An overview and Why
In this world, where it become easy to communicate with anyone, anywhere. This convience, easinesss comes with a cost. (a non finicail cost), it's Privacy, and for some of us, like journalits, or actvisits, it could mean their life or survival[1].
The Faraj Initiative is an initiative to provide resources and guidance for secure communication.
How can I just send a messge securely, a very simple straighforward quesition. This initiatve is just about answering that.
Convience is enemey of privacy
On the other hand, the easier it is to do, the more venruablae it is. Thus might not be releavnt for most readers, however it important to have the "How?", avaiable for the general public.
For cryptographic to be inseucre (as an algrothim), then all of mathmatician have failed us as as general public.
People are the weakest link in Information Security[2]
How
Playtype:
- state on state
- state sponsered companies on people
- people on people
Meta Note
Actors
Entity types: e.g. aramature, state sposnered, companies..etc, companies dedicated for that
Motive: Money, influence, power, espoige, public order, allgedgy national secutiry
How/Method:
- Utizling miss usage, user unablity
- In depth research utizling unknown venrablity (case of corps) OR back door
Structure
- Short intro about limitation/an overview (the What)
- The goal (The why)
- Explain the actors, thier motives, thier target
- All the stack holders
- Thier Methods of which (some are legal or illegal)
- Hgih usage base
- Follow digital print and other data left when using servoces
- Cooperation between setate and other coprs (e.g state with ISP)
- Corps are obligated to provide access when asked (they have to respect local reulgation)
- Abuse vulnerabilities (zero day )
- Their Motive (depends on the actor, companies: money, state: control or shape public opinion )
- Why I should trust this
- Talk about the weakest element of the chain (social/human aspects)
- As secure as the party contacting to (Faraj 2 suppose to make this agnostic)
Why I should trust this
- You don't have to, this intended to be as a resource for the public, if you find a mistake, uncorrect. Please submit an issue or just (you will be credit if you want to)
- I try to list resources of which this is based on.
Should we trust online resources of goverments
There has been incidents, of which governments tries to implement a backdoor, this is not longer a secret.
Last point:
Please remember softwares or application might have malfucntion, insecure, but algorithm don't. Cryptography is based on principles of prime numbers, which haven't been broken yet. If it was, then we as public not suppose to trust mahmatician.
For crytographic to be inseucre (as an algrothim or math concept), then all of mathmatician have failed us as general public.
If you still don't trust it (as math concept), then proof it's wrong may be?[3]
Lastly, again even if math is not broken, software might be and usually is, that's where physics comes in. When transmitting data
A quote by Bruce Schneier ↩︎
For example can you need to proof that is possible to have an algrothim that would quickly find factors of a very large prime number. other resources on ChatGPT chat ↩︎