Showing posts with label anonymity. Show all posts
Showing posts with label anonymity. Show all posts

Tuesday, January 3, 2017

The $9 NextThing ChipPC is Incredible Fun!

For those of you that drop by every now and then, you are aware that I have been a fan of projects using the RaspberryPI.
I had some free time and money on my hands and managed to get these from
NextThingCo during their completed Kickstarter Campaign:

My C.H.I.P     



ChipPC





















My PocketC.H.I.P


PocketCHIP


















Operating System:
  • Debian Linux

Installed Software for my Project:
  • hostapd    ( WiFi Access Point )
  • OpenVPN  ( Security )
  • Tor             ( Security )
  • oathtool     ( Two Factor/Multi-Factor Authentication )

Highlighted Hardware Capabilities:
  • Boots from internal flash ( no sdcard required )
  • Dual WiFi ( wlan0 and wlan1 )
  • Bluetooth
  • Can be managed with minicom or screen using a standard mini-USB cable

For the record I have 3 C.H.I.P units and one PocketC.H.I.P purchased during the KickStarter so my costs were a little higher than what you are seeing here.

Lets break this down in current costs from their site: 

  • ChipPC - $9
  • Chip Case - $2
  • Battery ( LiON 3.7v ) - $5
  • Composite Cable - $5
  • A complete Linux System with a dedicated WiFi AP with built in VPN with Tor I can run in my pocket  ( Priceless!)

Happy New Year and Happy Hacking!


Friday, April 10, 2015

Security Is Hard


This entry is the result of watching John Oliver interview Edward Snowden

Last Week Tonight with John Oliver: Government Surveillance (HBO)

 
I finally understand why the conversations about solutions for OpSec and extending protection for information everywhere by default don't exist outside of a small group of people.

From Aug 2013 to present, I have prototyped and built a dynamic working methodology that uses #IaaS with #Virtualization to proactively and reactively deal with small to large scale systems that is designed to deal with attacks and intrusions against Operating Systems and Application Data. By using this on the Internet, and allowing malicious intrusions on test systems, I have been able to test and refine what works while removing what doesn't.

Over many years I discovered that when I explain how this works and why it is needed to individuals that do not work in IT, no one will attempt to do it because my method requires a change in how systems and data get managed and that makes it "too hard" or "too expensive" to use to protect customer data.

I'm not worried, I can wait.
I created my first free Internet VPN / Public Proxy in 1997 with strong encryption and anonymity well before business and regular Internet users were interested. Since all the revelations on Internet Surveillance, many have become my customers.

What I have learned is that if all of us that work with information, applications, and communications can find a way to explain how encryption will prevent compromising photos of naked men and women from having their pictures getting intercepted, stolen, or revealed, we will all be very, very, rich.....and safer for it.



Friday, September 6, 2013

The Torduckin Promise

My desire to be technically creative has been moved by recent revelations of government capabilities in gathering intelligence on USA citizens.
One of the most influential books I have ever read was "Applied Cryptography".
I purchased the first edition when it came out and have followed the insights of Mr. Bruce Schneier ever since.

In his blog, Mr. Schneier makes very compelling arguments here
  •  http://www.schneier.com/essay-438.html 
and here
  • http://www.theguardian.com/commentisfree/2013/sep/05/government-betrayed-internet-nsa-spying
The Internet was built on public funds for public use. The Internet made it possible for me as a 13 year old in The South Bronx to reach out to the world and become successful at what I do today. I have found my way to giving back to the Internet by running completely free Anonymous Email Remailers and Anonymizing Public Proxies since 1997.

Effective Saturday September 7, 2013 I will be making a change to the MagusNet Anonymout Public Proxy ( Torduckin ) as an attempt to deal with the possibility that OpenVPN + Tor + SSH + Linux/OpenBSD may have an unknown vulnerability that has yet to be revealed in their cryptographic capabilities.

I will be auto-generating new SSL Certificates for OpenVPN on my website every 6 hours. There will be no logging of any kind in any location and the virtual machines that run in RAM and house the VPN  + Tor  + Citadel Hidden Sites will be wiped by writing over all RAM addresses multiple times before reloading.

This may be paranoid or maybe not going far enough. Either way, I am dedicated to making sure that I use my technical capabilities to engineer the most secure solutions I can to allow everyone everywhere in the world to use the Internet and feel just a little bit safer along the way.

Thank you.

-- Jean Francois - President and Founder of MagusNet, LLC.




Wednesday, August 29, 2012

The MagusNet Anonymous Public Proxy ( Torduckin ) Has New URLs

I finally decided to make it official and
get the MagusNet Anonymous Public Proxy ( Torduckin ) URLs:



-----BEGIN PGP MESSAGE-----
Comment: #Torduckin

jA0EAwMCVlWKaBgs85JgyYCP8SSFPFgPb+QWndofbhSBAr3sFYohBbDUPXfGxlep
DkFbUaAW68WYRGGCsFV7HwcAQN4G4vAeh4cXm4xeJTBe3VYpLD1Ai/tZD1k62/OO
RvdYdkipcOAwYin/h/1gKRZKcsgoZzbHBx2WFDfAQgqPfi0lenTwEkFN9CQRF3Th
Cg==
=FFfH
-----END PGP MESSAGE-----



Enjoy :)




Thursday, May 5, 2011

Providing Internet Anonymity - The MagusNet Anonymous Public Proxy

There is a silent conflict going on where users of the Internet that want to reach certain types of content are faced with other online entities that are interested in knowing what content is being accessed and using that information for tracking or blocking/filtering. On May 1, 2011 I decided to re-launch The MagusNet Anonymous Public Proxy to continue providing anonymity and deliver a way around Internet filtering for free.

From September 1997 to September 12, 2001 I operated The MagusNet Anonymous Public Proxy for web browsing while at the same time running an Anonymous Remailer ( Mixmaster ) for anonymizing email. The personal satisfaction I got from running both services came in the form of email from various countries where users were thankful that I was able to help them get around Internet filtering at no cost. Professionally, I was able to use my demonstrated knowledge of deploying an open proxy that was popular, secure, and easily usable the entire time it was in service.

My family was not pleased with phone calls and “unofficial” visits from the agencies like the FBI and the RCMP, along with the use of barratry to try to limit, monitor, harass, and shutdown a perfectly legal service. It amazes me to see the disconnect when the U.S. State Department can have a fund set aside to support the creation of services like I provide, while the U.S. Congress works at legislation to try to make operation of the same types of services a criminally punishable offense.

At the time I was using a known set of IP address ranges and ports and many filtering services went to great lengths to make my service and web pages unreachable. In fact, after 10 years of being offline, there are still vendors selling Internet filtering software that have my original URL listed. In order to bring back the MagusNet Anonymous Public Proxy I needed to decide on how to protect my users while giving myself greater flexibility in preventing the service from being filtered into obscurity.

The challenges to overcome were many and here are just a few:
* IP Address flexibility to defeat filtering
* Domain name decoupled from service
* End User Data security ( No Logging, No Data Capture )
* My Security ( Secure System, Location Independent )
* Manage Costs for Delivering a Free Service

I have found a way to deal with all of the issues mentioned, and a few others I discovered along the way, in order to re-launch what I consider a much needed service for Internet users.
By moving certain portions of the service into a “cloud” server, I no longer have to be concerned with the filtering of IP addresses since the Internet facing server is using a dynamically assigned IP address than I can change as needed to defeat most filtering.

Behind that server is a set of servers that run diskless as virtual machines to ensure that no data is stored on any physical media and as a side effect I get a benefit of efficiency by running everything in memory. I did this not only as a way to resolve data retention and data security workarounds, but also in case a server is ever compromised or has any non-security related issues, I can reboot from read-only media and be up quickly while analyzing the problem. My current configuration allows me to perform an hourly reload for each node and boot from read-only media with the capability of handling ~10,000 users per server, load balanced as needed.

The last hurdle was to make sure that my “core” servers were not visible for inbound and outbound traffic. By having OpenVPN used to encrypt and manage inbound traffic and requiring the use of The Onion Router ( Tor ) for traffic exiting into the Internet, I found I could not only deploy the “core” servers anywhere, I can replicate from a single read-only image to expand the number of nodes for improving loading and availability. Once I figure out how to transparently merge in and load balance multiple Tor exit nodes, going global will be complete.

I realize there are many global users of the Internet that do not have a need for this kind of service but for those individuals that are Human Rights Workers, live in a location that filters Internet content, or just everyday people that aren’t interested in having the most mundane of personal information looked at for any reason, I’ll be here and I’ll keep doing what I can to help out.

If you are a fellow citizen of the United States of America,
and feel this service is not needed since you have nothing to hide,
start sending all of your letters on post cards ( no envelopes! ) ,and
here is some reading material:
http://papers.ssrn.com/sol3/papers.cfm?abstract_id=998565

-- Jean Francois - MagusNet, LLC
Owner and Operator of The MagusNet Anonymous Public Proxy ( Torduckin )*
http://www.magusnet.com/proxy.html
* The name comes from how this is set up:
It uses an OpenVPN Tunnel stuffed into an SSH Tunnel stuffed into Tor.