Skip to Content
  • Home
  • About the Bar
  • Mission
  • Forms
  • Sitemap
    • Licensee Directory
      Last Name:
      First Name:
      Bar Number:
      City:


    • Login
OSB Logo

Oregon State Bar Bulletin — NOVEMBER 2008
Managing Your Practice
Active Privacy
Hiding from Prying Eyes
By Richard Abbott


This article describes some of the basic tools available to avoid being watched while online. This is not an article about picking good passwords, or not giving out personal information. This is an article describing tools for avoiding surveillance, be it illegal or otherwise. These tools allow you to play in the big leagues but they are also simple, free and totally open source. Some are good for everyday use, but most should be keep in your back pocket for that day you really need to not be watched.

Use Onions to Hide Your IP Address

www.torproject.org
Windows: www.vidalia-project.net
Linux: www.anonymityanywhere.com

The Onion Relay (TOR) is a network of encrypted proxy servers run by members of the public. TOR bounces internet traffic over random chains of these proxies to effectively mask the sender’s IP address from everyone involved. The use of a layered encryption protocol (the onion) means that anyone listening in on your internet connection will not be able to read your traffic. TOR users may access most all internet resources including web pages, IRC servers or even peer-to-peer networks without worry of wiretaps, packet shaping or other monitoring efforts by network administrators, ISPs or law enforcement.

The TOR network is sustained by those users who choose to donate bandwidth by hosting proxies, but anyone with the appropriate software may access the network. There are normally upwards of a thousand active TOR proxies. This vast distribution is key to frustrating any attempt to follow traffic across the network.

TOR offers users many unique abilities. Users may access Hidden Services, essentially secret websites accessible only through TOR. Existing outside of the normal internet, these pages and untraceable and answer to nobody. Additionally, having a choice of exit proxies allows TOR to circumvent censorship. TOR users may access websites not available in their home countries, or students may access Facebook.com from behind restrictive school firewalls. But perhaps TOR’s most powerful gift is the ability to investigate and test for the existence of censorship. Select a Chinese exit proxy and watch www.friends-of-tibet.org suddenly become unavailable.

But be warned! The configuration and safe use of TOR presents many challenges and requires some degree of skill. Do your homework before trusting TOR with anything important.

Use Encrypted E-mail

www.gnupg.org

Spend any time discussing IT security and you will run across Pretty Good Privacy (PGP). GnuPG is an open source implementation of the OpenPGP standard. At its heart, all PGP relies on encryption key pairs. Each user keeps one secret key, and its matching public key is meant to be shared. PGP e-mails are encrypted with the public key of the intended recipient and are then decodable only with the recipient’s secret key. Conversely a sender may digitally sign an e-mail with their secret key so that others may thereafter authenticate it against the sender’s public key.

Getting up an running with GnuPG is relatively simple. Most all e-mail clients offer support natively or via plug-ins. PGP and GnuPG are not limited to e-mail. All forms of data may be encrypted or signed with PGP keys. The downside of the scheme is its reliance on encryption key pairs which make communication with people not already familiar with PGP problematic.

Send Anonymous E-mail

mixminion.net
Windows Client: peculiarplace.com/mixminion-message-sender

Mixminion is an anonymous e-mail service that handles e-mail in much the same way that TOR handles general traffic. E-mail messages are encrypted, cut into pieces, bounced around several volunteer servers, then recompiled and sent to their destination. The e-mail arrives and is read just as any other normal e-mail. Mixminion e-mails, unlike PGP, are readable by recipients who know nothing about the system. This makes the system perfect for anonymous whistle blowing. Replies are possible without revealing the identity of the initial sender, but any such reply must be sent thought the Mixminion network. Even then, replies are only possible where the initial sender has taken the time to forward an appropriate Single Use Reply Block. Ongoing two-way conversations are labor intensive, so Mixminion therefore is best used for starting conversations or arranging more convenient methods of anonymous communication.

Hide Your Encrypted Files

www.TrueCrypt.org/

There are hundreds of encryption tools out there, but TrueCrypt offers some unique advantages. TrueCrypt utilizes volume encryption. Rather than encrypt specific files, an single large file called an "encrypted volume" is created. Initially this large file is empty. TrueCrypt then opens this file and "mounts" it as a virtual drive on your machine. Users may then work with directories and files within this virtual drive as they would any physical drive. When the time comes, the encrypted volume is unmounted and the virtual drive disappears. The encrypted volume does not change in size as it is filled or emptied. An attacker in possession of the unopened volume cannot read the contents, but also cannot even tell if there is anything inside to read.

Good passwords are the secret to effective encryption. A 256-plus bit encryption protocol is worthless if you use "password" as your password, but perfect series of random characters is equally useless if you scribble it on a post-it note beside your screen. There is another way. TrueCrypt allows the use of Keyfiles. Instead of remembering a long password, one need only point TrueCrypt to the appropriate file from which TrueCrypt extracts a hash. Multiple keyfiles may be combined with or without an additional pass phrase, allowing for complex custom security protocols to be developed. For instance, give each partner a separate keyfile and partnership records may only be opened in the presence of all. Or destroys one file, and the records are closed forever.

TrueCrypt’s most powerful tool may be its use of Hidden Volumes. Any TrueCrypt volume may in fact accept two separate password/keyfile combinations. When one is used, the outer volume opens and the user sees some files, and some apparently empty space. Use the other password and the hidden volume opens to reveal other files, and some other apparently empty space. Importantly, the existence or absence of a hidden volume cannot be proven without both password sets. A user may therefore provide one password and effectively deny any use of TrueCrypt’s hidden volume feature.

Conclusion
This may all seem very cloak and dagger, it should. Some of these tools began life in the world of defense intelligence and they are commonly used to hide very illegal activities. But one country’s criminal is another’s hero. If you are a Chinese dissident, a corporate whistlerblower or a lawyer with a terrorist for a client, these tools will help you keep control over you and your client’s privacy.

ABOUT THE AUTHOR
Richard Abbott is an IT consultant turned attorney and can be reached at Rabbit@shaw.ca..


— return to top
— return to Table of Contents

  • For The Public

      Public Legal Information

    • Public Information Home
    • Legal Information Topics
    • Oregon Juror Guide
    • Submit Ethics Complaint

    • Getting Legal Help

    • Finding The Right Lawyer
    • Hiring A Lawyer
    • Lawyers Fees

    • Client Services

    • Client Assistance Office
    • Client Security Fund
    • Fee Dispute Resolution
    • Public Records Request
    • Locating Attorney Files

    • Unlawful Practice of Law

    • UPL Information
    • UPL FAQ

    • Volunteer Opportunities

    • Public Volunteer Application
  • For Licensees

    OSB Login

    • Log In To OSB Site
    • Licensee Account Setup
    • Non-Licensee Account Setup
    • Reset Password

    OSB Resources

    • Career Center
    • Events
    • Forms Library
    • Marketplace
    • Online Resources
    • OSB Group Listings
    • Performance Standards
    • Rules Regulations and Policies
    • Surveys and Research Reports
    • Unclaimed Client Funds
    • Voting Regions and By-City
      County Information

    Benefits for Licensees

    • Log in to Decisis
    • – Decisis Information
    • – Decisis FAQ
    • – Inactive Licensee Subscriptions
    • No Cost Trust & Billing Software

    Legal Ethics

    • Legal Ethics Home
    • Find an Ethics Opinion
    • Bulletin Bar Counsel Archive

    Company Administrator

    • Company Administrator Home
    • Company Administrator FAQ
    • Authorization Form

    State Lawyers
    Assistance Committee

    • SLAC Info

    Volunteering

    • Volunteer Opportunities

    Court Information

    • Judicial Vacancies
    • Court Info | Calendars | Jury Info
    • Oregon Attorneys
      in Federal Court
    • Tribal Courts of Oregon

    OSB Publications

    • Bar Bulletin Magazine
    • – Bulletin Archive
    • – Legal Writer Archive
    • Capitol Insider
    • Disciplinary Board Reporter

    PLF Programs

    • (OAAP) Oregon Attorney
      Assistance Program
    • Practice Management Attorneys
    • Malpractice Coverage
  • CLE/Legal Publications

    CLE Seminars

    • CLE Seminars Home
    • Online Seminar Registration
    • General Info/FAQ

    My Account

    • My Content
    • My Events
    • Order History

    Legal Publications

    • Legal Publications Home
    • Log in to BarBooksTM
    • BarBooksTM FAQ
    • Online Bookstore
    • Legal Pubs Blog
  • Bar Programs

    Diversity & Inclusion

    • Diversity & Inclusion Home
    • Diversity Story Wall
    • D&I Programs
    • ACDI Roster
    • D&I Staff Contacts
    • D&I Links

    Legislative/Public Affairs

    • Legislative Home
    • Committee Contacts
    • Legislative Sessions
    • Staff Contacts
    • Useful Links

    Legal Services Program

    • LSP Home

    Oregon Law Foundation

    • OLF Home
    • Partners in Justice

    Fee Dispute Resolution

    • Fee Dispute Resolution Home

    Pro Bono

    • Pro Bono Home
    • Pro Bono Reporting
    • Volunteer Opportunities

    Lawyer Referral and Information Services

    • RIS Login
    • Summary of Referral and Information Services Programs
    • Lawyer Referral Service Info and Registration
    • Modest Means Program Registration Forms
    • Military Assistance Panel Training Info and Registration Form
    • Problem Solvers Registration Form
    • Lawyer To Lawyer Registration Form

    (LRAP) Loan Repayment Assistance Program

    • LRAP Home
    • LRAP FAQ
    • LRAP Policies
  • Licensee Groups

    Sections

    • Section Info/Websites
    • Joining Sections
    • CLE Registration Services
    • Standard Section Bylaws (PDF)
    • Leadership Resources
    • Treasurers Tools

    Committees

    • Home
    • Leadership Resources
    • Professionalism Commission
    • Volunteer Opportunities

    House of Delegates

    • HOD Home
    • HOD Resources
    • Meetings
    • Rules (PDF)
    • Roster (PDF)
    • Staff Contacts

    Board of Governors

    • BOG Home
    • Meetings & Agendas
    • Members
    • Liaisons
    • Committees
    • Resources
    • Task Forces

    Oregon New Lawyers Division

    • ONLD Home
    • Law Students
    • Student Loan Repayment
    • Committees
    • Upcoming Events

    Task Forces and Special Committees

    • Task Forces Home

    Volunteer Bars

    • List/Contacts
    • Leadership Resources

    Volunteering

    • Volunteer Opportunities
  • Licensing/Compliance

    Admissions

    • Admissions Home
    • Alternative Admittance
    • Applicants for Admission
    • Admissions Forms
    • Past Bar Exam Results

    Supervised Practice Portfolio Examination

    • SPPE Home

    Licensed Paralegal Program

    • LP Home

    Lawyer Discipline

    • Discipline Home
    • Disciplinary Board Reporter
    • Disciplinary Boards
    • Client Assistance Office
    • (SPRB) State Professional Responsibility Board

    Licensee Records

    • Address Changes
    • Good Standing Certificate
    • Request Discipline File Review

    MCLE

    • MCLE Home
    • Program Database
    • Forms
    • Rules (PDF)

    IOLTA Reporting

    • IOLTA Home
    • IOLTA FAQ
    • No Cost Trust & Billing Software

    Licensing Fees

    • Licensing Fee FAQ
    • Licensing Fee Payment

    Status Changes

    • Status Changes FAQ
    • Inactive Status Form
    • Retired Status Form
    • Active Pro Bono Status Form
    • Reinstatement Forms
    • Resignation Form A
    • Pending Reinstatements

    Unlawful Practice of Law

    • UPL Information
    • UPL FAQ

    Pro Hac Vice/Arbitration

    • Pro Hac Vice
    • Arbitration

    New Lawyer Mentoring Program

    • New Lawyer Mentoring Program Home

    Professional Liability Fund

    • Professional Liability
      Fund Website
For The Public

Public Information Home
Legal Information Topics
Oregon Juror Guide
Finding The Right Lawyer
Hiring A Lawyer
Lawyers Fees
Client Assistance Office
Public Records Request
Unlawful Practice of Law
Fee Dispute Resolution
Client Security Fund
Volunteer Opportunities
for the Public

For Licensees

BarBooksTM
Bulletin Archive
Career Center
Decisis
Judicial Vacancies
Legal Ethics Opinions
OSB Group Listings
OSB Login
OSB Rules & Regs
SLAC Info
Surveys and Reports
Volunteer Opportunities

CLE/Legal Pubs

CLE Seminars Home
Legal Publications Home

Bar Programs

Diversity & Inclusion
Fee Arbitration/Mediation
Legal Services Program
Legislative/Public Affairs
Loan Repayment
Assistance Program

Oregon Law Foundation
Pro Bono

Licensee Groups

Board of Governors
Committees
House of Delegates
Volunteer Bars
Oregon New
Lawyers Division

OSB Sections
Professionalism
Commission

Volunteer Opportunities

About The Bar

About the Bar
ADA Notice
Contact Info
Copyright Notice
Directions to the Bar
Meeting Room Rentals
Mission Statement
OSB Job Opportunities
Privacy Policy
Staff Directory
Terms of Use

Licensing/Compliance

Admissions
Client Assistance Office
Client Security Fund
IOLTA Reporting
Lawyer Discipline
MCLE
Licensee Fee FAQ
New Lawyer
Mentoring Program

Professional Liability Fund
Status Changes

Oregon State Bar Center

Phone: (503) 620-0222
Toll-free in Oregon: (800) 452-8260
Facsimile: (503) 684-1366

Building Location:
16037 SW Upper Boones Ferry Road
Tigard, OR 97224

Mailing Address:
PO Box 231935
Tigard, OR 97281

Oregon State Bar location Map

Copyright ©1997 Oregon State Bar  ®All rights reserved | ADA Notice | Mission Statement | Privacy Policy | Terms of Use