<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-3859105325576740988</atom:id><lastBuildDate>Wed, 28 Aug 2024 10:00:12 +0000</lastBuildDate><category>bitcoin p2p currency anonymity privacy</category><category>chat pidgin otr encryption</category><category>enigmail thunderbird encryption email</category><category>https everywhere eff</category><category>i2p encryption anonymity</category><category>pirate software privacy liberty freedom</category><category>seeks yacy search p2p anonymity</category><category>wuala cloud storage encryption</category><title>Pirate Software</title><description>I blog once a week about software for us who cares about online privacy,</description><link>http://pirate-software.blogspot.com/</link><managingEditor>noreply@blogger.com (Unknown)</managingEditor><generator>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3859105325576740988.post-2934587892767425601</guid><pubDate>Sun, 20 Feb 2011 18:30:00 +0000</pubDate><atom:updated>2011-02-20T23:12:18.408+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">seeks yacy search p2p anonymity</category><title>Pirate Software, week 7: Seeks</title><description>Ten years ago I collected bookmarks to everything interesting I found on the net. Today I don&#39;t, because I can in most cases find it again by just googling it up. But our dependency upon search is quite scary. The net is so vast that it is hard for us to tell if Google is doing a good job, or sending us to the wrong pages. And it is a bit scary that Google saves all our searches. Go &lt;a href=&quot;https://www.google.com/history/trends&quot;&gt;here&lt;/a&gt; and have a look at your own searches.&lt;br /&gt;
&lt;br /&gt;
If we translated the situation to meat-space, what if you always went to the same guy every time you had a question, and what about the idea of him writing down every question you ever asked?&lt;br /&gt;
&lt;br /&gt;
So, really, there are two issues here:&lt;br /&gt;
&lt;ol&gt;&lt;li&gt;Is Google giving us the right answers?&lt;/li&gt;
&lt;li&gt;How much is our privacy worth?&lt;/li&gt;
&lt;/ol&gt;The first question could be answered, perhaps, by some kind of research, of which I am not capable. There are true alternatives to Google, as you know, but why would we trust the alternatives more than Google? Could we do it ourselves? Well, yes, perhaps. I have found one such effort, &lt;a href=&quot;http://www.yacy.net/&quot;&gt;YaCy&lt;/a&gt;, which is a program you install on your own computer. You can send it off spidering the web for you, but the search results from your computer alone can&#39;t do the web justice, of course. Google has, after all, hundreds of thousands of computers at hand for search. So what YaCy does when you search for &quot;pirate party usa&quot; is to connect through peer-to-peer with other YaCy users and assemble the search result from all those peers. So, you might wonder, does it work? Unfortunately, no. My experience is that the results don&#39;t reflect what you&#39;d hope for. Your experience might differ, so try it out in case you&#39;re interested.&lt;br /&gt;
&lt;br /&gt;
What about privacy, not having all your searches saved by others? There are several ways you can go here:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;You can tell Google not to save your searches. But do you trust them not to? I think I do, but I&#39;d rather not depend on it.&lt;/li&gt;
&lt;li&gt;You can switch to one of the proxy search engines out there that explicitly claim they don&#39;t track your searches, such as &lt;a href=&quot;https://duckduckgo.com/&quot;&gt;Duck Duck Go&lt;/a&gt;, &lt;a href=&quot;https://ixquick.com/&quot;&gt;Ixquick&lt;/a&gt; or &lt;a href=&quot;https://ssl.scroogle.org/&quot;&gt;Scroogle&lt;/a&gt;. I haven&#39;t tried them much, but they seems to work fine. If you ask me, go for the Duck!&lt;/li&gt;
&lt;li&gt;You could install a proxy search engine on your own machine, such as &lt;a href=&quot;http://www.seeks-project.info/&quot;&gt;Seeks&lt;/a&gt;. It does share your searches, but anonymously, and only with other machines who have also installed Seeks. In that way it resembles YaCy, but does a much better job. You can try it out &lt;a href=&quot;http://www.seeks-project.info/search.php&quot;&gt;here&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;&lt;ol&gt;&lt;/ol&gt;&lt;pre style=&quot;font-family: inherit;&quot; wrap=&quot;&quot;&gt;I have currently chosen the Seeks project as my choice for search. Since it is open source I can potentially inspect the source and make up my own mind as to its claims for what it does. The project is &lt;a href=&quot;http://www.seeks-project.info/site/?page_id=2&quot;&gt;very ambitious&lt;/a&gt;, as they plan to in the future build its own search index. It may never get that far, but it is currently good enough for me. I might change to something else later, which is the good thing about search - simple to replace.&lt;/pre&gt;&lt;pre style=&quot;font-family: inherit;&quot; wrap=&quot;&quot;&gt;&lt;a class=&quot;moz-txt-link-freetext&quot; href=&quot;http://www.yacy.net/&quot;&gt;
&lt;/a&gt;&lt;/pre&gt;&lt;pre style=&quot;font-family: inherit;&quot; wrap=&quot;&quot;&gt;&lt;/pre&gt;&lt;pre style=&quot;font-family: inherit;&quot; wrap=&quot;&quot;&gt;&lt;/pre&gt;&lt;pre style=&quot;font-family: inherit;&quot; wrap=&quot;&quot;&gt;&lt;/pre&gt;&lt;pre style=&quot;font-family: inherit;&quot; wrap=&quot;&quot;&gt;&lt;/pre&gt;&lt;pre style=&quot;font-family: inherit;&quot; wrap=&quot;&quot;&gt;&lt;/pre&gt;</description><link>http://pirate-software.blogspot.com/2011/01/pirate-software-week-7-seeks.html</link><author>noreply@blogger.com (Unknown)</author><thr:total>5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3859105325576740988.post-6580180306640922071</guid><pubDate>Fri, 11 Feb 2011 09:00:00 +0000</pubDate><atom:updated>2011-02-11T10:35:56.214+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">chat pidgin otr encryption</category><title>Pirate Software, week 6: Pidgin + OTR</title><description>I was never into IRC for direct chat in the early days of the net. For me the whole concept started with &lt;a href=&quot;https://secure.wikimedia.org/wikipedia/en/wiki/ICQ&quot;&gt;ICQ&lt;/a&gt; in 1996, and then with &lt;a href=&quot;https://secure.wikimedia.org/wikipedia/en/wiki/Yahoo%21_Messenger&quot;&gt;Yahoo Messenger&lt;/a&gt; in 1999. These products used proprietary protocols for communication, and were never secure. They also quickly became bloatware and painful to use since they tried to expand into being much more than &quot;lowly&quot; chat.&lt;br /&gt;
&lt;br /&gt;
But chat will never go away, as we value direct conversations. Today many people mostly use Skype for chat, which is a bad idea for many reasons:&lt;br /&gt;
&lt;ol&gt;&lt;li&gt;It doesn&#39;t use an open protocol, so it is very hard, almost impossible, to put Skype to use except through the official Skype client.&lt;/li&gt;
&lt;li&gt;Your messages aren&#39;t encrypted between you and your chat partner, so your conversation can (and in some cases probably is) monitored. Remember that Skype offers phone calls to normal phones, and to be allowed to connect with the public phone system, they have to comply with lots of government regulation, of which machinery for wire-tapping by police is one.&lt;/li&gt;
&lt;li&gt;It isn&#39;t open source, so it is unclear how things works. &lt;/li&gt;
&lt;li&gt;Also Skype has become bloatware. &lt;/li&gt;
&lt;/ol&gt;A very good alternative is &lt;a href=&quot;http://www.pidgin.im/&quot;&gt;Pidgin&lt;/a&gt;, which is an open source chat client with which you can connect to IRC, ICQ, Yahoo Messenger, the open protocol &lt;a href=&quot;https://secure.wikimedia.org/wikipedia/en/wiki/XMPP&quot;&gt;XMPP&lt;/a&gt; and many many more. It works with Windows, Mac and many versions of Linux.&lt;br /&gt;
&lt;br /&gt;
Plus it supports &lt;a href=&quot;https://secure.wikimedia.org/wikipedia/en/wiki/Off-the-Record_Messaging&quot;&gt;OTR&lt;/a&gt;, which is an &lt;a href=&quot;http://www.cypherpunks.ca/otr/ubuntu-install/otr-setup.html%20&quot;&gt;easy to install&lt;/a&gt; plugin that offers (quoting directly from the website):&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;b&gt;Encryption&lt;/b&gt; - No one else can read your instant messages.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Authentication&lt;/b&gt; - You are assured the correspondent is who you think it is.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Deniability&lt;/b&gt; - The messages you send do &lt;i&gt;not&lt;/i&gt; have digital signatures that are          checkable by a third party.  Anyone can forge messages after a          conversation to make them look like they came from you.  However,          &lt;i&gt;during&lt;/i&gt; a conversation, your correspondent is assured the messages          he sees are authentic and unmodified.        &lt;/li&gt;
&lt;li&gt;&lt;b&gt;Perfect forward secrecy&lt;/b&gt; - If you lose control of your private keys, no previous conversation is compromised.&lt;/li&gt;
&lt;/ul&gt;So, install &lt;a href=&quot;http://www.pidgin.im/&quot;&gt;Pidgin&lt;/a&gt; and &lt;a href=&quot;http://www.cypherpunks.ca/otr/&quot;&gt;OTR&lt;/a&gt; and see if it works well for you. You can try out OTR with me if you like. My ICQ id is 309394, and my Yahoo id is mats_henricson.&lt;br /&gt;
&lt;br /&gt;
If you are curious about chat in general, EFF has a &lt;a href=&quot;https://ssd.eff.org/tech/im&quot;&gt;very good page&lt;/a&gt;.</description><link>http://pirate-software.blogspot.com/2011/02/pirate-software-week-6-pidgin-otr.html</link><author>noreply@blogger.com (Unknown)</author><thr:total>5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3859105325576740988.post-8075571828278072364</guid><pubDate>Sun, 06 Feb 2011 00:50:00 +0000</pubDate><atom:updated>2011-02-06T01:51:38.144+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">i2p encryption anonymity</category><title>Pirate Software, week 5: i2p</title><description>The idea of a private, completely anonymous internet guarded with strong encryption and re-routing of messages seems to be from at least mid 1988. Two fascinating r&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;eads are &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-size: small;&quot;&gt;&lt;a href=&quot;http://www.activism.net/cypherpunk/crypto-anarchy.html&quot;&gt;The Crypto Anarchist Manifesto&lt;/a&gt; &lt;span style=&quot;font-family: inherit;&quot;&gt;and &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-size: small;&quot;&gt;&lt;a href=&quot;http://www.activism.net/cypherpunk/manifesto.html&quot;&gt;A Cypherpunk&#39;s Manifesto&lt;/a&gt;. If you hesitated just a millisecond before you clicked on these links, then you know the reason these ideas still exist! Because today government agencies, companies and military organizations across the planet are monitoring what we all do on the net. The words &quot;crypto&quot;, &quot;anarchist&quot; and &quot;manifesto&quot; surely attracts some search queries. Is that desirable? Does it feel good to drop into a bucket labeled &quot;suspicious&quot; just because you&#39;re curious about cryptography?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;Many people think not, and some even try to do something about it. One of the best efforts out there is &lt;a href=&quot;http://www.i2p2.de/&quot;&gt;ip2&lt;/a&gt;, also known a&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt; Invisible Internet Protocol. It is completely open source and very actively developed by a large bunch of people. (As a side note, one of the developers went under the name of &lt;a href=&quot;http://www.i2p2.de/faq.html#jrandom&quot;&gt;jrandom&lt;/a&gt;, but he (or she, who knows) mysteriously left the project in 2008 and has not come back. There are other similar mysteries if you know where to look.)&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span class=&quot;postbody&quot;&gt;Anyway, ip2 is very simple to install, very simple to upgrade (being developer myself I must say it is exceptionally well done), and &lt;a href=&quot;http://www.i2p2.de/how_intro&quot;&gt;just works&lt;/a&gt;. There are lots of services built on top of i2p:&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;span style=&quot;font-size: small;&quot;&gt;Web browsing &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;span style=&quot;font-size: small;&quot;&gt;BitTorrent&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;span style=&quot;font-size: small;&quot;&gt;Chat&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;span style=&quot;font-size: small;&quot;&gt;Email&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;span style=&quot;font-size: small;&quot;&gt;Some of these services are completely hidden inside i2p, so if you use an i2p chat, then the messages never leaves the encrypted network. As such it is as private and anonymous as you can ever get. i2p uses strong encryption and p2p networking, technology that is threatening to many, and if our societies goes completely to hell it is likely i2p will be banned. So, we&#39;d better start using it now!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: small;&quot;&gt; &lt;/span&gt;</description><link>http://pirate-software.blogspot.com/2011/02/pirate-software-week-5-i2p.html</link><author>noreply@blogger.com (Unknown)</author><thr:total>5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3859105325576740988.post-2777644274811606715</guid><pubDate>Sun, 30 Jan 2011 19:11:00 +0000</pubDate><atom:updated>2011-01-30T22:38:51.148+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">wuala cloud storage encryption</category><title>Pirate Software, week 4: Wuala</title><description>&lt;a href=&quot;http://www.wuala.com/&quot;&gt;Wuala&lt;/a&gt; is a remarkable piece of software. It somewhat resembles &lt;a href=&quot;https://www.dropbox.com/&quot;&gt;Dropbox&lt;/a&gt;, which is a hugely successful product that lets you store files in the cloud. Lets review what Dropbox does first:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;All files you put in the special Dropbox directory on your computer gets copied to the cloud.&lt;/li&gt;
&lt;li&gt;You can install Dropbox on several computers, and the files will be in synch as long as they are connected to the net. &lt;/li&gt;
&lt;li&gt;2 GB is free, you can get more by referring friends and colleagues to Dropbox until you get about 10 GB. You&#39;ll have to pay if you need more than that.&lt;/li&gt;
&lt;li&gt;In case your computer gets stolen or destroyed, all your files are safe. Just install Dropbox on a new computer, login, and all files are downloaded from the cloud.&lt;/li&gt;
&lt;li&gt;Dropbox is very well designed, works well, and can be installed on Macs, Windows, Linux, iPhones, iPads, Android, etc.&lt;/li&gt;
&lt;li&gt;You can turn off Dropbox, and your files will still be there in your Dropbox folder.&lt;/li&gt;
&lt;li&gt;You can put files in a public folder where they are accessible to anyone. For example, here is my &lt;a href=&quot;http://dl.dropbox.com/u/1416421/cv/cv.html&quot;&gt;resume&lt;/a&gt;. Whenever I change it on my computer, the changes can be seen by everyone, which is very handy.&lt;/li&gt;
&lt;li&gt;You can create a group of friends and share files in this group.&lt;/li&gt;
&lt;/ul&gt;Dropbox has a few problems:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;It is not open source&lt;/li&gt;
&lt;li&gt;It does not encrypt your files all the way from your machine and out.&lt;/li&gt;
&lt;/ul&gt;Wuala works exactly the same as Dropbox described above, with a few differences: &lt;br /&gt;
&lt;ul&gt;&lt;li&gt;It isn&#39;t completely open source, but some parts are.&lt;/li&gt;
&lt;li&gt;If you turn off Wuala, then your files aren&#39;t available since they can&#39;t be accessed unless unencrypted by the Wuala program, using the encryption keys on your computer.&lt;/li&gt;
&lt;li&gt;Wuala encrypts your files on your machine, so they are never  readable to anyone else, not even Wuala employees. This is a crucial  difference to Dropbox, where your files are encrypted while in transit to  Dropbox, but then available unencrypted to  Dropbox.&lt;/li&gt;
&lt;li&gt;2 GB is free, but, you can trade up to 100 GB of your local hard disk for 100 GB of cloud storage. Wuala will copy encrypted files from other users onto your hard drive, and your encrypted files onto other Wuala users hard drives, forming a redundant cloud network. And if you have several computers connected to the same account and share local disk from all of them, then you are rewarded with cloud disk for all of it. If you need more than this, then you have to pay.&lt;/li&gt;
&lt;li&gt;Wuala works well with Linux, Mac and Windows, but the cross platform support isn&#39;t as good as for Dropbox. &lt;/li&gt;
&lt;li&gt;Wuala isn&#39;t really as easy to use as Dropbox, but some of that is on purpose, since they are dead serious about the privacy of your files.&lt;/li&gt;
&lt;/ul&gt;If you are committed to 100% open source then neither Dropbox or Wuala is for you. I&#39;d recommend &lt;a href=&quot;http://tahoe-lafs.org/&quot;&gt;Tahoe-LAFS&lt;/a&gt;, which is a piece of software I plan to talk about some other week.&lt;br /&gt;
&lt;br /&gt;
Wuala is a Swiss company, so probably not as likely to yield to governments knocking on the door asking for information. Regardless, I recommend downloading their software, register an account and check it out.</description><link>http://pirate-software.blogspot.com/2011/01/pirate-software-week-4-wuala.html</link><author>noreply@blogger.com (Unknown)</author><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3859105325576740988.post-3928086495157200573</guid><pubDate>Sat, 22 Jan 2011 10:30:00 +0000</pubDate><atom:updated>2011-01-22T11:42:58.731+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">bitcoin p2p currency anonymity privacy</category><title>Pirate Software, week 3: Bitcoin</title><description>I believe &lt;a href=&quot;http://www.bitcoin.org/&quot;&gt;Bitcoin&lt;/a&gt; is the nest evolutionary step for money!&lt;br /&gt;
&lt;br /&gt;
Which is a pretty bold statement, but let me explain. Bitcoin is encrypted currency in a peer-to-peer network. The code that runs all this is open source (with a few core developers) and the &lt;a href=&quot;http://www.bitcoin.org/smf/&quot;&gt;community&lt;/a&gt; around it is very very active. It is not backed by anything, such as gold, so its value is only backed by its usefulness, and the possibility of it becoming really big in the future.&lt;br /&gt;
&lt;br /&gt;
The &lt;a href=&quot;http://www.mtgox.com/&quot;&gt;current price&lt;/a&gt; (2011-01-22) for 1 Bitcoin (BTC) is USD 0.39, which is about &lt;span class=&quot;converted-result&quot;&gt;€ 0.29&lt;/span&gt; or SEK 2.57. The value goes up and down quite a bit, so don&#39;t buy Bitcoins for all your money, OK?&lt;br /&gt;
&lt;br /&gt;
The compelling features of Bitcoin (compared to money 1.0) is:&lt;br /&gt;
&lt;ol&gt;&lt;li&gt;You can be pretty much anonymous when you send money.&lt;/li&gt;
&lt;li&gt;Transfers can&#39;t be stopped, so if you wish to send money to Steve in Rio, nobody can stop it, not even Steve.&lt;/li&gt;
&lt;li&gt;Transfers are completely free, or almost free (I can&#39;t go into details here, unfortunately), so no bank or credit card company will take a slice.&lt;/li&gt;
&lt;li&gt;Transactions are pretty fast (within a few minutes), at least compared to many bank transfers. Not as fast as handing over cash, but almost.&lt;/li&gt;
&lt;/ol&gt;It is clear that Bitcoins in many ways are superior to money 1.0, and anonymous unstoppable transfers of money will not be popular with some governments, so we can expect a very hard reaction against Bitcoin in the future. That alone is perhaps reason enough to start using Bitcoins - who doesn&#39;t want to be a rebel?&lt;br /&gt;
&lt;br /&gt;
So, how does all of this work? Well, it is all described on the Bitcoin &lt;a href=&quot;http://www.bitcoin.org/wiki/doku.php?id=technical_series&quot;&gt;website&lt;/a&gt;, where there are free downloads for Mac, Windows and Linux. Go there, download the program, start it up, and contact me by encrypted email to &lt;a class=&quot;moz-txt-link-abbreviated&quot; href=&quot;mailto:mats_s@henricson.se&quot;&gt;mats_s@henricson.se&lt;/a&gt; (you should know how to do it now, right (LÄNK)) and I&#39;ll send you a Bitcoin to get you started. I currently have about 140 Bitcoins. All I need from you is a Bitcoin address. Here is one of my addresses: &lt;br /&gt;
&lt;blockquote style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;b&gt;1J68uJvM1RL6ZU3iSWaHPrJyM1TTkxMcGj&lt;/b&gt;&lt;/blockquote&gt;All I need from you is such an address, which your Bitcoin program can generate for you. Then send the coin somewhere, such as to the EFF. Their address is:&lt;br /&gt;
&lt;blockquote style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;b&gt;1MCwBbhNGp5hRm5rC1Aims2YFRe2SXPYKt&lt;/b&gt;&lt;/blockquote&gt;Just a few days ago there was an article on EFF&#39;s website called &quot;&lt;a href=&quot;https://www.eff.org/deeplinks/2011/01/bitcoin-step-toward-censorship-resistant&quot;&gt;Bitcoin - a step Toward Censorship-Resistant Digital Currency&lt;/a&gt;&quot;. It is a good read.&lt;br /&gt;
&lt;br /&gt;
&quot;Bitcoin is to Paypal as email is to fax.&quot;</description><link>http://pirate-software.blogspot.com/2011/01/pirate-software-week-3-bitcoin.html</link><author>noreply@blogger.com (Unknown)</author><thr:total>3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3859105325576740988.post-6339158644056357464</guid><pubDate>Mon, 17 Jan 2011 07:00:00 +0000</pubDate><atom:updated>2011-01-20T10:40:38.230+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">enigmail thunderbird encryption email</category><title>Pirate Software, week 2: Enigmail</title><description>There are many ways to send encrypted messages by email. I use Thunderbird, which has had an encryption plugin since 2003, called &lt;a href=&quot;http://enigmail.mozdev.org/&quot;&gt;Enigmail&lt;/a&gt;. It is reasonably simple to setup. Enigmail will prompt you for a password, and you&#39;ll better pick a strong one (described &lt;a href=&quot;https://secure.wikimedia.org/wikipedia/en/wiki/Password_strength#Examples_that_follow_guidelines&quot;&gt;here&lt;/a&gt;, among other places). Enigmail then lets you publish your public key to special key-servers where it can be found. You can also put it online somewhere. I have my public key &lt;a href=&quot;http://dl.dropbox.com/u/1416421/Mats%20Henricson%20mats_s%40henricson.se%20%280x6EC8CFB6%29%20pub.asc&quot;&gt;here&lt;/a&gt;. Have a look - it is good to know what these keys look like! You won&#39;t get my private key, though. It is for my eyes only.&lt;br /&gt;
&lt;br /&gt;
I have chosen to use a special email address for my encrypted emails, mats_s@henricson.se. The reason is because I once used my ordinary email address, then by mistake threw away my key. Don&#39;t ask me for details - it was so stupid that it still makes me blush, even though it happened 7 years ago.&lt;br /&gt;
&lt;br /&gt;
Now, turn on Enigmail encryption for your email account, and send me an &lt;a href=&quot;mailto:mats_s@henricson.se&quot;&gt;email&lt;/a&gt;! I promise to send an encrypted email back, letting you know it works.</description><link>http://pirate-software.blogspot.com/2011/01/pirate-software-week-2-enigmail.html</link><author>noreply@blogger.com (Unknown)</author><thr:total>6</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3859105325576740988.post-5179449337081991166</guid><pubDate>Sun, 09 Jan 2011 19:25:00 +0000</pubDate><atom:updated>2011-01-09T20:25:40.152+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">https everywhere eff</category><title>Pirate Software, week 1: HTTPS Everywhere</title><description>Most web traffic on the net is transferred pretty much in clear text, dead simple to read by anyone between your computer and the destination computer. The protocol used is, as you may know, &lt;span style=&quot;font-weight: bold;&quot;&gt;http&lt;/span&gt;. If this was the only way to communicate on the web, all our passwords would be stolen as soon as we sent them. Fortunately there is a cousin protocol called &lt;span style=&quot;font-weight: bold;&quot;&gt;https&lt;/span&gt; where the &quot;s&quot; stands for &quot;secure&quot;. It is in use in most cases where you login to a website (such as GMail). After you have logged in, traffic most often goes back to the insecure http protocol again.&lt;br /&gt;
&lt;br /&gt;
Now, why isn&#39;t https used everywhere, all the time? Traditionally the reason has been performance, since https traffic is encrypted, which requires mindboggling long computations on the server. Lately it has been shown that https can be turned on by default for all traffic with very little penalty. GMail is such a product, so you can actually read all your Google email using https. Unfortunately, most sites out there are still using https for login only.&lt;br /&gt;
&lt;br /&gt;
This is where the &lt;a href=&quot;https://www.eff.org/https-everywhere&quot;&gt;HTTPS Everywhere&lt;/a&gt; Firefox plugin from the Electronic Frontier Foundation comes in. It will do all the switching to https for you, automatically, for a whole bunch of sites:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Google Search&lt;/li&gt;
&lt;li&gt;Wikipedia&lt;/li&gt;
&lt;li&gt;Twitter&lt;/li&gt;
&lt;li&gt;Facebook&lt;/li&gt;
&lt;li&gt;bit.ly&lt;/li&gt;
&lt;li&gt;Wordpress.com blogs&lt;/li&gt;
&lt;li&gt;The New York Times&lt;/li&gt;
&lt;li&gt;The Washington Post&lt;/li&gt;
&lt;li&gt;Paypal&lt;/li&gt;
&lt;li&gt;EFF&lt;/li&gt;
&lt;li&gt;Tor&lt;/li&gt;
&lt;li&gt;...&lt;br /&gt;
&lt;/li&gt;
&lt;/ul&gt;So, a Google search for &quot;tunisia&quot; automatically becomes:&lt;br /&gt;
&lt;blockquote&gt;https://encrypted.google.com/search?q=tunisia&lt;/blockquote&gt;And if you click on the Wikipedia http link that looks like this:&lt;br /&gt;
&lt;blockquote&gt;http://en.wikipedia.org/wiki/Tunisia&lt;/blockquote&gt;The HTTPS Everywhere plugin will ensure that you are instead sent to this https link:&lt;br /&gt;
&lt;blockquote&gt;https://secure.wikimedia.org/wikipedia/en/wiki/Tunisia&lt;/blockquote&gt;If you use this Firefox plugin, the result is that it gets much much much harder to listen in to what you do on all of these websites mentioned above. If all web traffic was transformed from http to https, then it gets almost impossible for &lt;a href=&quot;http://www.fra.se/&quot;&gt;FRA&lt;/a&gt; to do any surveillance of Swedish web traffic.&lt;br /&gt;
&lt;br /&gt;
Now, who are these Electronic Frontier Foundation guys? They are indeed one of the truly Good Guys on the net. Quote from their website:&lt;br /&gt;
&lt;blockquote&gt;When our freedoms in the networked world come under attack, the  Electronic Frontier Foundation (EFF) is the first line of defense.&lt;/blockquote&gt;So, you can trust them!&lt;br /&gt;
&lt;br /&gt;
The plugin is very simple to install, and just works! &lt;a href=&quot;https://www.eff.org/https-everywhere&quot;&gt;Get it now&lt;/a&gt;!&lt;br /&gt;
&lt;span class=&quot;f&quot;&gt;&lt;cite&gt;&lt;/cite&gt;&lt;/span&gt;</description><link>http://pirate-software.blogspot.com/2011/01/pirate-software-week-1-https-everywhere.html</link><author>noreply@blogger.com (Unknown)</author><thr:total>4</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3859105325576740988.post-8437039874972726077</guid><pubDate>Sat, 08 Jan 2011 23:43:00 +0000</pubDate><atom:updated>2011-01-09T01:00:44.778+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">pirate software privacy liberty freedom</category><title>Pirate Software of the week</title><description>Hi, all!&lt;br /&gt;&lt;br /&gt;Here I plan to blog once a week about various software that I believe are more or less essential to anyone that cares about online privacy, freedom and liberty. I have tried out a fair number of them over the years, and will try to only recommend software I know is good and simple to use. Eventually I will run out of software to recommend, possibly around summer 2011, at which point I hope to get some help from others. If you are interested in helping out, contact me at &lt;a href=&quot;mailto:mats_s@henricson.se&quot;&gt;mats_s@henricson.se&lt;/a&gt; (my encryption key is &lt;a href=&quot;http://dl.dropbox.com/u/1416421/Mats%20Henricson%20mats_s%40henricson.se%20%280x6EC8CFB6%29%20pub.asc&quot;&gt;here&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;I will do my best to explain:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;What the software is good for (what it does)&lt;/li&gt;&lt;li&gt;How to install and use it (is it simple or difficult)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;The licensing (most will be open source in various flavors)&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;So, mark this feed and stay tuned in case this interests you!</description><link>http://pirate-software.blogspot.com/2011/01/pirate-software-of-week.html</link><author>noreply@blogger.com (Unknown)</author><thr:total>4</thr:total></item></channel></rss>