synthetikal.com Forum Index


Secure communication: Encrypted instant messaging
Goto page 1, 2, Next
Post new topic   Reply to topic    synthetikal.com Forum Index -> Computer Security
Author Message
Ionium

Joined: 09 Feb 2005
Posts: 20
544.40 Points

Mon Mar 07, 2005 8:00 am
Reply with quote

For private communications, I use X-IM. It has these features:



Hush messenger is also an option. Security is just about the same as X-IM.

A good thing about the above clients is that logging is not an option, unless you manually copy/paste it all into a file, so your chat will not accidentally be stored in a file.

I personally trust these programs enough to chat openly about absolutely private matters on them. If anyone knowledgeable about communication and data security think this is a bad idea, I'd like to hear your views on the subject.
Back to top
MargaretThatcher

Joined: 16 Feb 2005
Posts: 142
4420.96 Points

Tue Mar 08, 2005 7:14 am
Reply with quote

Never trust proprietary solutions. Currently, I would choose an open source
end-to-end encryption client. Jabber or SILC are the better chat protocols. Psi is a good jabber client.

You can use i2p to anonymise the client.
Back to top
Spacemonkey

Joined: 14 Feb 2005
Posts: 29
759.14 Points

Tue Mar 08, 2005 7:27 am
Reply with quote

Theres a pretty decent Encryption Plugin for Gaim as well.
Back to top
Ionium

Joined: 09 Feb 2005
Posts: 20
544.40 Points

Tue Mar 08, 2005 7:42 am
Reply with quote

The source code for X-IM is available on request, and the source code for the Hush encryption engine is available for download.
Back to top
IndoleAmine
Dreamreader Deluxe
Joined: 09 Feb 2005
Posts: 681
Location: Bahamas
18717.10 Points

Tue Mar 08, 2005 7:55 am
Reply with quote

Hush communications earns their money by providing 100% secure, transparent encryption for internet communication media, one single case creating a bad reputation could kill such a corporation. So they will do everything they can to provide the best service possible (somewhat like a bank) - I think (hope) one can trust them on their security....

(wasn't aware that they provide their source code for the algorithm though)


i_a
Back to top
auttie

Joined: 02 Jun 2005
Posts: 18
588.80 Points

Thu Jun 02, 2005 10:48 am
Reply with quote

silc is the way to go.. it provides you with a secure and possibly anonymous chatting platform.. http://www.silcnet.org/ I recomend everyone check it out.. we are coming to a new age.. its inportant that we bee careful.. we cant take risks.. understand your technology before you trust it.
Back to top
loki
guinea pig
Joined: 09 Mar 2005
Posts: 391
14167.88 Points

Thu Jun 02, 2005 11:50 am
Reply with quote

i'm running a silc server at m0c.no-ip.org on port 706... if anyone wants to chat to me i'm always logged into the room 'monastery' I'd be more than happy to have other rooms running, my server is not up 100% of the time, probably 98% or so. now and then my usb adsl modem misbehaves... so probably not very reliable yet, but getting there... might get better if i get a router/modem.
Back to top
auttie

Joined: 02 Jun 2005
Posts: 18
588.80 Points

Thu Jun 02, 2005 6:24 pm
Reply with quote

nice!
Back to top
MargaretThatcher

Joined: 16 Feb 2005
Posts: 142
4420.96 Points

Fri Jun 03, 2005 2:09 am
Reply with quote

Generally, the IRC protocol is best steered clear of - not because it is bad, but because it has a short message length, which makes it difficult to work with secure encryption clients and plugins.

There are a couple of encryption plugins for gaim. Remember, if you don't want the server host to be able to read your messages, you need end-to-end encryption, not just SSL to the server. Both of these plugins do end-to-end:

gaim-encryption http://gaim-encryption.sourceforge.net/

gaim otr http://www.cypherpunks.ca/otr/

For anonymity, i2p is a good solution. If you run a node, then you can connect pseudanonymously to servers hosted on the i2p network. There is one IRC and several jabber servers already hosted on i2p.

You can also get your client to tunnel through TOR to the messaging server to anonymise your connection.
Back to top
auttie

Joined: 02 Jun 2005
Posts: 18
588.80 Points

Fri Jun 03, 2005 11:48 am
Reply with quote

yah tor is your friend. I guess if nothing else def use encryption in gaim. tho.. gaim has proved unstable.. and there have been quite a few exploits for it. but if you cant bring yourself to use something like silc. def use encryption pluggins.
Back to top
loki
guinea pig
Joined: 09 Mar 2005
Posts: 391
14167.88 Points

Sat Jun 04, 2005 10:44 am
Reply with quote

yeah i just installed my gaim encryption plugin... i'm really waiting for silky to become a bit nicer and i'll quit using gaim for silc. On top of tor tho, i'm sure it's quite secure. tor has packet padding so packet sizes are either 500 or 1000 bytes each i think (or something like that)
Back to top
auttie

Joined: 02 Jun 2005
Posts: 18
588.80 Points

Sat Jun 04, 2005 11:45 am
Reply with quote

you should just use irssi for silc, in console.. it will be much more stable. GAIM+securtiy= flaky.. from what I heard.. but Im sure most of what I hear is biased..they are a bunch of bsd heads. I tryed connecting to your server yesturday w/ no luck I was using tor.. said it couldnt connect.. Ill try again in a few.. has a anonymous server which is nice. to all the windows users that are interested in secure communication.. and a new way of doing things Im more then willing to tell people what I know.. please consider making the switch to linux.. the big companies have alot in the works right now that will even further enslave computing... I guess they are just trying to take us to the breaking point =]

Last edited by auttie on Wed Jun 08, 2005 4:48 am; edited 1 time in total
Back to top
auttie

Joined: 02 Jun 2005
Posts: 18
588.80 Points

Sat Jun 04, 2005 11:56 am
Reply with quote

err I found out that this server is no longer functional.. Im sure a anonymous silc server will pop up.
Back to top
loki
guinea pig
Joined: 09 Mar 2005
Posts: 391
14167.88 Points

Sat Jun 04, 2005 12:00 pm
Reply with quote

i'm not sure why you can't get at my server... i get problems with it sometimes... you may have been unlucky and tried to get at it while connectivity was broken or something similar. i'm not sure what is causing the problem at this point, i should have a look and see if the usb adsl modem driver has been update yet
Back to top
MargaretThatcher

Joined: 16 Feb 2005
Posts: 142
4420.96 Points

Sun Jun 05, 2005 2:47 am
Reply with quote

Gaim is quite stable on Linux. The problem with gaim is bloat - it has so many protocols and features incorporated, that there are more places for security holes. Apart from silc, none of the clients I have come across seem to be written with security in mind.
Back to top
Display posts from previous:   
Post new topic   Reply to topic    synthetikal.com Forum Index -> Computer Security All times are GMT + 5.5 Hours
Goto page 1, 2, Next
Page 1 of 2

 



Powered by phpBB 2.0.11 © 2001, 2002 phpBB Group

Igloo Theme Version 1.0 :: Created By: Andrew Charron