Tor is building an anonymous instant messenger

Tor is building an anonymous instant messenger

Forget the $16 billion romance between Facebook and WhatsApp. There’s a new messaging tool worth watching.

Tor, the team behind the world’s leading online anonymity service, is developing a new anonymous instant messenger client, according to documents produced at the Tor 2014 Winter Developers Meeting in Reykjavík, Iceland.

The Tor Instant Messaging Bundle (TIMB) is set to work with the open-source InstantBird messenger client in experimental builds released to the public by March 31, 2014. The developers aim to build in encrypted off-the-record chatting and then bundle the client with the general Tor Launcher in the following months.

Pidgin, an older and more popular open-source chat client, was originally considered to be the foundation of the TIMB but was thrown out in favor of InstantBird. However, Tor still plans to hire independent security contractors to audit the new software and test its mettle so that “people in countries where communication for the purpose of activism is met with intimidation, violence, and prosecution will be able to avoid the scrutiny of criminal cartels, corrupt officials, and authoritarian governments.”

Over the long term, TIMB will likely become the messenger of choice for Tor users. Software such as TorChat and BitMessage already have significant userbases and smart advocates, but with the full weight of the Tor Launcher and team behind it, there’s little reason to imagine TIMB won’t succeed.

The creation of the TIMB is yet another step in what has been a years-long improvement in Tor software. A decade ago, the anonymity program was available only to tech-savvy users who knew enough to dive into their operating system’s command line.

Now, the Tor user interface has progressed to the point that almost anyone can anonymously surf the Web with just a few clicks. If TIMB follows in those footsteps, it will be another powerful anonymity tool at the fingertips of of both the tech literate and humanity at large.

The Tor Project, a $2 million per year nonprofit consisting of 30 developers spread out over 12 countries, is pushing forward on TIMB as part of an overall initiative to make Tor even easier to use for the average person. Also in the pipeline are more localized support staff as well as “point-click-publish Hidden Services,” to make it extremely easy for anyone to create a Deep Web site.

When it comes to the sort of security that Tor provides, ease of use is of paramount importance. Many users can’t or won’t take the time to learn about encryption programs like Pretty Good Privacy (PGP), leaving themselves open to surveillance.

Even many patrons of the Deep Web black market Silk Road don’t bother with the simplest encryption tools.

“I post my PGP key everywhere and beg my customers to use it but the majority don't..... including for some pretty big orders!,” popular Silk Road ecstasy vendor DrMDA wrote late last year.

“Something like 80 percent of SR users don't use PGP,” wrote astor, another longtime Silk Roader.

Many people need encryption served up to them on silver platter to even consider it. TIMB is the waiter that plans to deliver.

Secusmart puts its BlackBerry encryption chip to work on the desktop

At around 2,000 (US$2800) each, the secure smartphones that SecuSmart showed at Cebit last year were out of reach of many businessesalthough three governments have since bought them to secure mobile phone calls between senior officials, according to CEO Hans-Christoph Quelle. Now the company has developed a less expensive and more flexible system intended for the enterprise, and has extended the reach of its mobile system to secure VOIP calls on desktop phones.

The SecuSuite smartphone security system is built on the Balance feature of BlackBerry OS 10, which separates business and personal apps and data into two partitions. SecuSmart uses special SD cards containing a cryptographic engine and a keystore to further secure the data in the business partition, and to encrypt voice and data communications made from that partition.

Its new fixed-line product relies on the same SD cards, central key infrastructure and SIP servers used by the smartphone system, but now works with modified desktop VOIP phones from Tiptel and Snom. The phones have a slot for the SD card encryption engine, and additional software that manages the card, and indicates when a call is secured. They will allow government officials to place secure VOIP calls between premises that are not themselves secure.

SecuSmart and its partners have not yet set a price for the new desktop phones. Quelle said it will be less than the price of a BlackBerry Z10 equipped with the secure SD card, but not hugely so.

While SecuSuite is gaining traction in the government market, it can seem overengineered and overpriced to enterprises that only want to encrypt voice traffic because they already have MDM (mobile device management) tools to adequately secure their email and data traffic, Quelle said. Another obstacle, he said, is that businesses are reluctant to replace their and their employees existing smartphones with BlackBerry devices, and want software that works on all platforms.

Its reasonable to assume that enterprises concerned about voice encryption are already securing the platform and the data, and all thats needed is an end-to-end encryption system to prevent eavesdropping on calls, he said. Thats what prompted the company to work with network operator Vodafone Germany on the Secure Call app for Android phones. The app will be ready before the end of the year, he said, echoing the timetable Vodafone gave when it announced the app. Vodafone plans to charge around 10 a month to use Secure Call.

Vodafone offers an existing voice encryption service, also developed by SecuSmart, as part of its Secure SIM offering. To use it, all callers have to have a SIM from Vodafone Germany. Thats a problem for large companies that wish to dual-source services for security of supply or to obtain competitive prices, said Quelle, and its also a challenge for multinationals with employees in other countries.

The new app does all the encryption and key management in software, and is not tied to either an SD card or to the SIM card. That frees up users to choose other operatorsand also frees up SecuSmart. For now, said Quelle, Vodafone has exclusive rights to the app in Germany, but in other countries SecuSmart is free to work with other distributors, operators or not.

The worlds secret services may be about to find the massive interception of phone calls getting a lot harder.

Peter Sayer covers open source software, European intellectual property legislation and general technology breaking news. More by Peter Sayer

Go here to see the original:
Secusmart puts its BlackBerry encryption chip to work on the desktop

Google Expands Search Encryption to China, Elsewhere

Google is now "routinely encrypting" Web searches made by users in China as it goes global with SSL encryption in the wake of spying and privacy scandals.

Google is now "routinely encrypting" Web searches made by users in China, an expansion of search encryption practices the company has been conducting on a limited basis for several years, according to reports.

The move is not specifically aimed at China, which is known to censor the Internet and track the online activity of its citizens, but "rather part of a global expansion of privacy technology designed to thwart surveillance by government intelligence agencies, police and hackers," Google told The Washington Post.

In fact, the Internet giant began encrypting searches conducted by logged-in Google users in late 2011. Last September, in the wake of the NSA spying revelations made by Edward Snowden, Google stepped up its Searching over Secure Sockets Layer (SSL) parameters to cover basically all users of the site, logged in or not, Search Engine Land noted at the time.

Universal or not, as the Post noted, the current expansion of SSL-encrypted search by Google is likely to be an unwelcome development for the Chinese government and officials in other countries which routinely monitor Internet use.

"China's Great Firewall, as its censorship system is known, has long intercepted searches for information it deemed politically sensitive," the Post said. Chinese officials looking for search terms like "Dalai Lama" or "Tiananmen Square" could now be staring at "indecipherable strings of numbers and letters" when examining Google searches.

Thanks to expanded SSL encryption, the governments of countries like China and Saudi Arabia may have a tougher time keeping track of potential dissidents via their Internet browsing. But they still have a powerful arrow in their quiversimply blocking Google from the Internet within their borders, the Post noted.

Meanwhile, in another bit of privacy news, Twitter this week apologized for a bug that exposed nearly 100,000 private accounts to non-approved followers. The microblogging site said it had fixed a glitch that "under rare circumstances, allowed non-approved followers to receive protected tweets via SMS or push notifications since November 2013."

The Twitter SMS bug affected 93,788 protected accounts, the company said in a blog post.

"As part of the bug fix, we've removed all of these unapproved follows, and taken steps to protect against this kind of bug in the future," Twitter's Bob Lord said. "While the scope of this bug was small in terms of affected users, that does not change the fact that this should not have happened. We've emailed each of these affected users to let them know about this bug and extend our whole-hearted apologies."

Continued here:
Google Expands Search Encryption to China, Elsewhere