
Blue Sky Views offers commentary by experts on issues related to innovation and entrepreneurship in Chicago.
If you’re worried about whether the government, or anyone else, can read your emails, I have good news and bad news. The bad news is that a determined, well-resourced attacker will almost always find a way. The good news is that you can take basic steps to protect your privacy, and those steps most likely will make a difference.
So say some of the leading figures in the unclassified cryptography community. I asked them what they do to safeguard their most important communications.
Two themes emerged: Establish unbreakable — or nearly unbreakable — passwords, and encrypt your most sensitive email.
See encryption at work using the buttons below
Created National Institute of Standards and Technology, 2001, based on Rijndael cipher
Key length 128, 192 and 256 bits
Used in WinZip, Windows 2000 and later file-system encryption, FileVault disk encryption on OS X, OpenSSL
Status Under suspicion of weakening by NSA
Created IBM, early 1970s
Key length 56 bits
Used in Not currently in use, but catalyzed academic, non-military study of cryptography
Status Known to be insecure due to small key length
Created American National Standards Institute and other government agencies, 1998 or earlier, by applying DES 3 times on each block of a message
Key length 56, 112 or 168 bits
Used in Electronic payments including MasterCard and Visa; Microsoft OneNote and Outlook 2007
More Top Picks Best Clip On Book Lights For Reading In Bed
Status National Institute of Standards and Technology considers it secure through 2030
Created Cryptico A/S, Copenhagen, 2003
Key length 128 bits
Used in Wireless networks, open-source SSL/TLS implementations
Status No known significant vulnerabilities
Created Ron Rivest, RSA Security, 1987
Key length Variable, typically between 40 and 256 bits
Used in WEP and WPA WiFi security, Skype (modified form), PDF
Status Known vulnerability if portion of output isn’t discarded, other implementation flaws can render it very insecure
Implementation by CryptoJS
Encrypting gives you some control over your own security, and it is a more effective approach than you might think. Grounded in solid mathematical principles, open-source encryption tools make it effectively impossible for even the most sophisticated attacker to decrypt a message. This is because these tools rely on intrinsic properties of very large numbers that are fairly mind-blowing.
For instance, as Bruce Schneier demonstrated in his book “Applied Cryptography,” if you were to hook up a decryption computer to a supernova and somehow convert all of the energy released by that stellar explosion into attempts to decode a secret with brute force (i.e., random guessing), you would eventually be able to guess any 219-bit password.
But typical strong passwords, or keys (which are reasonably interchangeable for the purposes discussed here), used today are 256 bits long. And with each additional bit added to the key length, the amount of effort required to randomly guess a password doubles. This means you would need one supernova to guess a 219-bit password; two to get to 220 bits; four to get to 221 bits; and 137 billion supernovae just to guess one 256-bit password.
How to pick and manage strong passwords
No encryption scheme is going to protect your data if the password you use is “password.” Dictionary-based attacks, where thousands of the most common passwords are guessed every second, can make quick work of short, insecure keys.
If your password isn’t long enough, even perfectly randomly generated passwords are vulnerable. In late 2012, a single system employing just 25 graphics cards, of the kind found in a consumer desktop PC, was able to guess more than 350 billion Windows passwords a second, according to a December 2012 article in Ars Technica, a technology news and information Web site.
That’s enough to try every possible eight-character password (consisting of letters, numbers and 33 different symbols) in under six hours. It would take that same machine more than 4 trillion years to guess all 16-character passwords using the same set of letters, numbers and symbols.
So long passwords are ideal, but they’re pretty tough to remember. It’s hard enough to recall something like Htu67%c* — and it’s completely unrealistic to expect most users to remember something twice as long and just as arbitrary.
Happily, with a long enough phrase, you can sacrifice some randomness and make a secure password easy to remember. Randall Monroe proposed one technique in his webcomic, “xkcd”: just pick four random words and use them as your password. “Join symphony forget blankets” is actually a pretty secure password, and much easier to remember than a much less secure, randomly generated string like “1&hT^s5%.”
And of course, don’t reuse any of these fiendishly complex long strings of random text, in case they get stolen from one Web site, leaving your accounts on others vulnerable.
So how can you possibly keep all of them straight, short of writing them down or getting a truly unholy number of tattoos? One option is to use a password manager like 1Password or Lastpass. Their browser extensions fill in your passwords and automatically generate new ones of whatever complexity you prefer.
While it might sound dangerous to store all your passwords with any one company, many of the technically inclined and security-conscious people I spoke with were more than comfortable with the arrangement. Formidable IT security is a craft, and most companies that don’t specialize in it aren’t likely to do it perfectly.
It’s obviously not without risk to store all your passwords in one place. But the benefits to your security of using a password manager to store a variety of strong passwords likely far outweigh the risks of using a centralized service to do so.
How to encrypt your emails (and other stuff)
If you want to keep a document or message safe, there’s no substitute for encrypting it, transforming it from a readable piece of text into something unintelligible.
Encryption algorithms work by applying complex mathematical operations to a message, and different algorithms use wildly different techniques. These techniques, while extremely complex, rely on some simple mathematical properties in order to be effective. An early technique relied on multiplying large prime numbers by other large primes, which results in numbers large enough to make it impractical to reverse the operation (a prime number discovered in 2013 contains more than 17 million digits, for instance).
One of the most common and still-secure methods for encrypting something that only certain people can read is called public-key cryptography. It relies upon pairs of keys — one public, one private — that allow anyone with the public key to encrypt a message but that prevent anyone from decrypting the message unless they have the accompanying private key. For instance, a freelance writer wishing to protect her communications would advertise her public key as widely as possible — on her Web site, in her unencrypted email signatures, on her business card and so on — so that anyone could correspond with her. When someone sends her a private message, they can include their own public key, allowing her to send encrypted messages back. (It should be noted that, even if an email is encrypted, the metadata associated with that email — what address sent it, to what address it was sent, what the subject line was, etc. — is sent in the open, and can be easily intercepted.)
Although recent Edward Snowden-leaked documents indicate the NSA has sabotaged certain public-key encryption algorithms, other algorithms remain — for the moment — free of suspicion. The experts I corresponded with still considered public-key encryption a powerful technique, even against adversaries as sophisticated as the NSA, but there is at least one serious weakness to any encryption protocol: the crowbar technique. In simplified terms, imagine what would happen if several large individuals with crowbars began beating you while demanding your encryption password, and you begin to see some flaws in the whole endeavor.
The crowbar technique demonstrates the ultimate futility of any technological solution to a non-technical problem, but it shouldn’t dissuade you from securing your data, anyway.
For most users, encryption, strong passwords and good security practices aren’t meant to keep all of your data safe from prying eyes for eternity; they’re meant to make it that much harder to steal your secrets, encouraging attackers to look elsewhere. In that way, they have more in common with the lock on your front door than the vault at your bank.
Abraham Epton is a Web developer for the baiduhai and Blue Sky Innovation and previously worked at Google News. A Chicago native, he earned a B.A. in international relations with a minor in computer science from the University of Illinois in Urbana-Champaign. He uses a password manager to generate and save strong passwords. Most of the time.
More Top Picks Ratings
.crypt-text {
word-wrap: break-word;
}
#schemes {
margin-bottom: 10px;
}
#decrypt {
margin-bottom: 20px;
margin-left: 35%;
}
.encrypt-options {
margin-bottom: 20px;
}
http://crypto-js.googlecode.com/svn/tags/3.1.2/build/rollups/aes.js
http://crypto-js.googlecode.com/svn/tags/3.1.2/build/rollups/tripledes.js
http://crypto-js.googlecode.com/svn/tags/3.1.2/build/rollups/rabbit.js
http://crypto-js.googlecode.com/svn/tags/3.1.2/build/rollups/rc4.js
http://crypto-js.googlecode.com/svn/tags/3.1.2/build/components/core-min.js
http://crypto-js.googlecode.com/svn/tags/3.1.2/build/components/enc-base64-min.js
var crypt_key = “Yes, I used a cleartext key.”;
var crypt_status = {};
var glob_crypt_status = false;
var in_process = false;
var last_used_scheme = ‘aes’;
var last_hovered_scheme = ‘aes’;
$(document).ready(function() {
$(‘#decrypt’).hide();
$(‘.explainer’).hide();
$(‘#’ + last_used_scheme + ‘_explainer’).show();
$(‘.encrypt’).click(function() {
last_used_scheme = this.id;
$(‘.crypt-text’).each(function() {
toggleCryptElement(this.id);
});
glob_crypt_status = true;
$(‘.encrypt-options’).hide();
setTimeout(function() {
$(‘#decrypt’).show();
var header = $(‘#header-text’).text();
if (header.length > 45) {
$(‘#header-text’).html(
header.substr(0, 45) + ‘‘);
}
}, 500);
});
$(‘#decrypt’).click(function() {
$(‘.crypt-text’).each(function() {
toggleCryptElement(this.id);
});
$(‘.encrypt-options’).show();
$(‘#decrypt’).hide();
$(‘#’ + last_used_scheme + ‘_explainer’).show();
});
$(‘.encrypt’).mouseover(function() {
$(‘#’ + last_hovered_scheme + ‘_explainer’).hide();
$(‘#’ + this.id + ‘_explainer’).show();
last_hovered_scheme = this.id;
});
});
function toggleCryptElement(el_id) {
if (in_process) {
return;
}
var text = ”;
if (!crypt_status.hasOwnProperty(el_id)) {
in_process = true;
$(“#” + el_id).text(encryptText($(“#” + el_id).text()));
crypt_status[el_id] = true;
in_process = false;
} else if (crypt_status[el_id] == false) {
in_process = true;
$(“#” + el_id).fadeOut(function() {
$(“#” + el_id).text(encryptText($(“#” + el_id).text()));
$(“#” + el_id).show();
});
crypt_status[el_id] = true;
in_process = false;
} else if (crypt_status[el_id] == true) {
in_process = true;
$(“#” + el_id).fadeOut(function() {
$(“#” + el_id).text(decryptText($(“#” + el_id).text()));
$(“#” + el_id).show();
});
crypt_status[el_id] = false;
in_process = false;
}
}
function encryptText(cleartext) {
if (last_used_scheme == ‘aes’) {
return CryptoJS.AES.encrypt(cleartext, crypt_key).toString();
} else if (last_used_scheme = ‘des’) {
return CryptoJS.DES.encrypt(cleartext, crypt_key).toString();
} else if (last_used_scheme = ‘3des’) {
return CryptoJS.TripleDES.encrypt(cleartext, crypt_key).toString();
} else if (last_used_scheme = ‘rabbit’) {
return CryptoJS.Rabbit.encrypt(cleartext, crypt_key).toString();
} else if (last_used_scheme = ‘rc4’) {
return CryptoJS.RC4.encrypt(cleartext, crypt_key).toString();
} else if (last_used_scheme = ‘rc4drop’) {
return CryptoJS.RC4Drop.encrypt(cleartext, crypt_key).toString();
} else {
return ”
}
}
function decryptText(ciphertext) {
if (last_used_scheme == ‘aes’) {
return CryptoJS.AES.decrypt(ciphertext, crypt_key).toString(CryptoJS.enc.Utf8);
} else if (last_used_scheme = ‘des’) {
return CryptoJS.DES.decrypt(ciphertext, crypt_key).toString(CryptoJS.enc.Utf8);
} else if (last_used_scheme = ‘3des’) {
return CryptoJS.TripleDES.decrypt(ciphertext, crypt_key).toString(CryptoJS.enc.Utf8);
} else if (last_used_scheme = ‘rabbit’) {
return CryptoJS.Rabbit.decrypt(ciphertext, crypt_key).toString(CryptoJS.enc.Utf8);
} else if (last_used_scheme = ‘rc4’) {
return CryptoJS.RC4.decrypt(ciphertext, crypt_key).toString(CryptoJS.enc.Utf8);
} else if (last_used_scheme = ‘rc4drop’) {
return CryptoJS.RC4Drop.decrypt(ciphertext, crypt_key).toString(CryptoJS.enc.Utf8);
} else {
return ”
}
}