Friends-
The security and anonymity of this site has recently been called into question in the wake of a "bomb threat." I'd like to explain a little more so that you can be properly educated. We need to set some context around the the state of Internet and the digital world in which we live because scrutinizing b@b alone would be dangerously short-sighted.
I'm sure by now everyone has at least heard of PRISM. If anyone wants to get really technical with how this system very likely may work, I'd recommend checking out a podcast by Steve Gibson that provides one possible explanation (and still un-refuted). I will try to summarize:
It's a bit misleading that PRISM is presented in all capital letters as if it were an acronym. Steve suspects it more likely describes at a high level how the system works... What does a prism do? It splits light. If your goal was to essentially make a copy of all Internet traffic, splicing the light in fiberoptic cables at critical backbones of the Internet would probably be your best bet. This second beam of light could then be diverted to a relay (or private NSA locker) to be passed on for storage. In this case, a 5 zetabyte facility south of Salt Lake City. To help comprehend the magnatide of storage capacity: this is equivalent to 5 billion terabytes. Store everything and sift through it when you need to build a case. Or better yet, hook it up to an IBM Watson.
That said, it needs to be clear that b@b DOES make a secured SSL connection between your browser and the server. Which means, the things that you post are being stored in an encrypted, unreadable form (with modern computing) by the NSA. Why keep this unreadable data? Because in the future computers will get stronger and faster and perhaps quantum computing technology will allow these guys to just collapse our encryption standards. b@b transfers data using 256-bit encryption with TLS 1.0 (MUCH better than most sites using 128-bit), but still, perhaps that could be collapsed someday. For the moment anyway, it is very unlikely this is possible without quantum computing, which is still very far off. The things that you type/post ARE encrypted. However, there are many other points of failure... so those of you who think you can do anything, like walk into a room and wave a gun, stop being an idiot and listen:
Firstly, metadata. Do not underestimate these facts. Metadata is not the main content (your posts) but rather, its embellishment. For example, when your browser makes a query, "headers" are sent which contain additional information: Date, time, browser type, screen resolution, cookies and so forth are all browser metadata. Here is a fantastic paper by the EFF about the uniqueness of your browser. From the abstract: "We observe that the distribution of our (browser) fi ngerprint contains at least 18.1 bits of entropy, meaning that if we pick a browser at random, at best we expect that only one in 286,777 other browsers will share its fi ngerprint"-- This meta IS being stored and when analyzed in bulk using big data computing it can provide an enormous amount of identifying information and intelligence.
Second, I have identified a more glaring point of failure previously unknown to me. Now that I understand how this NSA system probably works, email verification doesn't provide sufficient anonymity as I once thought, regardless of whether b@b discards any trace internally. I've learned that email transiting the web is actually not encrypted. Email SMTP technology (the protocol) does not involve encryption when we send email from place to place unless an individual deliberately encrypts their email. For instance, if you use Gmail, you may have a secured SSL connection to Google's web server, but the moment that email leaves Google to go to a recipient, say your grandma on AOL, it is being sent over SMTP connections which are not encrypted. Our interchanges within Google or b@b are encrypted, but email traveling across the Internet is not. So the point of failure: While you're making a secure connection to b@b, using email as a verification method delivered to your inbox likely is not. The contents and its metadata (the recipient email in plain text) is very likely being copied. Even though b@b does not have a record of this information, it is very likely big brother does. There's nothing I can do about that, except NOT use email verification. Yes. Back to the drawing board.
Before you say, "Well I'll just use an email disposal service" or delude yourself that a Tor browser is sufficient anonymity... you should be aware that simply attempting to hide yourself implies guilt. The magnification factor on your Internet activity is dialed up.
So before you go and tear down my attempts at making this service as anonymous as possible, neither I, nor Google, nor Facebook, nor any other web service out there knew this was happening to this degree. And the points of failure are in the fundamental architectures of the Internet.
I am re-evaluating the Privacy Policy for b@b and need to make these facts about the Internet known for the average person. This is on my to-do list and I will put something up as soon as I can.
Jae
Jae...you alive?
ReplyDeleteI haven't been able to login for the last few days. Is this happening to anyone else?
ReplyDelete^ Yes, obviously.
ReplyDelete