Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Air gaped mode? #194

Open
gmaxwell opened this issue Jun 22, 2015 · 1 comment
Open

Air gaped mode? #194

gmaxwell opened this issue Jun 22, 2015 · 1 comment

Comments

@gmaxwell
Copy link

I don't know about other folks, but I generally keep my discreet relationships with the Director of the CIA confined to an air-gapped host.

For Pond the only way to do this currently is to put ascii armored PGP inside pond messages. This has a couple downsides: it's a pain to use (e.g. requires unusual procedures from your pond counter parties), it roughly halves the channel capacity, and it blows forward secrecy if you leave the storage you used to shuttle information across the airgap where it can be discovered; if you're at all careless with the pgp it can also break deniability.

Of course, one can compromise the airgap and make only the tor connection to the pond server work; but it's somewhat hard to be sure you got this right.

It would be nice if I could run a headless pond polling daemon that polled for data and dropped it into a directory that I could shuttle across the airgap UUCP style-- but which didn't have access to the ephemeral keys needed to decrypt messages. This might also improve traffic analysis immunity, since the headless polling might have a reduced uptime signature than a GUI-enabled client with an enduser sitting at it.

@burdges
Copy link
Contributor

burdges commented Jun 22, 2015

Axolotl needs two-way communication, so you'd need to send messages from the air gapped machine too, and transfer them over.. or finagle some mechanism for transfering 32 byte keys.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants