Originally posted by TexasGuy1988
View Post
I doubt that even using VPNs would be helpful to avoid being tracked. The Onion RIng browser (TOR) was funded by the CIA to give its agents in foreign countries a way to report in without having to leave messages at drops, using carriers, etc... The gov hackers can use what they call "signatures" that are unique to each computer, based on hardware, OS, browser, applications running, etc., to identify specific data streams. In addition to that, they have "partnered" with ISPs to add tracking numbers to each HTML packet header, which gets passed along regardless of what VPN or TOR triplet you access. Using a P2P protocol, like FreeNet, IPFS, etc..., will establish a tunnel from your computer through your ISP to your destination, providing they are using the same protocol, and the information passing through it is encrypted. However, they can still identify the tunnel and save its packets for later analysis. A story of how the feds attacked the Dark Web is here.
I suspect that progress on quantum computers is occurring faster than researchers are saying, and it wouldn't surprise me to learn that the Feds (or Russia or China or Israel) have been using them for over 5 years to crack many passwords. Look how quickly Israel hacked into a locked Apple iPhone. Therefore, it also wouldn't surprise me to learn that the gov has been throwing shade on quantum computer development for that long as well.
Shor's and/or Grover's quantum algorithms may be farther along that we realize. It is often claimed that the AES-256 requires an attack time (or string size of 2^128 (9007 TB), but actual has been reduced to 2^56, which is less than what was required of the AES-128 key. Besides, AES-256 keys derived from text string passwords could have less than 256 bits of entropy because of pattern similarity: greygeek1234, greygeek1235, greygeek1236, etc....
So, want to keep it secure? Don't save it on a computer, especially one connected to the Internet. For me, running Kubuntu and my firewalls to keep normal hackers out, and 4096 key to sign my emails so that they can't be altered by recipients who could claim I wrote something I didn't, is all the security I will bother to support. The rest just takes too much time and bother, and is a pain to maintain. I even remove apparmor, which is also a big pain.




Leave a comment: