Tag Archives: computer security

Live CD for anonymous internet browsing: The (Amnesic) Incognito Live System

After the sole developer of Incognito, arguably, the best Linux live CD for anonymous internet browsing, announced that he could not carry on with his work in the project, another anonymous live CD, Amnesia, decided to merge with Incognito Linux live CD, and hence, the (Amnesic) Incognito Live System was born.

 

Information security awareness poster
Information security awareness poster

 

Version 0.5 of The Amnesic Incognito Live CD is now out and includes lots of goodies for anonymous internet surfing, encryption and erasing your online tracks, such as:

  • Tor 0.2.1.25
  • Vidalia 0.2.8
  • Claws Mail 3.7.5 with OpenPGP support.
  • Pidgin automatically connects to irc.oftc.net with a randomized nickname.
  • At shutdown time, only prompt to remove CD; just halt when booted from a USB stick.
  • Forbid any IPv6 communication with the outside.
  • Added some wifi drivers: Ralink rt2570, rt2860 and Broadcom STA.

My hats off to this great live CD for anonymous internet surfing!

For those who fear that the Chinese or British secret services will seize their computers one day, a live CD is the sure way to avoid leaving any tracks on your computer.

The (Amnesic) Incognito Live System homepage

 

Review: Free speech webhosting NearlyFreeSpeech

I have been with NearlyFreeSpeech webhosting for three years (not this blog) and this review is based on that experience. The fact that I have been with them for so long already indicates that I am happy with their services, although there isn’t too much competition in the free speech webhosting field and that also helped.

Besides webhosting, NearlyFreeSpeech.net also does domain name registration with whois privacy included.

At the time of writting this NearlyFreeSpeech fees are very cheap for static sites (no database and few pictures).  Just remember to change the settings on your account because by default it is set up to support PHP and once you change it to static site the price will go down.

You will need to pay in order to get support for your hosting account at NearlyFreeSpeech, but I have found their members only forum, to be very useful,  NearlyFreeSpeech staff hangs around there too and they will help you out whenever they can.

During my time with NearlyFreeSpeech I have always gotten free meaningful support from their forums. No question has gone unanswered.

Muhammed the prophet
Muhammed the prophet

The Good Stuff

As long as your content is legal in the United States, where NearlyFreeSpeech is based, you will have absolutely no problems with them, it does not matter if you are promoting pedophilia, Hitler, Stalin or anything similar, NearlyFreeSpeech will not take the content down if this is legal in the US and does not infringe on copyright.

You can pay via Paypal, credit card or sending a money order in the post, the last payment method being a rare find for a webhost.

NearlyFreeSpeech will also take anonymous donations to fund your hosting account, this is an excellent way for people to anonymously fund your website, with no involvement from your part, the donator will only need to indicate your hosting account number, which you can make clear on your site, and you will be notified by NearlyFreeSpeech every time someone sends money in.

NearlyFreeSpeech members can propose new features to be implemented and they are then submitted to a popular vote.  There is support for SFTP and SSH and the sense of community at the forums is also very good.

The Bad Stuff

The only way to upload your files is with an FTP or SFTP client, there is no web interface to do that. Nearlyfreespeech hosting control panel is unique to them and has been developed in house, its navigation is hard and you will need to get used to it, it also has far less features than the more usual cPanel.

It will be hard for you to work out what you are going to pay at the end of the year, the way used to calculate that is complex, consisting of the sum of number of active databases, bandwith used, space used, email forwarding used, etc.

You will need to pay to get hosting support and any hosting software you need to install will have to be done manually because you can’t do that from the control panel.

Barak Obama
Barak Obama

Conclusion

If your site is controversial but legal in the US, you will feel safe hosting it at NearlyFreeSpeech.

Their hosting panel is poor and hard to navigate and you will need not to know the basics of webhosting, such as how an FTP client works.

You will only be better off NearlyFreeSpeech if your website has specific software needs such as some peculiar CMS that you would like to install through the hosting panel. You may also be bothered by not being able to work out what the hosting is going to cost you at the end of the year.

Visit NearlyFreeSpeech


Alternatives to NearlyFreeSpeech:

Invisihosting

CrisisHost: Read my CrisisHost review

Freebie: Free full version East-Tec Eraser 2009

I came accross this offer at Softpedia today and I thought about sharing it with all of you. Valid until 31st January 2010, you can download a free full licensed version of East-Tec Eraser 2009.

I just downloaded and registered it and so far so good, it works fine with Windows Vista 64 bit. East-Tec Eraser is last year’s version of this software but still has lots of great features. It can clean your Windows registry, email software, Windows OS unwanted backups and page file, cookies, history, and a long etc.

East-Tec Eraser 2009 is highly configurable and it has a wide range of wiping methods.

Eas-Tec Eraser 2009 wiping software
Eas-Tec Eraser 2009 wiping software

Note: Do not fool yourself! East-Tec Eraser does a great job making life difficult for anyone trying to recover data from your computer. But if your life is at stake, use full disk encryption (Truecrypt)! Sometimes only a single picture or a single document is necessary to ruin your life for ever.

Free East-Tec Eraser 2009 (link valid until 31st January 2010):
http://www.east-tec.com/offers/softpedia/2009/eraser/register.htm (Offer gone!)

Late readers: get Eraser (Freeware):
http://sourceforge.net/projects/eraser/

Secret FBI subpoena demanding IP Addresses of all visitors to Indymedia.us

It is only now that the subpoena has been fought off successfully in court that it can be know how the FBI attempted to get all the IP addresses of people visiting Indymedia.us, an independent news website. The subpoena also imposed a gag order and demanded the recipient’s silence under threat of being prosecuted for obstruction to justice.

Unfortunately for the FBI Indymedia has a no logs policy so besides being defeated in Court by the Electronic Frountiers Foundation, its request could not be fulfilled anyway.

I wonder what kind of people the US has protecting them from terrorism, unpaid fines and rape, when the FBI intelligence team is not aware that Indymedia does not keep logs?

This is actually public information that Indymedia has all over its website.

FBI: Fucktard Bureau of Investigation
FBI: Fucktard Bureau of Investigation

You can read all of the saucy details on how the Electronic Frontier Foundation won the case against this bogus FBI subpoena at the EFF webpage: Anatomy of a Bogus Subpoena

Indymedia UK security set up

Just for all the fucktard officers reading this who do not know how to use Google, let me tell you some of UK Indymedia security set up. (I will assume the security of their Worldwide Indymedia counterparts resembles it).

Hardware encryption:

There are two physical servers that are owned by Indymedia UK, both servers are fully encrypted, the passphrases required for the disk encryption software are in the region of 30-40 characters minimum, they are only stored in an encrypted format by trusted administrators.

If any of the servers are turned off for any reason the passphrases needs to be manually re-entered before the machine can become functional again. People who have physical access to the servers do not normally hold the passphrases, and in some instances, the passphrases are kept in a different country to where the machine is located.

Software anonymisation:

The UK Indymedia website uses software designed around a central publish server from which static HTML content is then copied to mirrors.

UK  Indymedia has employed up to 10 mirrors at any one time, the mirrors may be located anywhere around the world, when you post an article you will be redirected to one of these mirrors at random. Mirrors, like the publish server, are set up to not log IP addresses.

FBI top secret tip to always get it right

-"This is the best marksmanship I have ever seen" - said the
idiot man
-"How in the World do you do it?"
-"Nothing to it" - says the Fucktard Bureau of Investigation
 officer
-"I shoot first and draw the circles afterwards"

The NSA worked on Windows 7 before its release

The recent testimony of Richard Schaefer’s  to the Senate Judiciary’s Subcommittee on Terrorism and Homeland Security reveals that the NSA tinkered with Windows 7 before its release, it looks like one of the biggest voyeur agencies in the World is not missing a single opportunity to get its filthy pawns all over people’s operating system.

Richard Schaefer, NSA Information Assurance Director quoted

“Working in partnership with Microsoft and elements of the DoD, NSA leveraged our unique expertise and operational knowledge of system threats and vulnerabilities to enhance Microsoft’s operating system security guide without constraining the user’s ability to perform their everyday tasks”

PRIVACY WARNING: Before visiting the NSA website use a proxy!

Full testimony: http://www.nsa.gov/public_info/speeches_testimonies/17nov09_schaeffer.shtml

USA spying on citizens
spooks spying on innocent citizens

Protection against possible NSA backdoors on Windows 7

If you are a Windows 7 user you will want to protect your life, wife and kids from outside interference, but this will be extremely hard now that it is known the NSA had access to Windows 7 before you.

The obvious advice is that you should not use Windows 7 at all, but if you must, at the very least try to stop any possible NSA malware with open source security software:

  • Do not use the Windows 7 firewall get some old computer and install a free open source firewall based on FreeBSD such as M0n0wall
  • Do not use Microsoft Windows Defender get a free open source antivirus such as ClamWin
  • Watch what data packets are being sent out and where, download a free packet sniffer such as Wireshark

Review: Virtual Pritate Network for private internet surfing AceVPN

I have been using AceVPN for three months now and this review is based on this length of time. Before getting into a Virtual Private Network for anonymous internet surfing purposes, you should understand that a VPN will make it more difficult for TLA agencies such as the CiA and Mi5 to spy on you, but a VPN is a single hop proxy, if they want you bad they will most likely have you.

For serious anonymous internet surfing you should use Tor, which unfortunately it is slow for most activities other than posting at bulletin boards.

At the moment there is a 50GB monthly bandwith cap on AceVPN, I think this is a very reasonable amount of bandwith, the average surfer will probably download half that and since P2P programs are not allowed on AceVPN I can hardly see anyone going over the limit.

The Good Stuff

Every time I have emailed AceVPN, around five times, I always got a useful reply in under 24 hours. AceVPN at the time of writing this, has servers in the US, UK and France and claims to be planning new servers at other countries.

One of the USA VPN I was using got blocked by Hulu, a US only TV website, apparently they do not like people from abroad being able to watch their films through a proxy. AceVPN has a secret list of VPNs to access US only sites such as Hulu TV, Pandora radio and Crackle TV, if you email AceVPN support and tell them you want to watch Hulu and they are blocking your proxy, they will send you a new non public configuration file with new servers for the VPN.

AceVPN uses OpenVPN to tunnel the data as opposed to the more unsecure PPTP, and besides Windows, AceVPN also works in Mac, Linux/BSD and the iPhone, any device where you can install OpenVPN should work.

You can choose the UDP or TCP protocol for tunneling. Normally you should choose the UDP protocol, this is que fastest method to download data through the VPN, the TCP protocol is provided because some ISPs and private networks block all UDP traffic to stop certain applications from accessing the internet.

World Internet Plugged In

The Bad Stuff

When you sign up for AceVPN they will send you a very hard to remember cryptic password that you can not change, you will need to enter this every time you want to access the VPN, better write it down somewhere, I personally have it saved on a .txt file on my Desktop.

AceVPN has servers in several countries but  in order to choose what server you want to connect to you will have to manually edit the OpenVPN config file in Notepad and comment out the servers you want to avoid, there is no control panel to do this.

Torrents and P2P programs are not allowed at AceVPN, even if some users use it, as  per terms and conditions this is forbidden.

Conclusion

AceVPN is great value for money and it stops your ISP from logging your internet activities making the life of those who spy on others much more difficult, AceVPN is also one of the cheapest VPN available and the wide choice of servers located in different countries guarantees that if one goes down you can still connect somewhere else.

Be aware that during my time with AceVPN one of their USA servers was seized by the FBI, this was due to a DMCA request according to AceVPN management.

While AceVPN claims not to keep logs, the FBI is known to have great computer forensic facilities and only God knows what kind of personal private data from innocent people they managed to retrieve from that server.

I will be greatly surprised if these professional meddlesome informers resisted the temptation of not looking at other users accounts, I will say it again because people’s lives may be at stake, never forget to use full disk encryption as a security back up. A VPN will make the spooks job more difficult but not impossible, privacy advocates are a high target for TLA, people who have a private life scare the shit out of them, they are not used to that, be ready for an early morning raid from people wanting to know what you do in your spare time, whether you use VPN or you don’t, the Obama deception is here, this is not a joke, the CiA means business, your little VPN will not be enough to stop them, think bigger.

http://www.acevpn.com

UPDATE: As of 01 December 2009, I am having serious problems to watch USA TV with AceVPN (it’s very slow), after various speed tests at http://www.speedtest.net I have detected that their USA servers are very slow at times, in the order of 500Kb/download.

This may change in the future but as for now be warned of this problem. Their French and UK server speed was acceptable.

Review: Full disk encryption DiskCryptor v0.7.435.90

Most of you will have heard of Truecrypt, a free an open source hard disk encryption product, there are only another free and open source software for full disk encryption in Windows that I am aware of, DiskCryptor. You can download a 32bit or 64bit version of Diskcryptor depending on your OS.

I tested DiskCryptor using it for full disk encryption of my netbook, an Asus PC901 with a 12GB HDD divided in between two solid state disks of 8GB and 4GB. DiskCryptor is an ideal alternative to encrypt a netbook because netbooks do not have a CD drive and Truecrypt will force you to burn a CD to use system encryption, which DiskCryptor does not.

DiskCryptor cascade algortyhms
DiskCryptor cascade algortyhms

The first thing that impressed me of DiskCryptor is how small it is in size, a little over 500KB, but this comes at a price since the software manual does not come along and you get a link to their website instead.

I was pleased to see DiskCryptor offering a wide choice of encryption algorythms, AES-256, Twofish or Serpent algorithms in XTS mode, all of them seem to be pretty sound algorythms to me, and they can be used on cascade mode as well, VIA Padlock hardware accelaration for encryption and hashing is supported too.

The built-in benchmark shows the top speed with which cryptographic algorithms can perform, but I have to tell you that even on a netbook with a single core Intel Atom processor, regardless of the encryption algortyhm used I noticed no perfomance difference while using the netbook.

DiskCryptor encryption of partition
DiskCryptor encryption of partition

DiskCryptor allows wipe while encrypting, with three, seven or thirty five passes (Guttman method), but wiping a solid state disk like the one Asus Eee PC901 has is not safe, since solid state disks, like thumb drives, use wear levelling technology and the wiping passes are spread evenly accross the disk and not on the same sectors. If you are using a solid state disk, make sure it does not contain any confidential data that an electrons microscope could recover(very expensive to do right now), the only way to do this is by using a new disk, wiping it may fail to sanitize de disk.

With DiskCryptor you also can encrypt an ISO file and then burn it to CD-R/DVD/BD-R , after that you  will only be able to mount the image with DiskCryptor and the correct password/keyfile.

You can also set up a hot key to cause a blue screen of death, if you need to urgently shut down your computer when someone busts into your home unexpectedly this seems the way to go, it is quicker than clicking on the power off button.

The Good Stuff

DiskCryptor works with RAID volumes, you get a wide choice of algorythms, DiskCryptor is easy to use and unlike Truecrypt, it works on netbooks out of the box. DiskCryptor is open source, you can check for backdoors if you have the skills.

The software does not cost you any money, you can customize the boot loader widely, DiskCryptor boot loader customization is far better than Truecrypt, you can choose to install the bootloader on a CD/DVD, set up timeouts, choose if you want to use a QUERTY or DVORAK keyboard, and there is also a Windows live CD BartPE plugin for DiskCryptor.

The Bad Stuff

DiskCryptor should include some basic documentation at the very least, the GUI is easy to use and intuitive but encryption products need to come with instructions, a newbie could easily feel overwhelmed. DiskCriptor is only available for Windows, and there is no choice of hashing algorythms other than the default SHA-512.

There is also no choice of burning a recovery CD in case the boot loader gets corrupted (although you can backup the headers).

DiskCryptor password enter box
DiskCryptor password box

Conclusion

DiskCryptor is an excellent free and open source full disk encryption  alternative to Truecrypt, with a wide choice of encryption algorythms and easy to use, but they need to improve their poor documentation.

Their FAQ states that they are planning to implement a hidden OS in future versions, I think Diskcryptor looks promising and Truecrypt has a worthy competitor.

http://www.diskcryptor.net