Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, January 3, 2017

The $9 NextThing ChipPC is Incredible Fun!

For those of you that drop by every now and then, you are aware that I have been a fan of projects using the RaspberryPI.
I had some free time and money on my hands and managed to get these from
NextThingCo during their completed Kickstarter Campaign:

My C.H.I.P     



ChipPC





















My PocketC.H.I.P


PocketCHIP


















Operating System:
  • Debian Linux

Installed Software for my Project:
  • hostapd    ( WiFi Access Point )
  • OpenVPN  ( Security )
  • Tor             ( Security )
  • oathtool     ( Two Factor/Multi-Factor Authentication )

Highlighted Hardware Capabilities:
  • Boots from internal flash ( no sdcard required )
  • Dual WiFi ( wlan0 and wlan1 )
  • Bluetooth
  • Can be managed with minicom or screen using a standard mini-USB cable

For the record I have 3 C.H.I.P units and one PocketC.H.I.P purchased during the KickStarter so my costs were a little higher than what you are seeing here.

Lets break this down in current costs from their site: 

  • ChipPC - $9
  • Chip Case - $2
  • Battery ( LiON 3.7v ) - $5
  • Composite Cable - $5
  • A complete Linux System with a dedicated WiFi AP with built in VPN with Tor I can run in my pocket  ( Priceless!)

Happy New Year and Happy Hacking!


Friday, April 10, 2015

Security Is Hard


This entry is the result of watching John Oliver interview Edward Snowden

Last Week Tonight with John Oliver: Government Surveillance (HBO)

 
I finally understand why the conversations about solutions for OpSec and extending protection for information everywhere by default don't exist outside of a small group of people.

From Aug 2013 to present, I have prototyped and built a dynamic working methodology that uses #IaaS with #Virtualization to proactively and reactively deal with small to large scale systems that is designed to deal with attacks and intrusions against Operating Systems and Application Data. By using this on the Internet, and allowing malicious intrusions on test systems, I have been able to test and refine what works while removing what doesn't.

Over many years I discovered that when I explain how this works and why it is needed to individuals that do not work in IT, no one will attempt to do it because my method requires a change in how systems and data get managed and that makes it "too hard" or "too expensive" to use to protect customer data.

I'm not worried, I can wait.
I created my first free Internet VPN / Public Proxy in 1997 with strong encryption and anonymity well before business and regular Internet users were interested. Since all the revelations on Internet Surveillance, many have become my customers.

What I have learned is that if all of us that work with information, applications, and communications can find a way to explain how encryption will prevent compromising photos of naked men and women from having their pictures getting intercepted, stolen, or revealed, we will all be very, very, rich.....and safer for it.



Friday, September 6, 2013

The Torduckin Promise

My desire to be technically creative has been moved by recent revelations of government capabilities in gathering intelligence on USA citizens.
One of the most influential books I have ever read was "Applied Cryptography".
I purchased the first edition when it came out and have followed the insights of Mr. Bruce Schneier ever since.

In his blog, Mr. Schneier makes very compelling arguments here
  •  http://www.schneier.com/essay-438.html 
and here
  • http://www.theguardian.com/commentisfree/2013/sep/05/government-betrayed-internet-nsa-spying
The Internet was built on public funds for public use. The Internet made it possible for me as a 13 year old in The South Bronx to reach out to the world and become successful at what I do today. I have found my way to giving back to the Internet by running completely free Anonymous Email Remailers and Anonymizing Public Proxies since 1997.

Effective Saturday September 7, 2013 I will be making a change to the MagusNet Anonymout Public Proxy ( Torduckin ) as an attempt to deal with the possibility that OpenVPN + Tor + SSH + Linux/OpenBSD may have an unknown vulnerability that has yet to be revealed in their cryptographic capabilities.

I will be auto-generating new SSL Certificates for OpenVPN on my website every 6 hours. There will be no logging of any kind in any location and the virtual machines that run in RAM and house the VPN  + Tor  + Citadel Hidden Sites will be wiped by writing over all RAM addresses multiple times before reloading.

This may be paranoid or maybe not going far enough. Either way, I am dedicated to making sure that I use my technical capabilities to engineer the most secure solutions I can to allow everyone everywhere in the world to use the Internet and feel just a little bit safer along the way.

Thank you.

-- Jean Francois - President and Founder of MagusNet, LLC.