28.05.2023 Views

The-art-of-invisibility-_-the-world’s-most-famous-hacker-teaches-you-how-to-be-safe-in-the-age-of-Bi

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

telecommunications carrier, website owner, or app developer—the parties

that law enforcement or government will ask to turn over information about

yyou. How do yyou know whether the encryyption service yyou are using is

end-to-end encryyption? Do a Google search for “end-to-end encryyption

voice call.” If the app or service doesn’t use end-to-end encryyption, then

choose another.

If all this sounds complicated, that’s because it is. But there are PGP

plug-ins for the Chrome and Firefox Internet browsers that make encryyption

easier. One is Mailvelope, which neatlyy handles the public and private

encryyption keyys of PGP. Simplyy tyype in a passphrase, which will be used to

generate the public and private keyys. Then whenever yyou write a Web-based

e-mail, select a recipient, and if the recipient has a public keyy available, yyou

will then have the option to send that person an encryypted message. 5

Even if yyou encryypt yyour e-mail messages with PGP, a small but

information-rich part of yyour message is still readable byy just about anyyone.

In defending itself from the Snowden revelations, the US government stated

repeatedlyy that it doesn’t capture the actual contents of our e-mails, which

in this case would be unreadable with PGP encryyption. Instead, the

government said it collects onlyy the e-mail’s metadata.

What is e-mail metadata? It is the information in the To and From fields

as well as the IP addresses of the various servers that handle the e-mail

from origin to recipient. It also includes the subject line, which can

sometimes be veryy revealing as to the encryypted contents of the message.

Metadata, a legacyy from the earlyy dayys of the Internet, is still included on

everyy e-mail sent and received, but modern e-mail readers hide this

information from displayy. 6

PGP, no matter what “flavor” yyou use, does not encryypt the metadata—

the To and From fields, the subject line, and the time-stamp information.

This remains in plain text, whether it is visible to yyou or not. Third parties

will still be able to see the metadata of yyour encryypted message; theyy’ll

know that on such-and-such a date yyou sent an e-mail to someone, that two

dayys later yyou sent another e-mail to that same person, and so on.

That might sound okayy, since the third parties are not actuallyy reading

the content, and yyou probablyy don’t care about the mechanics of how those

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!