SgtSpike (OP)
Legendary
Offline
Activity: 1400
Merit: 1005
|
|
March 26, 2013, 03:48:50 PM |
|
If I was to send someone some really sensitive information that I wanted to be 100% sure no one else could see, what would be the best way(s) of doing so? Say, for example, it was a Bitcoin private key.
|
|
|
|
CIYAM
Legendary
Offline
Activity: 1890
Merit: 1086
Ian Knowles - CIYAM Lead Developer
|
|
March 26, 2013, 03:49:53 PM |
|
If they are at all computer literate GPG would probably be your best option.
|
|
|
|
jackjack
Legendary
Offline
Activity: 1176
Merit: 1280
May Bitcoin be touched by his Noodly Appendage
|
|
March 26, 2013, 03:50:17 PM |
|
Crypting it with GPG?
|
Own address: 19QkqAza7BHFTuoz9N8UQkryP4E9jHo4N3 - Pywallet support: 1AQDfx22pKGgXnUZFL1e4UKos3QqvRzNh5 - Bitcointalk++ script support: 1Pxeccscj1ygseTdSV1qUqQCanp2B2NMM2 Pywallet: instructions. Encrypted wallet support, export/import keys/addresses, backup wallets, export/import CSV data from/into wallet, merge wallets, delete/import addresses and transactions, recover altcoins sent to bitcoin addresses, sign/verify messages and files with Bitcoin addresses, recover deleted wallets, etc.
|
|
|
BIGMERVE
|
|
March 26, 2013, 03:51:12 PM |
|
Just send them a letter with a seal.
|
|
|
|
theymos
Administrator
Legendary
Offline
Activity: 5376
Merit: 13357
|
|
March 26, 2013, 03:51:19 PM |
|
Give it to them in person.
|
1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
|
|
|
SgtSpike (OP)
Legendary
Offline
Activity: 1400
Merit: 1005
|
|
March 26, 2013, 03:53:37 PM |
|
GPG, a letter with a seal... sounds good. Give it to them in person.
Well, yes, but assume they aren't near me.
|
|
|
|
CIYAM
Legendary
Offline
Activity: 1890
Merit: 1086
Ian Knowles - CIYAM Lead Developer
|
|
March 26, 2013, 03:57:22 PM |
|
Also depending upon level of paranoia you could divide the private key into parts and say:
Part 1) Email Part 2) SMS/Phone Part 3) Snail mail
|
|
|
|
SgtSpike (OP)
Legendary
Offline
Activity: 1400
Merit: 1005
|
|
March 26, 2013, 04:01:23 PM |
|
Good point CIYAM!
What about BitMessage? It should be secure for sending, right? Or... an encrypted .rar, provided the passkey is sent separately?
|
|
|
|
MysteryMiner
Legendary
Offline
Activity: 1512
Merit: 1049
Death to enemies!
|
|
March 26, 2013, 05:14:55 PM |
|
PGP encrypted mail OTR encrypted IM chat TorChat
The list can go on.
|
bc1q59y5jp2rrwgxuekc8kjk6s8k2es73uawprre4j
|
|
|
SgtSpike (OP)
Legendary
Offline
Activity: 1400
Merit: 1005
|
|
March 26, 2013, 05:17:44 PM |
|
PGP encrypted mail OTR encrypted IM chat TorChat
The list can go on.
Let's keep it to options where we don't have to be online at the same time... but thanks for the suggestions!
|
|
|
|
bbit
Legendary
Offline
Activity: 1330
Merit: 1000
Bitcoin
|
|
March 26, 2013, 05:38:22 PM |
|
Give it to them in person.
^^this^^
|
|
|
|
SgtSpike (OP)
Legendary
Offline
Activity: 1400
Merit: 1005
|
|
March 26, 2013, 05:52:55 PM |
|
Give it to them in person.
^^this^^ Assume they live across the globe and it is not possible.
|
|
|
|
Lethn
Legendary
Offline
Activity: 1540
Merit: 1000
|
|
March 26, 2013, 05:55:00 PM |
|
Just send them a letter with a seal.
You should also make sure they burn it after they read it otherwise someone might pick it up in the bin.
|
|
|
|
SgtSpike (OP)
Legendary
Offline
Activity: 1400
Merit: 1005
|
|
March 26, 2013, 09:29:46 PM |
|
Screw GPG, it doesn't allow long enough keys for paranoid people. Have your friend generate a 16,384 bit RSA keypair with openssl, encrypt it with the public key, and send it off.
I like it.
|
|
|
|
kokjo
Legendary
Offline
Activity: 1050
Merit: 1000
You are WRONG!
|
|
March 26, 2013, 09:33:15 PM |
|
This generating private/public keypairs is useless, IF YOU ARE NOT GIVING IT IN PERSON. http://en.wikipedia.org/wiki/Man-in-the-middle_attack
|
"The whole problem with the world is that fools and fanatics are always so certain of themselves and wiser people so full of doubts." -Bertrand Russell
|
|
|
Raoul Duke
aka psy
Legendary
Offline
Activity: 1358
Merit: 1002
|
|
March 26, 2013, 09:35:07 PM |
|
|
|
|
|
molecular
Donator
Legendary
Offline
Activity: 2772
Merit: 1019
|
|
March 26, 2013, 09:58:46 PM |
|
if you're familiar with the voice of the person, I think it's pretty safe to transmit the public key via phone after having a conversation about the weather.
|
PGP key molecular F9B70769 fingerprint 9CDD C0D3 20F8 279F 6BE0 3F39 FC49 2362 F9B7 0769
|
|
|
Rothgar
|
|
March 26, 2013, 10:02:27 PM |
|
Send the person a picture of a cat to use as a one time pad. Mail them a CD with the picture of the cat that you take yourself. Email the OTP encrypted file. I'm being a little silly this is probably overkill.
|
|
|
|
MysteryMiner
Legendary
Offline
Activity: 1512
Merit: 1049
Death to enemies!
|
|
March 26, 2013, 10:08:20 PM |
|
TorChat is out-of-box solution that cannot be compromised unless Tor asymmetric encryption is totally broken or one of boxes are compromised.
|
bc1q59y5jp2rrwgxuekc8kjk6s8k2es73uawprre4j
|
|
|
SgtSpike (OP)
Legendary
Offline
Activity: 1400
Merit: 1005
|
|
March 26, 2013, 10:23:54 PM |
|
Hmmm, good point. Would there be a way for someone to MITM communications in such a way that the receiver of the information still gets it and doesn't know that it is compromised? Obviously, the key is getting the correct Bitmessage address for a particular person, but I've heard that Bitmessage addresses can be generated from Bitcoin addresses? That might be one way to prove ownership of a particular address. if you're familiar with the voice of the person, I think it's pretty safe to transmit the public key via phone after having a conversation about the weather. Good point as well... Send the person a picture of a cat to use as a one time pad. Mail them a CD with the picture of the cat that you take yourself. Email the OTP encrypted file. I'm being a little silly this is probably overkill. LOL. What about just mailing a password (plaintext), and then emailing a .rar encrypted file? I don't know what OTP is or how a cat picture could be used as a pad, and yes, that might be overkill for my purposes anyway.
|
|
|
|
|