Meta tags:
description= LESSON ID= 0019 Don’t worry, this first encryption lesson will be short and easy. We’re mostly just going to learn the lingo today. We need this to talk about the next lesson, Secure Browsers, and there will be a deeper encryption discussion in a later lesson. Why is this important? Remember from the Privacy and Anonymity…;
Headings (most frequently used words):
encryption, 101, menu, leave, comment, cancel, reply, symmetric, asymmetric, certificate, authorities, the, trust, factor, final, details, comments, on,
Text of the page (most frequently used words):
the (91), and (46), key (35), encryption (34), you (32), your (23), are (22), with (21), this (20), #symmetric (19), secure (18), keys (18), one (17), that (17), public (17), for (16), time (15), tor (14), lesson (13), can (13), there (12), asymmetric (12), they (11), used (11), email (10), level (10), got (10), text (10), from (9), private (9), encrypted (9), darknet (8), 101 (8), will (8), pad (8), need (8), message (8), enough (7), out (7), privacy (7), how (7), 2014 (7), what (7), encrypt (7), process (7), but (7), same (7), decrypt (7), isn (6), other (6), sites (6), tools (6), security (6), start (6), only (6), use (6), than (6), called (6), code (6), like (5), dark (5), black (5), stupid (5), have (5), https (5), part (5), browser (5), anonymity (5), concepts (5), way (5), shared (5), secret (5), otp (5), want (5), random (5), bits (5), certificate (5), authorities (5), get (4), content (4), now (4), system (4), test (4), surveillance (4), self (4), studies (4), hunt (4), vpn (4), freefor (4), pgp (4), browsing (4), data (4), info (4), 2015 (4), not (4), group (4), intel (4), version (4), technology (4), says (4), here (4), just (4), pki (4), session (4), lessons (4), their (4), both (4), different (4), being (4), plaintext (4), character (4), plain (4), organizations (4), bank (4), someone (4), wordpress (3), com (3), comment (3), comments (3), report (3), join (3), create (3), free (3), ssl (3), eff (3), metadata (3), find (3), tails (3), gpg (3), end (3), point (3), anon (3), tenets (3), coursework (3), follow (3), gbppr (3), patriot (3), some (3), today (3), reply (3), far (3), important (3), ffio (3), able (3), also (3), idea (3), reading (3), amused (3), technical (3), simple (3), next (3), sessions (3), many (3), something (3), know (3), non (3), types (3), since (3), much (3), length (3), kept (3), must (3), remember (3), pads (3), algorithm (3), examples (3), cas (3), trust (3), signed (3), these (3), when (3), communicate (3), design (2), site (2), website (2), required (2), log (2), sign (2), subscribed (2), subscribe (2), already (2), subscribers (2), tracker (2), visualizers (2), tests (2), dns (2), leak (2), behavior (2), tool (2), kit (2), defense (2), jacob (2), appelbaum (2), study (2), silk (2), road (2), case (2), parallel (2), construction (2), paul (2), revere (2), lizard (2), farmer (2), hamops (2), operation (2), turnkey (2), i2p (2), freenet (2), hidden (2), onion (2), whonix (2), virtual (2), machines (2), over (2), cascading (2), vpns (2), mask (2), unmask (2), haystack (2), linux (2), distros (2), encrypting (2), android (2), orb (2), risks (2), organize (2), spoofing (2), mac (2), internet (2), search (2), engines (2), anonymous (2), emails (2), read (2), rules (2), contact (2), address (2), opsec (2), red (2), team (2), project (2), page (2), radio (2), lastbox (2), ivy (2), mike (2), cafe (2), defensive (2), max (2), velocity (2), mosby (2), force (2), dialtone (2), comms (2), liberty (2), guerrillamerica (2), forward (2), primer (2), leave (2), sound (2), procedures (2), adequate (2), trump (2), careless (2), even (2), best (2), every (2), most (2), learned (2), infosec (2), doing (2), was (2), help (2), material (2), which (2), anyone (2), else (2), should (2), trying2b (2), thanks (2), deeper (2), see (2), discuss (2), more (2), well (2), folks (2), clear (2), publish (2), while (2), risk (2), trying (2), short (2), people (2), such (2), effectively (2), between (2), slower (2), transfer (2), parties (2), after (2), using (2), characters (2), very (2), math (2), formula (2), xor (2), decryption (2), ideally (2), all (2), unless (2), scrambling (2), 0019 (2), understand (2), least (2), lengths (2), bigger (2), has (2), them (2), send (2), legitimate (2), think (2), our (2), doesn (2), impersonating (2), certificates (2), going (2), right (2), huge (2), easy (2), ensure (2), happens (2), about (2), learn (2), home (2), started, name, write, loading, collapse, bar, manage, subscriptions, view, post, reader, copy, shortlink, account, blog, 2026, august, september, october, february, march, april, may, archives, suggest, real, new, then, krypt3ia, grugq, hacker, b3rn3d, staying, darkness, hack, crow, psywar, global, guerrillas, silicon, graybeard, open, warfare, mil, espionage, homebrew, main, green, bay, professional, packet, come, make, tech, wirecutter, lonely, libertarian, frontiersmen, steel, beam, sipsey, street, irregulars, pennsylvania, light, foot, ohio, valley, minutemen, renegade, militia, charles, carroll, society, alamance, county, rangers, south, carolina, sierra12, mason, dixon, tactical, john, training, combat, spartan, specops, medic, hogwart, grid, down, medicine, medics, sparks, radiomaster, reports, tradecraft, danmorgan76, amrron, rightful, warfighter, sppt, observer, magazine, culper, institute, drives, fight, western, rifle, shooters, essentials, bruce, schneier, psyops, 9jul14, psyop, 27jun14, wrong, scouts, disappear, sigint, sparks31, covert, rural, mission, clearing, confusion, crowdsourcing, osint, community, jungle, telegraph, featured, posts, gpg4win, latest, beta, looking, glass, current, versions, cancel, haven, seen, before, might, guy, technically, historically, interesting, http, users, telenet, rijmenants, onetimepad, htm, banner, line, soon, appreciate, glad, improve, especially, tagline, looks, edited, illustrate, perfectly, valid, disregard, objection, prior, again, providing, insights, behind, seemingly, indeed, exchange, pointed, service, providers, implementing, ephemeral, perfect, secrecy, significantly, www, org, web, taken, struggle, balance, decided, less, easily, increase, posture, rather, deep, would, choosing, progress, refine, needed, hopefully, stray, path, trying2be, commenting, course, correct, substitution, fixed, taking, little, keep, resembling, orient, crypto, basic, understanding, employ, analogy, relate, illustrates, concept, token, algorithms, schemes, practical, systems, communicating, further, long, discarded, any, given, scheme, greater, human, readable, term, improperly, series, applied, typically, each, corresponding, sequence, merely, running, against, provided, truly, destroyed, once, hence, principle, unbreakable, however, managing, difficult, cover, its, nature, precludes, memorization, shorter, easier, string, robust, proving, distinctly, trivial, complexity, itself, sufficent, vulnerable, cryptanalysis, rsa, diffie, helman, elgamal, ecc, 3des, aes, rc4, rc5, blowfish, 128, 2048, expressed, better, sizes, 256, range, 512, 4096, mathematical, particular, method, stronger, strength, governed, things, final, details, entire, along, infrastructure, operate, responsible, ensuring, vouching, contain, plus, electronically, wax, seal, indicating, asked, clearly, bad, really, belong, russian, hackers, act, trusted, intermediary, serve, companies, documents, thing, connect, rogue, without, into, lot, detail, provide, proper, whom, comodo, godaddy, thawte, verisign, factor, advantage, distribute, own, generate, trade, begin, communication, basis, fact, give, allow, places, servers, functions, cannot, safe, fast, strong, big, weakness, become, problem, never, met, universally, above, sometimes, refer, old, school, minute, basically, apply, scrambled, check, diagram, below, applying, creating, cipher, combine, through, two, minimum, requires, nothing, magical, soldiers, difference, digital, world, leverage, complex, mathematics, ciphers, terms, why, driven, chats, critical, fundamentals, don, worry, first, mostly, lingo, talk, browsers, discussion, later, faqs, desk, suggestion, box, information, ops, skip, menu, 177, hits, lookingglass, fame,
Text of the page (random words):
encryption 101 there isn t a darknet dark enough to black out stupid rules contact info there isn t a darknet dark enough to black out stupid lastbox of lookingglass fame 73 177 hits menu skip to content home start here what s information ops tenets ff io do today suggestion box help desk faqs email pgp key coursework level 1 io o l1 0 read tenets start o l1 1 anonymous emails o l1 2 anon search engines o p1 3 internet 101 o l1 4 privacy anonymity concepts o l1 5 end point security o l1 5 1 secure pc o l1 5 2 spoofing your mac x l1 6 secure organize data o l1 6 encryption 101 o l1 7 secure browsing o l1 7 1 secure browser part 1 o l1 7 2 secure browsing part 2 risks level 2 io x l2 1 tor x l2 2 android tor orb x l2 4 encrypting email pgp gpg x l2 5 tails linux distros x p2 x freefor haystack x p2 x mask unmask level 3 io x l3 1 vpns x l3 1 cascading vpn s x l3 2 tor over vpn level 4 io x l4 1 virtual machines vm s x l4 2 whonix level 5 io x l5 1 tor hidden sites onion x l5 2 darknet i2p freenet x l5 3 operation turnkey x l5 4 hamops how they hunt o lizard farmer s how they hunt o metadata to find paul revere o parallel construction case studies o silk road tor self study o s1 1 tor s jacob appelbaum o s1 2 eff surveillance self defense tool kit o behavior tools o security tools o test tools o ip test sites o dns leak sites o https ssl o system tests o visualizers lesson tracker home encryption 101 encryption 101 4 comments lesson id 0019 don t worry this first encryption lesson will be short and easy we re mostly just going to learn the lingo today we need this to talk about the next lesson secure browsers and there will be a deeper encryption discussion in a later lesson why is this important remember from the privacy and anonymity lesson that we need both privacy and anonymity privacy is driven by encryption you will learn to secure your browser sessions encrypt your email and ensure your chats are secure it is critical you understand the fundamentals key terms symmetric asymmetric certificate authorities pki remember there is nothing magical about the concepts of encryption it happens all the time when soldiers use one time pads the only difference is that in the digital world we can leverage complex mathematics ciphers to create the encrypted text we will discuss two types of encryption symmetric and asymmetric a minimum encryption system requires plain text a key and a process symmetric encryption check out the diagram below plain text is what you start with your message encryption is the process of applying a scrambling process a math formula to the plain text and creating encrypted text also called cipher text the key is a code you have that you combine with the message as you send it through the encryption process think old school for a minute your one time pad is basically a key you apply the otp to your message to create a scrambled or encrypted message someone on the other end with the same otp can use their key to decrypt your message what you see above is called symmetric encryption the key to encrypt and decrypt is the same or symmetric it is what happens with one time pads and it is how you secure your browser sessions we sometimes refer to this as a shared secret symmetric encryption is fast and strong the big weakness is that you both need to have the same key that can become a huge problem if you are trying to communicate with someone you ve never met there is no universally easy way to ensure you both have the right key asymmetric encryption in asymmetric encryption there are 2 different keys a public key and a private key they are one way functions the public key is used to encrypt but cannot be used to decrypt the private key is used to decrypt and must be kept safe since the public key can t be used to decrypt your message only encrypt it doesn t need to be kept secret in fact you want to give your public key to anyone you need to communicate with it will allow them to encrypt a message that only you can decrypt with your private key people and organizations publish their public keys in many places like public key servers and certificate authorities you can on your own generate public and private keys if you know someone you can trade public keys and begin encrypted communication this is the basis for pgp or gpg encrypted email asymmetric encryption is slower than symmetric encryption but has the huge advantage of being able to distribute public one way encryption keys with no risk of someone else being able to decrypt your message unless they have your private key certificate authorities the trust factor when you want to connect to your bank how do you get their key or how do you know that a rogue group isn t impersonating your bank without going into a lot of detail right now there are organizations we trust to provide us with the proper public keys for parties with whom we want to communicate these organizations are the certificate authorities or cas some examples are comodo godaddy thawte and verisign cas act as a trusted intermediary and serve up the public keys of other companies to us as signed documents these are called certificates when we go to the next lesson on https these are called ssl certificates but they are the same thing they contain the public key we need plus some other info and are electronically signed by the ca signed with the ca s key think wax seal indicating the key we asked for is legitimate clearly it is bad if we encrypt our private data with a key that doesn t really belong to our bank but to russian hackers impersonating a bank certificate authorities must operate in such a way that we can trust them they are responsible for ensuring the public keys they send to us are legitimate keys for other organizations so they are effectively vouching for the keys we need this entire system of asymmetric encryption public and private keys along with cas is called the public key infrastructure or pki final details the strength of encryption is governed by 2 things the length of the key bigger key is stronger encryption the mathematical algorithm used for a particular encryption method key lengths are expressed in bits bigger is better symmetric encryption has key sizes of 40 256 bits asymmetric key lengths range from 512 4096 bits ideally we want symmetric keys of at least 128 bits and asymmetric keys of at least 2048 bits symmetric algorithm examples are 3des aes idea rc4 rc5 and blowfish asymmetric algorithm examples are rsa diffie helman elgamal ecc that s it for now you should understand encryption decryption symmetric encryption shared keys just like one time pads and asymmetric encryption public private keys ca s and pki this is lesson id 0019 4 comments on encryption 101 trying2b amused says 08 30 2014 at 20 06 you are using the term one time pad improperly here a one time pad is a series of random characters the same length as the plaintext to be encrypted and is applied to the plaintext using a very simple math formula typically xor each character of the plain text with the corresponding character in sequence of the one time pad decryption if xor character by character was used is merely doing the same running the encrypted text against the one time pad this is provided that the one time pad is truly random and kept secure ideally it is destroyed after being used only once hence one time in principle unbreakable however managing the one time pad material is difficult since there must be enough of it to cover the length of all the plaintext to be encrypted and its random nature precludes memorization a symmetric code key is much shorter than the plaintext and can be something much easier to remember than a string of random characters but unless the scrambling process is very robust proving this is distinctly non trivial complexity by itself is not sufficent the encrypted text is vulnerable to cryptanalysis also while asymmetric encryption schemes are slower than symmetric in practical public private key systems the asymmetric encryption is used only to transfer what is called a session key between the communicating parties this is a symmetric code key which is used for further data transfer with a symmetric code but since the session key can be and is long random and discarded after being used for one session the security of any given symmetric code scheme is much greater than if human readable symmetric code keys are used reply ffio says 08 31 2014 at 00 20 trying2be amused thanks for reading and commenting of course you are correct on otp it is a one for one substitution while symmetric encryption is a fixed key at the risk of taking a little liberty here we re trying to keep the concepts simple short and resembling something people already know we want to orient it such that non it types and non crypto types can get enough of a basic understanding to effectively employ privacy and anonymity as an analogy to otp both use a shared secret and is something that many can relate to it illustrates the concept that there is clear text a shared secret and a process the process is different for otp but by the same token it is different between different encryption algorithms as well your point is well taken and we struggle with this balance we decided to design lessons with less technical content so that folks can easily increase their security posture rather than deep technical content that would leave many folks choosing to not follow the lessons as the lessons progress we ll clear up and refine the concepts that are needed and hopefully not stray to far from the path as we publish lessons you ll see in the next lesson on https we do indeed discuss the pki exchange of symmetric session keys as you pointed out now we just need more service providers to start implementing ephemeral keys perfect forward secrecy for significantly more secure sessions https www eff org encrypt the web report thanks again for reading and providing deeper technical insights on what is behind a seemingly simple idea ffio reply trying2b amused says 09 01 2014 at 22 41 it looks like you ve edited the material to just use one time pad as a way to illustrate the idea of a shared secret which is perfectly valid so anyone else reading this should disregard the objection in my prior comment i appreciate what you re doing here and i m glad i was able to help improve it i also especially like your tagline sound procedures with adequate technology will trump careless use of even the best technology every time and this is by far the most important lesson to be learned in infosec ffio says 09 02 2014 at 07 01 this will go up as a banner line soon sound procedures with adequate technology will trump careless use of even the best technology every time and this is by far the most important lesson to be learned in infosec if you haven t seen this before you might find this guy s site technically and historically interesting http users telenet be d rijmenants en onetimepad htm leave a comment cancel reply δ current versions looking glass secure email version latest beta tor browser 04 09 15 version 4 0 8 tails 03 31 15 version 1 3 2 gpg4win 03 18 15 version 2 2 4 featured io posts from dialtone community jungle telegraph part 1 from guerrillamerica crowdsourcing intel osint project clearing up opsec confusion start your intel mission today from ivy mike cafe covert rural surveillance from sparks31 got sigint do it wrong scouts disappear from mosby patriot psyop primer pt i 27jun14 patriot psyops primer pt ii 9jul14 from bruce schneier metadata surveillance essentials got hq western rifle shooters intel drives the fight got some culper institute forward observer magazine guerrillamerica max velocity warfighter intel sppt rightful liberty report got comms amrron patriot radio danmorgan76 dialtone comms tradecraft radiomaster reports sparks 31 got medics hogwart s grid down medicine specops medic got spartan combat studies group defensive training group ga force on force john mosby mason dixon tactical max velocity sierra12 defensive studies group got freefor south carolina free alamance county rangers charles carroll society free nc ivy mike cafe ga militia lastbox s freefor darknet tor only nc renegade ohio valley minutemen pennsylvania light foot sipsey street irregulars steel i beam the frontiersmen the lonely libertarian wirecutter got tech come and make it green bay professional packet radio gbppr main page gbppr mil espionage homebrew gbppr project page open warfare the silicon graybeard got red team global guerrillas psywar red team us crow got hack b3rn3d staying in the darkness the grugq hacker opsec krypt3ia we suggest you do not follow us with your real email address do lesson 2 get a new anon email then follow us email address secure your info join us join 48 other subscribers archives may 2015 4 april 2015 4 march 2015 5 february 2015 2 october 2014 4 september 2014 8 august 2014 8 contact info rules coursework coursework level 1 io o l1 0 read tenets start o l1 1 anonymous emails o l1 2 anon search engines o p1 3 internet 101 o l1 4 privacy anonymity concepts o l1 5 end point security o l1 5 1 secure pc o l1 5 2 spoofing your mac x l1 6 secure organize data o l1 6 encryption 101 o l1 7 secure browsing o l1 7 1 secure browser part 1 o l1 7 2 secure browsing part 2 risks level 2 io x l2 1 tor x l2 2 android tor orb x l2 4 encrypting email pgp gpg x l2 5 tails linux distros x p2 x freefor haystack x p2 x mask unmask level 3 io x l3 1 vpns x l3 1 cascading vpn s x l3 2 tor over vpn level 4 io x l4 1 virtual machines vm s x l4 2 whonix level 5 io x l5 1 tor hidden sites onion x l5 2 darknet i2p freenet x l5 3 operation turnkey x l5 4 hamops how they hunt o lizard farmer s how they hunt o metadata to find paul revere o parallel construction case studies o silk road tor self study o s1 1 tor s jacob appelbaum o s1 2 eff surveillance self defense tool kit o behavior tools o security tools o test tools o ip test sites o dns leak sites o https ssl o system tests o visualizers lesson tracker 2026 there isn t a darknet dark enough to black out stupid create a free website or blog at wordpress com subscribe subscribed there isn t a darknet dark enough to black out stupid join 48 other subscribers sign me up already have a wordpress com account log in now privacy there isn t a darknet dark enough to black out stupid subscribe subscribed sign up log in copy shortlink report this content view post in reader manage subscriptions collapse this bar loading comments write a comment email required name required website design a site like this with wordpress com get started
|