-03-29T17:06:19","guid":{"rendered":"https:\/\/cldc.org\/?post_type=organizing_resources&#038;p=6893"},"modified":"2022-11-28T14:52:48","modified_gmt":"2022-11-28T22:52:48","slug":"direct-encryption","status":"publish","type":"post","link":"https:\/\/cldc.org\/nl\/direct-encryption\/","title":{"rendered":"Directe versleuteling"},"content":{"rendered":"<p>End-to-End Encryptie is het beste beveiligingsmodel voor communicatie of online opslag van documenten, maar de term is een beetje een mondvol die niet altijd duidelijk is (\u201cde \u201dends' zijn ik en de server, toch?\" \u2014 fout!). Laten we dus proberen een nieuwe term te gebruiken \u2014 <strong>Directe versleuteling<\/strong> \u2014 betekenis: de enige mensen die berichten kunnen ontsleutelen en lezen zijn degenen die direct betrokken zijn bij een priv\u00e9gesprek of project. Cruciaal is dat dit ook de enige mensen zijn die de encryptiesleutels beheren. Directe encryptie is de basis voor veel van onze aanbevelingen: <a href=\"https:\/\/cldc.org\/nl\/gpg\/\">PGP\/GPG\u00a0<\/a><a href=\"https:\/\/cldc.org\/nl\/gpg\/\">(Thunderbird+Enigmail)<\/a>, <a href=\"https:\/\/cldc.org\/nl\/trustworthy-tech\/\">Draad<\/a>, <a href=\"https:\/\/cldc.org\/nl\/signal-activist-best-practices\/\">Signaal<\/a>, en <a href=\"https:\/\/cldc.org\/nl\/trustworthy-tech\/\">Cryptpad<\/a>.<\/p>\n<p>(We hebben deze term deels gekozen vanwege filosofische parallellen met <a href=\"https:\/\/crimethinc.com\/2017\/03\/14\/direct-action-guide\">Directe actie<\/a>, waarbij groepen vaak werken om hun doelen te bereiken in de overtuiging dat machtige entiteiten, zoals de staat of grote bedrijven, niet te vertrouwen zijn. Bovendien betekent een goede beveiligingscultuur dat informatie wordt behandeld op basis van een 'need-to-know'-principe.<\/p>\n<p>Hier zijn enkele afbeeldingen om te illustreren waarom directe versleuteling zo belangrijk is bij priv\u00e9berichten. <a href=\"https:\/\/en.wikipedia.org\/wiki\/Subcomandante_Marcos\">Marcus<\/a> (links) probeert een bericht (Ursula K. Le Guin's The Dispossessed) door te geven aan <a href=\"https:\/\/en.wikipedia.org\/wiki\/Che_Guevara\">Ernesto<\/a> (rechts) met laptops en internet:<img decoding=\"async\" class=\"wp-image-6848 size-large alignleft\" src=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738-1024x516.png\" alt=\"\" width=\"1024\" height=\"516\" srcset=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738-1024x516.png 1024w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738-500x252.png 500w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738-700x353.png 700w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738-200x101.png 200w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738-300x151.png 300w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738-768x387.png 768w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated6-e1518111520738.png 1042w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>Maar de geest van <a href=\"https:\/\/en.wikipedia.org\/wiki\/COINTELPRO\">boze J. Edgar Hoover<\/a> spookt door de infrastructuur. De \u2018Man in the middle\u2019 kan hier elk onbeveiligd bericht dat tussen onze twee helden wordt verzonden, onderscheppen, lezen en wijzigen. Zoals dit:<br \/>\n<img decoding=\"async\" class=\"alignnone wp-image-6849 size-large\" src=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118-1024x516.png\" alt=\"\" width=\"1024\" height=\"516\" srcset=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118-1024x516.png 1024w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118-500x252.png 500w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118-700x353.png 700w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118-200x101.png 200w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118-300x151.png 300w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118-768x387.png 768w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated8-e1518111618118.png 1069w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>(Edgar zou het bericht ook gewoon kunnen lezen en ongewijzigd doorsturen).  Wat de zaak nog erger maakt, is dat de bewering dat een app \u201cversleuteling\u201d gebruikt (zonder specifiek te vermelden wie de sleutels in bezit heeft) geen garantie biedt dat berichten priv\u00e9 en authentiek blijven.\u00a0 Als bijvoorbeeld een server tussen de twee vrienden de versleutelingssleutels beheert, zou iedereen met toegang tot de server alle berichten tussen hen kunnen lezen en wijzigen:<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-6850 size-large\" src=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764-1024x499.png\" alt=\"\" width=\"1024\" height=\"499\" srcset=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764-1024x499.png 1024w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764-500x244.png 500w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764-700x341.png 700w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764-200x97.png 200w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764-300x146.png 300w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764-768x374.png 768w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-TMITM-illuminated-keys-e1518111598764.png 1100w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>Als directe encryptie (end-to-end encryptie waarbij alleen de kameraden de sleutels bezitten) wordt gebruikt, is er geen manier voor een tegenstander om de boodschap te zien of te wijzigen. Hoera! Zo:<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-6946 size-large\" src=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10-1024x509.png\" alt=\"\" width=\"1024\" height=\"509\" srcset=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10-1024x509.png 1024w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10-500x248.png 500w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10-700x347.png 700w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10-200x99.png 200w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10-300x149.png 300w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10-768x382.png 768w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/integrity-fingerprinting10.png 1100w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>Hoe weet u of een app Directe Encryptie gebruikt? Er zal een manier zijn om encryptiesleutels handmatig te verifi\u00ebren \u2014 <a href=\"https:\/\/signal.org\/blog\/safety-number-updates\/\">Signal maakt dit super eenvoudig met veiligheidsnummers<\/a> en <a href=\"https:\/\/support.wire.com\/hc\/en-us\/articles\/207692235-How-can-I-compare-key-fingerprints-\">Wire gebruikt traditionele vingerafdrukken<\/a> dat zal bekend voorkomen bij iedereen die GPG heeft gebruikt. Wire gebruikt een unieke sleutel voor elk van je apparaten, dus het verifi\u00ebren van vingerafdrukken kan omslachtig worden als je vrienden elk meerdere apparaten gebruiken. Het voordeel is echter dat je met Wire of GPG gemakkelijk je vingerafdrukken op meerdere openbare plaatsen kunt plaatsen \u2013 zoals sociale media of de website van je organisatie \u2013 en vrienden kunt vragen om ze te kopi\u00ebren\/plakken\/zoeken om ze te verifi\u00ebren. Ook, <a href=\"https:\/\/support.wire.com\/hc\/en-us\/articles\/207859855-How-can-I-manage-my-devices-on-Wire-\">als een apparaat zoekraakt of wordt gestolen<\/a> u kunt de sleutel op afstand ongeldig maken, zodat het gecompromitteerde apparaat niet langer kan worden gebruikt om versleutelde berichten te lezen of te verzenden.<\/p>\n<p>Onthoud dat het van cruciaal belang is dat elke app voor directe versleuteling open source is, zodat de beveiligingsfuncties ervan kunnen worden gecontroleerd en de beveiliging en gebruiksvriendelijkheid ervan openbaar kunnen worden bekritiseerd en vervolgens verbeterd.<\/p>\n<p>Een andere manier om het risico op blootstelling aan kwaadwillende derden te verminderen, is via peer-to-peer-berichtenverkeer, waarbij vaak wordt gezegd dat er \u201cgeen server\u201d wordt gebruikt om je berichten door te sturen. Deze aanpak kan zeker helpen, vooral als het betekent dat je Google of Facebook niet langer als je chatserver gebruikt.\u00a0 Aan de andere kant kan het argument om \u201cde server\u201d uit je gesprekken te verwijderen misleidend zijn: er zit een enorme hoeveelheid internetinfrastructuur tussen jou en je vrienden in, die voor de meeste gebruikers en apps gewoon onzichtbaar is.  Maar juist deze infrastructuur wordt door de staat misbruikt om verdachtingsloze, grootschalige surveillance uit te voeren.<\/p>\n<p>Blijf veilig daar!<\/p>","protected":false},"excerpt":{"rendered":"<p>End-to-End Encryption is the best security model for communications or online document storage, but the term is a bit of a mouthful that isn&#8217;t always clear (&#8220;the ends are me and the server, right?&#8221; &#8212; wrong!).  So let&#8217;s try using a new term &#8212; Direct Encryption &#8212; meaning: the only people who can decrypt and read messages are those directly involved in a private conversation or project. <\/p>","protected":false},"author":1,"featured_media":4536,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[12],"tags":[203,237,265],"class_list":["post-6893","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-digital-security","tag-fundamentals","tag-trusted-tech"],"acf":[],"_links":{"self":[{"href":"https:\/\/cldc.org\/nl\/wp-json\/wp\/v2\/posts\/6893","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cldc.org\/nl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cldc.org\/nl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cldc.org\/nl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cldc.org\/nl\/wp-json\/wp\/v2\/comments?post=6893"}],"version-history":[{"count":0,"href":"https:\/\/cldc.org\/nl\/wp-json\/wp\/v2\/posts\/6893\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cldc.org\/nl\/wp-json\/wp\/v2\/media\/4536"}],"wp:attachment":[{"href":"https:\/\/cldc.org\/nl\/wp-json\/wp\/v2\/media?parent=6893"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cldc.org\/nl\/wp-json\/wp\/v2\/categories?post=6893"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cldc.org\/nl\/wp-json\/wp\/v2\/tags?post=6893"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}