“When I was in Hong Kong, I spoke to my partner in [Rio de Janeiro] via Skype and told him I would send an electronic encrypted copy of the documents,” Greenwald noted. “I did not end up doing it. Two days later his laptop was stolen from our house and nothing else was taken. Nothing like that has happened before. I am not saying it’s connected to this, but obviously the possibility exists.”
If I am paying so much money for our awesome military industrial complex, I would AT LEAST expect them to know how to stage the house to make it look like a robbery. Or copy the hard drive and then bug the machine & router to intercept all future communications.
If the government really did break in and just stole his laptop, this is like the least cool spy thriller ever.
> If I am paying so much money for our awesome military industrial complex, I would AT LEAST expect them to know how to stage the house to make it look like a robbery.
On the other hand, if this wasn't done by a government then it really is what a robbery looks like!
To be fair, exactly this happened to a friend of mine living in Fulham, London. His laptop (a very pricey MacBook) was visible through the window from the street. Someone was in through the (old, poorly-secured) window and back out with the laptop within a couple of minutes whilst my friend was in the shop across the street. Didn't check the bedroom for jewelry, didn't take his expensive decks or TV - just grabbed the laptop and left. It seems some thieves do specialise - either that, or my mate is into some other stuff I don't know about and had just been told he was going to receive an encrypted file...hmmm.
When I was robbed they ransacked my apartment. They went through the couch, luggage, kitchen cabinets, took the TV, my change jar, bed sheets(probably to wrap up their loot). It looked the way it does in movies.
Yes but you work the odds of the robbery happening right after the Skype call and then the thieves taking just the laptop where some of the most valuable pieces of intel are. Anything is possible, but...
On another note, if Snowden wasn't in HK, CIA would have already "paid him a visit" or five. Probably each of them was shadowed by dozens of Chinese ones so they couldn't take the risk.
They may have heard a sound, assume they may be about to be discovered, and just scarpered with what the already had in their hands (which just happened to be the laptop).
My car was broken into a few years back and all the thief took was my school books sitting in the back seat. My iPod was even sitting in the cup holder on a pile of loose change.
Doesn't make sense. Implication: USG was listening to GG's Skype conversations, heard him say he would send big encrypted file, USG stole laptop. But GG says he never did send the big encrypted file. So they're supposedly spying on him, but not well enough to notice the non-transmission of the encrypted material.
You assume that they have full access to all comms in and out of the system; it's entirely possible that a transmission could have happened outside of a monitorable band (for example, mega.com).
To those without the key, an HTTPS download of a porn video is entirely indistinguishable from a tarball of state secrets.
Perhaps they didn't want to take the risk that the file somehow got past them (they failed to detect/recognize it, or it was sent another way (courier, etc.)).
Maybe there was a transmission of encrypted material (from a third party, something completely unrelated) and since it'd be difficult to determine if it was Snowden's they chose to take it anyways. (this is all, of course, presuming that the USG was responsible)
> If I am paying so much money for our awesome military industrial complex, I would AT LEAST expect them to know how to stage the house to make it look like a robbery. Or copy the hard drive and then bug the machine & router to intercept all future communications.
You forget the fact that the majority of operative work abroad is done by minimum wage hired thugs who don't give a single fuck about the intricacies of the execution of the task at hand; they probably even like the fact that they can help make the US look like a bunch of morons.
ASK HN: How Does Edward's Dead Man Switch(EDMS) Function?
How?
So, there are these remote backups/sites out there, encrypted. Say, every week ES has somebody Bob post a keyword somewhere, a forum, pastebin, etc. The owner(s) Alice, Doreen, Glen, etc... of these backup sites manually or 'auto-crontab' for this keyword, or coded sequence of keywords, if so, fine, steady as Edward goes.
If not, .... ES released his hand(See hyperventilated Dyson's DMS in Terminator II film) sprung trigger. NOT good:
This interrupts the auto-cron periodic keyphrase(word) update and the toothpaste tubes are vigorously flattened, and you can't get the toothpaste back in.
(How? ie, How does EDMS trigger release become known to remote system trigger manager Bob or crontab daemon?)
Neighbor Bob check's local lampposts for Ed's new white tape once a week?
This is needlessly complex. Just find people that you trust to hold onto the key, and a few other people to hold onto the file. People who's priorities are aligned properly and are use to being leaned on (journalists and/or activists). When they read in the New York Times that Edward Snowden is dead, some or all of them publish.
If you are worried about one of those people colluding with another to get the secret sauce too early, then split the secret. Give it to 50 people and require any 10 of them to release their material. Or whatever, you can tune it how you like depending on how many people you trust and how much you trust them. Automation is unnecessary.
Give group A the encrypted data. Give group B the encryption keys. Give group C the email addresses of group A and group B. Give them all their instructions on when to "pull the trigger", either through a period of lack of communication or events in the media or something else.
# cat /etc/cron.daily/dead-man-switch
#!/bin/bash
wget -O latest https://raw.github.com/asdf/feab/data.txt
if [ ! grep `date +%m%d%Y` latest ] ; then
echo "The key is uRYB9vCT53jCSkjzaf9b" | mail -s "I'm dead." glenn.greenwald@...
fi
Wouldn't be hard to run this on a few random computers around the world pretty anonymously. The NSA getting the key isn't too big of a deal.
Of course, you'd want to test this and make it more fault tolerant.
"Good morning Mr Snowden? How was your sleep last night? Oh yes, that's right, you didn't get any.
So to begin with, No I will not get that light out of your face, What was this you or Mr Greenwald mentioned about having your distributed files securely backed up, and have you a deadman switch Mr Snowden, you understand, in case of your demise? .... a bash shell script? Why the hell you didn't you use python?! This is going to be a problem. How are we going to fix it?"
It could work, but I know that if I were in Snowden's place I would be more keen on relying on people, and not having to "phone home" (I am fairly confident that news of his demise or "disappearance" would eventually become public).
Find one, know the page, obtain the logs who accessed the page, find all. Or catch Snowden and keep updating the page yourself. Not that it can not be done in a similar way but it is non-trivial to get it right.
POST EDMS triggered launch, a simmering autonomous viral botnet, foisting ES plaintext onto infected email address lists, pastebin, etc., anything else it can fool CAPTCHA registration, with generating SHA256 signatures, new passwords, the whole open source kitchen sink of paranoidal-crypto-craft to effect public-at-large propagating whistle-blaring incriminating secrets, successfully leaked.
If you are worried about one of those people colluding with another to get the secret sauce too early, then split the secret. Give it to 50 people and require any 10 of them to release their material. Or whatever, you can tune it how you like depending on how many people you trust and how much you trust them. Automation is unnecessary.
This is, in fact, practical to do with Reed Solomon codes.
Um, well, er... no, I prefer crontab. It has let me down far fewer times than mortals.
EDIT: An agent running on some VM somewhere isn't that tough to implement. You could do it from a friggin' R-Pi. If the "all clear" isn't posted where it is supposed to be, let the monkeys loose. (Kids in the Hall" reference, fwi)
> I prefer crontab. It has let me down far fewer times than mortals.
This opens lifestyle guidance for our aspiring youth:
Prefer crontab. It will let you down far fewer times than mortals.
Choose bitcoin over any Ben Bernake or Alan Greenspan currency.
Believe Snowdenspeak over Clapperspeak, Kieth Alexander's mouth moving, or any Obama-ism.
Go to lunch with Richard Stallman before that mean looking bald-headed angry man with that desperate hunted rictus fixed to his face, who works at Microsoft, but not for much longer.
I agree this is wayyy complicated. All you do is send the encrypted data to whomever you want and then have some servers check an email every day to see if it got an email from snowden indicating the date. If its there repeat tomorrow else email key to journalists/publish on the internet.
ES is vulnerable if physically must be connected. Ideally, if he does a single-bit "I'm alive today" `annnuciator flag', say, once a week, and if this get's interrupted, his total autonomous bot wakes up swinging email, postings, and HWALL w3-wide `Guardian-class Bombshells'.
I believe any organization worth its salt that has NSA/CIA as enemy would have thought of something better and easier for a fail-safe device, an insurance on their lives if you will. Wikileaks has an insurance of this form.
Post encrypted file to everyone. Probably there is several VMs checking in or even scraping most news sites for "Assange dead", and if that happens, pastebin the keys. And even this is complicated.
If I would need a dead-man switch, Id include people I trust to release the keys, or parts of the keys in case I need to trust several people to be in agreement at the same time.
A technological solution in case I cant trust anyone, then I would run several php scripts on those free hosting sites, or get a plan with heroku or redhats openshift, all of which check for updates from my sock puppet accounts on facebook, g+ and email, weekly or so. Say every other update on at least one of the public services must contain a secret codeword in hidden form like first letter of each sentence or rot3 of those. If no updates are found for three weeks on all the sites, or if the codeword is not there two times, pastebin the keys all over the internets.
"Rio de Janeiro has been rated “Critical” for crime by the State Department for the past 25 years. Crimes statistics for 2012 reflect continued critically high and rising levels of crimes in both the state and city of Rio de Janeiro in the categories of robbery, rape, fraud, and residential thefts." [1]
"The high level of residential burglary has made most residents opt to reside in apartments where the “porteiro” (doorman) ensures 24/7 access control for the building. Having effective access control is critical."
So, NSA supposedly has access via PRISM to direct access to Microsoft servers, and yet they supposedly have to go steal a laptop to get access to sent files ?
Reminds me of the time the house I was renting with a bunch of other international students was broken into and obviously searched, but nothing was taken, not even cash.
“When I was in Hong Kong, I spoke to my partner in [Rio de Janeiro] via Skype and told him I would send an electronic encrypted copy of the documents,” Greenwald noted. “I did not end up doing it. Two days later his laptop was stolen from our house and nothing else was taken. Nothing like that has happened before. I am not saying it’s connected to this, but obviously the possibility exists.”