David Gessel

Yard Berries

Monday, November 4, 2013 

20130804_111745.jpg
Posted at 11:19:54 GMT-0700

Category: GeopostMapphoto

Xabber now uses Orbot: OTR+Tor

Sunday, November 3, 2013 

As of Sept 30 2013, Xabber added Orbot support. This is a huge win for chat security. (Gibberbot has done this for a long time, but it isn’t as user-friendly or pretty as Xabber and it is hard to convince people to use it).

The combination of Xabber and Orbot solves the three most critical problems in chat privacy: obscuring what you say via message encryption, obscuring who you’re talking to via transport encryption, and obscuring what servers to subpoena for at least the last information by onion routing. OTR solves the first and Tor fixes the last two (SSL solves the middle one too, though Tor has a fairly secure SSL ciphersuite, who knows what that random SSL-enabled chat server uses – “none?”)

There’s a fly in the ointment of all this crypto: we’ve recently learned a few entirely predictable (and predicted) things about how communications are monitored:

1) All communications are captured and stored indefinitely. Nothing is ephemeral; neither a phone conversation nor an email, nor the web sites you visit. It is all stored and indexed should somebody sometime in the future decide that your actions are immoral or illegal or insidious or insufficiently respectful this record may be used to prove your guilt or otherwise tag you for punishment; who knows what clever future algorithms will be used in concert with big data and cloud services to identify and segregate the optimal scapegoat population for whatever political crises is thus most expediently deflected. Therefore, when you encrypt a conversation it has to be safe not just against current cryptanalytic attacks, but against those that might emerge before the sins of the present are sufficiently in the past to exceed the limitations of whatever entity is enforcing whatever rules. A lifetime is probably a safe bet. YMMV.

2) Those that specialize in snooping at the national scale have tools that aren’t available to the academic community and there are cryptanalytic attacks of unknown efficacy against some or all of the current cryptographic protocols. I heard someone who should know better poo poo the idea that the NSA might have better cryptographers than the commercial world because the commercial world pays better, as if the obsessive brilliance that defines a world-class cryptographer is motivated by remuneration. Not.

But you can still do better than nothing while understanding that a vulnerability to the NSA isn’t likely to be an issue for many, though if PRISM access is already being disseminated downstream to the DEA, it is only a matter of time before politically affiliated hate groups are trolling emails looking for evidence of moral turpitude with which to tar the unfaithful. Any complacency that might be engendered by not being a terrorist may be short lived. Enjoy it while it lasts.

And thus (assuming you have an Android device) you can download Xabber and Orbot. Xabber supports real OTR, not the fake-we-stole-your-acronym-for-our-marketing-good-luck-suing-us “OTR” (they did, but that link is gone now) that Google hugger-muggers and caromshotts you into believing your chats are ephemeral with (of course they and all their intelligence and commercial data mining partners store your chats, they just make it harder for your SO to read your flirty transgressions). Real OTR is a fairly strong, cryptographically secured protocol that transparently and securely negotiates a cryptographic key to secure each chat, which you never know and which is lost forever when the chat is over. There’s no open community way to recover your chat (that is, the NSA might be able to but we can’t). Sure, your chat partner can screen shot or copy-pasta the chat, but if you trust the person you’re chatting with and you aren’t a target of the NSA or DEA, your chat is probably secure.

But there’s still a flaw. You’re probably using Google. So anyone can just go to Google and ask them who you were chatting with, for how long, and about how many words you exchanged. The content is lost, but there’s a lot of meta-data there to play with.

So don’t use gchat if you care about that. It isn’t that hard to set up a chat server.

But maybe you’re a little concerned that your ISP not know who you’re chatting with. Given that your ISP (at the local or national level) might have a bluecoat device and could easily be man-in-the-middling every user on their network simultaneously, you might have reason to doubt Google’s SSL connection. While OTR still protects the content of your chat, an inexpensive bluecoat device renders the meta information visible to whoever along your coms path has bought one. This is where Tor comes in. While Google will still know (you’re still using Google even after they lied to you about PRISM and said, in court, that nobody using Gmail has any reasonable expectation of privacy?) your ISP (commercial or national) is going to have a very hard time figuring out that you’re even talking to Google, let alone with whom. Even the fact that you’re using chat is obscured.

So give Xabber a try. Check out Orbot, the effortless way to run it over Tor. And look into alternatives to cloud providers for everything you do.

Posted at 08:50:47 GMT-0700

Category: FreeBSDSelf-publishingTechnology

Iraq

Friday, November 1, 2013 

destroyed tank.jpg
There were still souvenirs of the war around in 2013.
Posted at 12:51:24 GMT-0700

Category: photoPlacesTravel

Google outrage at ‘NSA hacking’

Friday, November 1, 2013 

Outrageous, OUTRAGEOUS I says!

Yeah yeah, the NSA didn’t pay you for the data this time?

Google outrage at ‘NSA hacking’

Posted at 01:18:25 GMT-0700

Category: FreeBSDTechnology

India to Impose eMail Restrictions

Thursday, October 31, 2013 

The cloud is public and ephemeral. Never trust important data to anyone else’s hardware.

India and Brazil are getting it. Finally.

The USG is still moving data to the cloud. It will be an interesting day when it is realized the US isn’t the only country companies like Google and Amazon do business in that have national security data access requirements.

India to impose email restrictions

Posted at 00:33:10 GMT-0700

Category: PoliticsTechnology

Cat day

Tuesday, October 29, 2013 

Happy cat day.

20131030_085515.jpg
Posted at 23:05:50 GMT-0700

Category: CatsEventsFunny

Protein Ratios in Food Bars

Thursday, July 4, 2013 

I’ve always been annoyed by the way food nutritional content is reported. It isn’t hard to find a food item with 1,000 calories per serving that claims to be be “high” in iron because it has 5% of the US RDA. The ratio of the RDA of iron to calories would be 1:10. You couldn’t eat enough to get the full allowance of iron in a day and you’d become a human blimp trying.

In an age of obscene abundance, the trick is not so much getting the minimum nutritional value, but getting it at the minimum caloric cost. I looked through some reviews of “good” protein bars and popular ones on Amazon and tabulated the nutritional data in Excel and then computed the ratio of grams of protein to three bad things: kilo-calories, grams of saturated fat, and dollars of cost. Thus, higher values are better. It is interesting to see a huge range in all three values. Sadly, it is common to get closer to the maximum recommended value of saturated fat per day than calories, meaning that eating only enough calories of these “healthy” bars will result in increased risk of disease compared to normal, “unhealthy” food. That’s pretty inexcusable.

protein bars.PNG

I’d like to change the way nutritional labels are printed from hard to read tables presenting only favorable values to simple bar graphs of all basic, essential nutrients, all of which would always be included so that empty calories foods would have a big red block of bar graphs pointing to the left indicating a food that had better be a pleasure to eat to compensate for the lack of nutrition.

But back to food bars: the ratio of protein to calories is a good way to select a food bar for healthy people. Finding one with the best ratio of protein to saturated fat can be important for some people and avoiding the worst ratios is good for everyone. Finding the most protein for your dollar may have merit as well (though prices are just Amazon prices and may vary significantly by outlet).

The Excel table for your editing pleasure protein bars.xlsx

Posted at 11:55:41 GMT-0700

Category: ReviewsTechnology

Yahoo account PSA

Sunday, March 17, 2013 

Yahoo Logo

It seems that if you have a yahoo mail account it either already has or  will soon be hacked. There’s some news out there about this…..

Yes, how could you not be sure that when somebody offers to host your  personal data for free on their servers that nothing could possib-lie go  wrong. Uh, PossibLY go wrong.

Posted at 08:08:01 GMT-0700

Category: PoliticsSelf-publishingTechnology

posthumous hack

Monday, March 11, 2013 

I just got an email from a friend of mine, which might not seem particularly atypical, and this turned out to be hack-spam from his Yahoo account. What was jarring about seeing mail from him in my inbox is that he has been dead for six months.

IRL, we move people to cemeteries or other repositories of the dead and keep our interaction space for the living. On social networks and other digital interaction spaces, there’s no particular cost and some respect shown by leaving the presence of those that have passed as it was when they last touched it. But in time, all social networks will fill with the static presence of the passed on. It may be a little less cheerful to log in to facebook when your friend’s list is dominated by those who can no longer answer a poke.

Posted at 16:51:20 GMT-0700

Category: Odd

A Day Out And About In Basra

Sunday, March 10, 2013 

A day spent out reviewing alternate sites where unexpected underground obstructions impact construction means a chance to make new friends.

Iraqi Guards.jpg
Two of the excellent officers assigned to our detail get us through traffic and keep us safe.

New Friends.jpg

These days the attention we attract is welcome and fun.

Posted at 08:11:06 GMT-0700

Category: GeopostPlacesTravel