<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cybersecurity &#8211; John Large &#8211; Technology, Hardware,Web Development, Digital Privacy &amp; Ethics</title>
	<atom:link href="https://www.johnlarge.co.uk/tag/cybersecurity/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.johnlarge.co.uk</link>
	<description>I&#039;m a Computer science academic, working towards a PhD. I&#039;m researching digital privacy &#38; ethics. I also run a busy e-commerce business.</description>
	<lastBuildDate>Fri, 04 Sep 2026 08:44:46 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
<site xmlns="com-wordpress:feed-additions:1">6164056</site>	<item>
		<title>End to End encryption &#8211; The reasons we can&#8217;t just outlaw encryption for all.</title>
		<link>https://www.johnlarge.co.uk/end-end-encryption-reasons-cant-just-outlaw-encryption/</link>
		
		<dc:creator><![CDATA[John Large]]></dc:creator>
		<pubDate>Mon, 27 Mar 2017 17:59:24 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Technical]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[encrypt]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[end to end]]></category>
		<category><![CDATA[imessage]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[whatsapp]]></category>
		<guid isPermaLink="false">https://www.johnlarge.co.uk/?p=1702</guid>

					<description><![CDATA[Over the past few days in the UK there has been a renewed sense of urgency within government to address &#38; ban/circumvent end to end encryption in communications apps. On Wednesday of last week in the UK an attack was launched on Westminster. During the subsequent investigation it has come to light that the attacker [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Over the past few days in the UK there has been a renewed sense of urgency within government to address &amp; ban/circumvent end to end encryption in communications apps. On Wednesday of last week in the UK an attack was launched on Westminster. During the subsequent investigation it has come to light that the attacker used the WhatsApp messaging app to message a friend or accomplice minutes before the attack. The government&#8217;s response to this, perhaps with the best of intentions, is to outlaw or circumvent encryption for the purposes of law enforcement. The reasoning, to stop criminals using platforms to co-ordinate is commendable, however it is totally unworkable. encryption&#8217;s raison d&#8217;etre is to make interception by a third-party as difficult as possible, if not impossible.</p>
<p>It would be wonderful if the government could figure out a way to allow complete privacy between&nbsp;citizens for all of the personal communications, whilst being able to listen in on the bad guys, but the two aims are mutually exclusive. We have to pick one side or the other, either all of our communications are un-encrypted &amp; able to be read by anyone, or we admit that for the good of the privacy of billions&nbsp;of people, encryption is a must. It&#8217;s ethically tough to defend encryption amidst a criminal investigation, especially one as sensitive as an act of terror, however the privacy of millions of UK citizens cannot be surrendered for the sake of a few fringe elements of our society.</p>
<p>If encryption was to be removed from the likes of Whatsapp, iMessage, Facetime and a whole host of messaging apps, people would lose trust in the platforms. Imagine, for example having a video message with your children &amp; not knowing if a third-party was watching your live video stream, making recordings or notes &amp; redistributing them online. Imagine the same party intercepts something intimate, a private exchange&nbsp;between lovers or a chat of confidential nature such as discussing finances. If this video was intercepted it could be used to extort those involved with the threat of publishing said private material in a public place online.</p>
<p>As the internet of things becomes a major industry, consider&nbsp;the implications of an&nbsp;IoT without encryption. Your neighbour accessing your thermostat and turning your heating on while at work to cost you money. A sexual predator using an internet or wi-fi connected video baby monitor to watch &amp; talk to your child in their bedroom. A stalker connecting remotely to your home CCTV system. The list of problems &amp; threats is huge &amp; encryption means that such data can pass over the internet from your home to your device, without any man in the middle or third parties accessing the feeds. This kind of stuff needs discussing to balance the governments insistence&nbsp;on having access to everything.</p>
<p>Imagine you send a photo of your children to a family member, and those photos are intercepted &amp; distributed online among child abusers &#8211; the very thought would&nbsp;send chills down your spine &amp; invoke outrage. We trust that information between each other is secure &amp; that no third parties can listen in, including governments. There are thousands of strong arguments&nbsp;in favour of strong encryption &amp; very few strong arguments against.</p>
<p>Another method of interception being discussed freely by MP&#8217;s such as Amber Rudd is that of requiring manufacturers of hardware &amp; applications&nbsp;to include back doors into their encrypted apps. This would hopefully give governments free access to accounts while limiting the exposure of &nbsp;personal information to eavesdroppers and criminals. However a back door into an encrypted system essentially nullifies encryption. If your communications are safe until such a time when someone comes along and reads them through a back door, they aren&#8217;t safe at all.&nbsp;Developers spend countless hours securing code &amp; systems against such vulnerabilities, to write one in by default &amp; just bide your time until a criminal cracker (note I&#8217;m not using the often incorrect term used by the media of hacker, completely different beast) or questionable regime expose the weakness and they too start reading messages would be madness.</p>
<p>Now, picture the scene. The government of the UK has legislated to require a back door into all hardware &amp; all software which employs encryption. They believe this gives them an edge over criminals &amp; allows intelligence services to track certain individuals. What they haven&#8217;t realised&nbsp;is that a third-party government has employed a group of crackers to find &amp; breach these back doors. For months, the emails, text messages sent via iMessage or Whatsapp, the video conferences over Cisco or Facetime, the encrypted VPN&#8217;s allowing them to connect to their place of work in Whitehall on the go (I&#8217;m assuming they have some sort of encrypted tunnel, I could be wrong) have all been cracked &amp; the contents of all of those communications have been captured. The foreign governments now have intimate knowledge of the inner workings of our democracy. We are exposed &amp; vulnerable &amp; the misinformed MP&#8217;s and public via tabloid witch hunts all supported the legislation of back doors. There would be a scramble to find out what had been breached, information would be used against the UK &amp; distributed amongst criminals &amp; foreign governments. We would be facing a leak of monumental proportions &amp; all because we enforced the introduction of a weak spot via a back door. A way around that would be a two tier system where government employees are allowed encryption without back doors while the general public aren&#8217;t, but this would be a serious ethical issue in any democracy. It would also leave the public exposed.</p>
<p>I admit, that is an extreme example, but encryption is an all or nothing kind of thing. You wouldn&#8217;t, for instance, be happy to give a copy of your house keys to the government so they could pop in whenever they liked to check everything was in order. You wouldn&#8217;t allow them to just have a quick read of all of your post before it came to you, just to make sure you where a good citizen. How about someone in a trench coat sitting with you over a romantic dinner to make sure conversation was all to their liking? That would be preposterous, but when it comes to tech, ministers lag behind in a big way.</p>
<p>Let&#8217;s use an analogy for the back door in encryption software. Every house in Britain, for securities sake, has to be fitted with a secret door around the back of the house. Only the government would know exactly where it was, just in case they wanted to pop in now and then, but it would be common knowledge that everyone had a secret back door (no puns or innuendo please) which was unlocked and ready to use, if you could just find it. Can you imagine such a use case for that? But the same ministers push for either an end to encrypted communications or at least a way in. My advice to them would be to consult someone with a grasp of technology before coming out on live TV and making statements which are either impossible or unworkable.</p>
<p>MP&#8217;s are always banging on (I&#8217;m a Northerner, sometimes I like to write with an accent) about making Britain the tech capital of the world. With innovation it could be the next huge export. But with such a simplistic grasp of the basics of tech, it&#8217;s hard to imagine how these same people can legislate towards this mecca of a country for innovation. If encryption is outlawed in the UK, our apps will be useless to a worldwide market, the products we produce will be insecure &amp; undesirable. Our ability to harness the power of e-commerce &amp; online finance will be impossible without stronger &amp; stronger encryption. Any watering down of encryption &amp; vilification by MP&#8217;s and the press will only make such innovation harder if not impossible.</p>
<p>This website uses encryption via a HTTPS certificate. That means that anyone watching, other than my server &amp; your browser, will only see the metadata of you viewing my website. They will see the time you connected and the top level domain, but not the individual pages you load. Chances are, you have checked your online banking today via an app or your banks website. Good news, those connections are encrypted too. You&#8217;ve probably signed into websites today, over encrypted connections and safe in the knowledge&nbsp;that your passwords with that website are hashed &amp; encrypted, so any data dumps or site hacks won&#8217;t reveal your password.</p>
<p>Encryption is a fundamental of privacy &amp; guaranteed privacy is the only way that the internet can work for private or transactional data. If you thought your texts where being read, you would seldom say anything which needed to remain private. If logging into your bank meant others could intercept your traffic and access your bank account online, you would never use internet banking. This is where the rhetoric of MP&#8217;s without a basic working knowledge collides with the realities of passing data over public networks. If you wanted to tell someone something in secret or confidence, face to face, you would generally meet somewhere with a closing door &amp; without others present. The only way to simulate this kind of data transfer online (over a public network like the internet) is to encrypt the traffic, otherwise it&#8217;s the equivalent of shouting your bank card details and billing address across a crowded pub. You wouldn&#8217;t do it for fear of someone making a note.</p>
<p>The final issue we need to deal with is retention of data. Since the introduction of the IP Bill a requirement is coming into force that ISP&#8217;s and providers need to retain data on their users. Logs &amp; metadata. Without encryption, this could be expanded to keeping a copy of all files you upload to the cloud, a recording of all voice and video chats, retention of all personal instant message chats and countless other data sets. As much as companies try to safeguard this data, eventually they will face a data breach. This could be an external hack or it could be a breach from within such as an employee breaching their privileges and accessing or leaking your data. This kind of breach could expose so many data points &amp; so much personal information about you that your privacy could be breached indefinitely. If someone gains access to your most intimate information, you&nbsp;could potentially face a lifetime of identity theft and frauds in your name. I would hope that any data retained would be encrypted &amp; protected with as much security as possible, but the best defence would be to not require any logging of data. Once it has been deleted or the transaction has taken place, the data expires and its erased. This does prove to be an obstacle for law enforcement, but the security of millions of citizens intimate lives needs to be considered when trying to stop a handful of criminals.</p>
<p>The conundrum faced by politicians is not an easy one, but they need to seek advice from those with the technical skills to educate them. A reactionary &#8220;we must tackle&#8221; or &#8220;we must ban encryption&#8221; isn&#8217;t a reasoned argument. Criminals use all sorts of tools that regular citizens use. They drive cars, they cook with knives &#8211; this means they have the tools required to harm fellow humans. The solution isn&#8217;t to ban everything, but to develop tools that can be used to detect. Behavioural patterns, anonymous tip offs, education of the general public &#8211; not the removal of all citizens rights to a private life.</p>
<p>Encryption will be the scape goat for a lot of government &amp; tabloid problems, but ultimately without it, we revert to the pre-internet days of filling in forms and transacting face to face. Without the ability to secure over a public network, the internet is nothing more than a public library of information. I&#8217;m an academic. I research internet security for my studies &amp; also out of personal interest (I know, my hobbies sound really boring). The discussion around privacy in the UK needs to change. It&#8217;s not about having something to hide, it&#8217;s the freedom to express yourself and communicate without the fear of someone else reading or hearing your conversations. I believe everyone would see that as a basic right &amp; one that needs protecting.</p>
<p>Let me know your views in the comments. I would&nbsp;love to hear from you. Also, send me any corrections, I&#8217;m sure there will be a few. I&#8217;ve written this all in one sitting to address concerns brought up by people asking me questions today, following the press coverage, so excuse any errors.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1702</post-id>	</item>
		<item>
		<title>PGP encrypted emails on Mac OS X/Sierra using GPGtools GPGsuite</title>
		<link>https://www.johnlarge.co.uk/pgp-encrypted-emails-mac-os-xsierra-using-gpgtools-gpgsuite/</link>
		
		<dc:creator><![CDATA[John Large]]></dc:creator>
		<pubDate>Mon, 20 Mar 2017 18:24:13 +0000</pubDate>
				<category><![CDATA[Apple Hardware]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Technical]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[encrypt]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[gpg]]></category>
		<category><![CDATA[gpgtools]]></category>
		<category><![CDATA[opengpg]]></category>
		<category><![CDATA[openpgp]]></category>
		<category><![CDATA[pgp]]></category>
		<category><![CDATA[secuirty]]></category>
		<guid isPermaLink="false">https://www.johnlarge.co.uk/?p=1690</guid>

					<description><![CDATA[As part of my cybersecurity posts I&#8217;ve decided to write briefly about PGP (Pretty Good Privacy) encryption of email. We will use GPG which stands for GNU Privacy Guard and is a compatible free software equivalent of Symantec&#8217;s proprietary encryption algorithm. Both PGP and GPG are interchangeable so you can use either protocol. These keys [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>As part of my cybersecurity posts I&#8217;ve decided to write briefly about PGP (Pretty Good Privacy) encryption of email. We will use GPG which stands for GNU Privacy Guard and is a compatible free software equivalent of Symantec&#8217;s proprietary encryption algorithm. Both PGP and GPG are interchangeable so you can use either protocol. These keys use a high level of encryption. I Use RSA 4096 for my keys which is possibly a little overkill, but I like to future proof when learning.</p>
<p>GPG is important for emails as it means that an email remains encrypted between the sender &amp; the receiver. It works on the principle of key pairs. Each user generates a pair of keys, one private key remains secret and on the user&#8217;s computer, the other, known as a public key is free to distribute on the internet and allows you to pass it on to those you wish to communicate with.</p>
<p>It is important that your private (secret) key always remains private &amp; you never share it with anyone. The keys are paired so that both are required to encrypt &amp; decrypt emails. I won&#8217;t go into the technicals of it, if you are interested there are a lot of free resources which will guide you through the technology.</p>
<p>Encryption also requires a password to be set when creating your key pair. This password allows you to unlock your keys &amp; use them to encrypt your email. Both sender &amp; receiver need to set up a keypair &amp; share their public keys with each other. This allows encrypted communication between both parties.</p>
<p>On OSX/ OS Sierra you can use the free &amp; open source <a href="https://gpgtools.org/" target="_blank" rel="nofollow">GPG Suite</a> to install the tools required to start encrypting email. The suite includes the GPG keychain which allows you to create your key-pair for your email address, and it also allows you to store the public keys of your recipients &amp; to upload your public keys to public key servers. It allows you to manage&nbsp;&amp; store your keys.</p>
<p>Also in GPG suite you have GPG mail which integrates with the native mac mail client. Much of the encryption process is automated once you setup your keypair, including downloading the keys of recipients you address your emails to. You can also sign your emails with GPG Mail which confirms your email as authentic to the recipient.</p>
<p>First, <a href="https://gpgtools.org/" target="_blank" rel="nofollow">install GPGsuite using the .DMG file available on their website</a>. If you are using Sierra or require cutting edge enhancements, opt for the beta package.</p>
<p>Once installed you will have an extra option in your settings preference pane called GPG Preferences. This allows you to set your GPG preferences, such as update checking and the public keyserver you would like to use. Most people can just leave this set with the default values.</p>
<figure id="attachment_1691" aria-describedby="caption-attachment-1691" style="width: 653px" class="wp-caption aligncenter"><img data-recalc-dims="1" fetchpriority="high" decoding="async" class="size-full wp-image-1691" src="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.27.33.png?resize=648%2C627&#038;ssl=1" alt="GPGpreferences icon in your Mac OS settings" width="648" height="627" srcset="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.27.33.png?w=653&amp;ssl=1 653w, https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.27.33.png?resize=300%2C290&amp;ssl=1 300w" sizes="(max-width: 648px) 100vw, 648px" /><figcaption id="caption-attachment-1691" class="wp-caption-text">GPGpreferences icon in your Mac OS settings</figcaption></figure>
<figure id="attachment_1692" aria-describedby="caption-attachment-1692" style="width: 662px" class="wp-caption aligncenter"><img data-recalc-dims="1" decoding="async" class="size-full wp-image-1692" src="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.10.44.png?resize=648%2C520&#038;ssl=1" alt="GPG Preferences pane" width="648" height="520" srcset="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.10.44.png?w=662&amp;ssl=1 662w, https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.10.44.png?resize=300%2C241&amp;ssl=1 300w" sizes="(max-width: 648px) 100vw, 648px" /><figcaption id="caption-attachment-1692" class="wp-caption-text">GPG Preferences pane</figcaption></figure>
<p>The first thing you will want to set up are your keypairs. Make sure you have added the email account you want to start using with encryption as one of your Mac Mail accounts. If you use a free account such as Gmail you can still add it to your Mac Mail software &amp; encrypt emails using that account.</p>
<p>Next, head to your applications folder &amp; select the newly installed GPG keychain application. Open the application and click New in the top left corner. You will be presented with the following screen, showing you your Mac Mail email addresses. In these settings, select the email account you would like to use with GPG encryption, select the box to upload your public key (makes it much easier for people to correspond with you) and enter your passphrase.</p>
<p>The passphrase is a vital part of your encryption as it unlocks your keypair for use. Make sure it is a strong password &amp; one you can remember. Also, my advice is to use a password you only use for encryption. This password is never for use with any online services such as websites. A single hack of any of those sites could reveal your password, so encryption passwords are only for local use.</p>
<p>Once you are happy with your passphrase, click generate key. Your GPG key pair will be generated &amp; public key uploaded to they keyservers.</p>
<figure id="attachment_1693" aria-describedby="caption-attachment-1693" style="width: 443px" class="wp-caption aligncenter"><img data-recalc-dims="1" decoding="async" class="size-full wp-image-1693" src="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.34.17.png?resize=443%2C295&#038;ssl=1" alt="Setting up a GPG keypair in OSX using GPGsuite" width="443" height="295" srcset="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.34.17.png?w=443&amp;ssl=1 443w, https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.34.17.png?resize=300%2C200&amp;ssl=1 300w" sizes="(max-width: 443px) 100vw, 443px" /><figcaption id="caption-attachment-1693" class="wp-caption-text">Setting up a GPG keypair in OSX using GPGsuite</figcaption></figure>
<p>You should then see your newly created key within GPG Keychain. You are now good to start creating encrypted emails.</p>
<figure id="attachment_1694" aria-describedby="caption-attachment-1694" style="width: 927px" class="wp-caption aligncenter"><img data-recalc-dims="1" loading="lazy" decoding="async" class="size-full wp-image-1694" src="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.13.10.png?resize=648%2C215&#038;ssl=1" alt="My GPG Keychain." width="648" height="215" srcset="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.13.10.png?w=927&amp;ssl=1 927w, https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.13.10.png?resize=300%2C99&amp;ssl=1 300w, https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.13.10.png?resize=768%2C254&amp;ssl=1 768w" sizes="auto, (max-width: 648px) 100vw, 648px" /><figcaption id="caption-attachment-1694" class="wp-caption-text">My GPG Keychain.</figcaption></figure>
<p>My advice, if you are going to start encrypting emails between friends, family or colleagues is to first send them an email with your public key attached. This way, they can import it into their keychain to allow them to email you. They can also send you theirs back. This isn&#8217;t a requirement if you have both uploaded them to a keyserver, but it&#8217;s always a good idea before you start encrypting communications between you. It&#8217;s also a friendly way to allow the other party to know that you want to encrypt your emails &amp; to expect future emails to be encrypted.</p>
<p>Now, fire up Mac Mail and compose a new email, you will see a new OpenPGP option in the top right of your compose window. This will be green if using an email account for which you have created a keypair &amp; will be greyed out if composing from an account without a keypair. In the screenshot below I&#8217;m emailing between my own account &amp; my unused gmail account which also has a keypair. As you can see the OpenPGP button is green which means a keypair is present &amp; I can encrypt on this account.</p>
<figure id="attachment_1695" aria-describedby="caption-attachment-1695" style="width: 986px" class="wp-caption aligncenter"><img data-recalc-dims="1" loading="lazy" decoding="async" class="size-full wp-image-1695" src="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.12.27.png?resize=648%2C318&#038;ssl=1" alt="OpenPGP options in Mac Mail" width="648" height="318" srcset="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.12.27.png?w=986&amp;ssl=1 986w, https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.12.27.png?resize=300%2C147&amp;ssl=1 300w, https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.12.27.png?resize=768%2C377&amp;ssl=1 768w" sizes="auto, (max-width: 648px) 100vw, 648px" /><figcaption id="caption-attachment-1695" class="wp-caption-text">OpenPGP options in Mac Mail</figcaption></figure>
<p>You will also see in the above screenshot the two blue icons. They are blue if they are enabled, but are greyed out if either&nbsp;a public key isn&#8217;t present for your recipient or you have opted not to encrypt. If you do have a public key for your recipient in your&nbsp;GPG Keychain you can activate one or both of these buttons. The left one which is a padlock is your encryption button, the right one is your GPG signature to securely sign your email. If sending to someone with whom you have a public key, I would always sign &amp; encrypt.</p>
<p>Once you are setup, emailing is just as straightforward as before. Write your message, your subject and add any attachments you would like. Note that only the body of the email is encrypted, the subject line is not so be careful what you use there as it is publicly viewable. Once you are ready you can hit send, at this point you will be given an OpenGPG prompt for your pass phrase. This is your encryption pass phrase which you setup at the time of creating your key pair. This password will be required every time you encrypt or decrypt an email. You can opt to save the pass phrase in your keychain but I would advise against that. The whole point of encryption is to make email for your eyes only (and your recipient of course) so keep the passphrase to yourself &amp; commit it to memory. It&#8217;s just good practice.</p>
<figure id="attachment_1696" aria-describedby="caption-attachment-1696" style="width: 539px" class="wp-caption aligncenter"><img data-recalc-dims="1" loading="lazy" decoding="async" class="size-full wp-image-1696" src="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.12.49.png?resize=539%2C250&#038;ssl=1" alt="Enter your OpenPGP passphrase to encrypt &amp; decrypt emails" width="539" height="250" srcset="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.12.49.png?w=539&amp;ssl=1 539w, https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.12.49.png?resize=300%2C139&amp;ssl=1 300w" sizes="auto, (max-width: 539px) 100vw, 539px" /><figcaption id="caption-attachment-1696" class="wp-caption-text">Enter your OpenPGP passphrase to encrypt &amp; decrypt emails</figcaption></figure>
<p>The last part of the puzzle is decrypting email. Below is a screenshot I took of the email I just sent between my two accounts. When opening the email you will be asked for your encryption passphrase, this is to unlock your own keypair to decrypt the email. You will see from the screenshot that the email looks like any other, with the exception that it has signature and encryption details. The padlock shows that the email is encrypted.</p>
<figure id="attachment_1697" aria-describedby="caption-attachment-1697" style="width: 652px" class="wp-caption aligncenter"><img data-recalc-dims="1" loading="lazy" decoding="async" class="size-full wp-image-1697" src="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.13.50.png?resize=648%2C207&#038;ssl=1" alt="openPGP decrypted email" width="648" height="207" srcset="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.13.50.png?w=652&amp;ssl=1 652w, https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-20-at-17.13.50.png?resize=300%2C96&amp;ssl=1 300w" sizes="auto, (max-width: 648px) 100vw, 648px" /><figcaption id="caption-attachment-1697" class="wp-caption-text">openPGP decrypted email</figcaption></figure>
<p>If you follow these steps you will ensure any correspondence sent between you &amp; your friends/family can&#8217;t be read by any third-party. This means that if your email account is hacked, the contents of your messages remain private. Perfect for family photos, private information and general personal chatter. It also means that companies such as google can&#8217;t read your emails for advertising &amp; data collection purposes. The message remains scrambled with encryption across the whole internet, no matter who intercepts it.</p>
<p>Once you get used to this process it will become second nature. I like the &#8216;at rest&#8217; security of encrypted emails. I&#8217;m less worried about personal emails being hacked or stolen in a data grab. If my server is compromised, my emails are not. I also like the fact that using a completely unique password for my encryption means that my encryption password is never in the wild online. I&#8217;ve committed a complex password to memory &amp; I&#8217;m not likely to forget it after typing it so many times.</p>
<p>No security is perfect, but this is by far the biggest bang for your buck with regards securing your communications on a day-to-day basis.</p>
<p>You must keep your key pair secure. You can back them up using GPG keychain, both your public &amp; private key, but you must keep them safe. Never put your secret (private) key online or into cloud storage. If you ever lose control of your keypair, someone could pose as you and send emails masquerading as you, not to mention decrypt emails if they guess your passphrase. GPG Keychain has the ability to revoke keys if you feel they have been compromised. You can then generate a new keypair &amp; upload to keyservers as required.</p>
<p>This is just a brief outline of how to get started with OpenPGP using GPGSuite. If you would like to know more, you can read up online. A good starting point is the <a href="https://gpgtools.org/" target="_blank" rel="nofollow">GPGtools</a> site itself.</p>
<p>If you would like to send your first encrypted email, drop me a message at john AT johnlarge.co.uk using my <a href="https://www.johnlarge.co.uk/jodsclasspgpkey.asc">public key</a> which you can retrieve from the keyservers or <a href="https://www.johnlarge.co.uk/jodsclasspgpkey.asc">download by clicking here</a>. If you want to add to this post or correct please do let me know, like my other cybersecurity posts I&#8217;ve kept it as simple and non technical as possible to make it accessible. The post will evolve over time.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1690</post-id>	</item>
		<item>
		<title>Apple Cybersecurity basics &#8211; Securing your hardware</title>
		<link>https://www.johnlarge.co.uk/apple-cybersecurity-basics-securing-hardware/</link>
		
		<dc:creator><![CDATA[John Large]]></dc:creator>
		<pubDate>Sat, 18 Mar 2017 14:02:11 +0000</pubDate>
				<category><![CDATA[Apple Hardware]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[aes]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[cybe sercurity]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[encrypt]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[filevault]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[macbook]]></category>
		<category><![CDATA[opsec]]></category>
		<guid isPermaLink="false">https://www.johnlarge.co.uk/?p=1682</guid>

					<description><![CDATA[I&#8217;ve been planning on writing a series of posts on cybersecurity for a while now. I&#8217;ve been interested in computer security for decades &#38; have always tried to secure my machines, data &#38; online profiles. In the modern computing landscape, many aspects of basic cybersecurity have been lost. When I started out online, perhaps in [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>I&#8217;ve been planning on writing a series of posts on cybersecurity for a while now. I&#8217;ve been interested in computer security for decades &amp; have always tried to secure my machines, data &amp; online profiles. In the modern computing landscape, many aspects of basic cybersecurity have been lost. When I started out online, perhaps in the early 90&#8217;s, there was a strong culture of using online handles as opposed to your own personal details. We had an awareness that the internet was a public sphere which is universally accessible.</p>
<p>The internet is a public place, but it is also a place where you can&#8217;t control data flows. As soon as you upload information or data to the internet, you need to assume it is now on public record. Even if you believe your account is private and secure, there is a good chance that at some point, the data will be used, resold or even hacked &amp; released into the wild. If you approach the internet with this in mind it is very easy to secure your information. I&#8217;ll come to internet security later, but let&#8217;s start with your hardware itself.</p>
<p>I personally have a lot of computers. I have two Macbook Pro&#8217;s and an iMac, I also have Raspberry Pi&#8217;s running various versions of Linux &amp; also an old IBM Thinkpad X200 running Trisquel Linux. All of these machines use full disk encryption.</p>
<p>With apple products, make sure your software is up to date. All of my machines run OS Sierra which is a free upgrade. Sierra has a very good version of full disk encryption known as Filevault 2. Filevault 2 allows you to encrypt the entire contents of your hard drive with a password. This means that without the password, the contents of the Hard Drive can&#8217;t be read by a third-party. File Vault requires the disk password as soon as you start your machine, so anyone who steals your hardware will be unable to boot your machine to access information &amp; also unable to wipe the hard drive to reinstall the OS on your hard drive. This is vital in case of loss or theft of your devices. We store so much personal information on our devices &amp; their security is as important as securing your own home. Perhaps more important.</p>
<p>The same goes for iPhones. Make sure you use a strong passcode or passphrase to secure your device &amp; consider not using fingerprint access. Your fingerprint is very convenient, but a strong passcode is much more secure. Also, backup your iPhone or iPad to an actual computer and not to iCloud. If someone hacks your iCloud, they could clone your iPhone from one of your own backups &amp; access your entire iOS environment.</p>
<p>The passwords you use should be unique &amp; strong. You should also ensure that your encryption password is never stored or used for any online accounts. Your encryption password should be unique from any other password you use. You can choose a way of codifying your password, for instance take your favourite book (paper back or hard back) and use your birthday to select a page and a line. For instance, pick up a copy of Harry Potter, go to the page number which relates to your day of birth and then on that page go to the line number which relates to your month of birth. Use the text on that line for your password.</p>
<p>You can use any method to code your password, that is just a single example. Whatever you choose, make sure you have a way of reminding yourself which is not obvious. Without your encryption password your data would be lost forever.</p>
<p>Also, on Macs, make sure you disable any guest accounts in Settings &gt; Users &amp; Groups. Turn on the Firewall in Settings &gt; Security &amp; Privacy. This menu also contains the settings for turning on Filevault.</p>
<p>While in Security &amp; Privacy, make sure you choose to require a password after sleep or screen saver. This means that if you need to leave your laptop or desktop unattended, you can put it to sleep to lock the machine or set the screen to sleep after a certain amount of idle time. These are basics steps to secure your machine but will make a vast difference to the physical security of your Mac.</p>
<figure id="attachment_1683" aria-describedby="caption-attachment-1683" style="width: 660px" class="wp-caption aligncenter"><img data-recalc-dims="1" loading="lazy" decoding="async" class="size-full wp-image-1683" src="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-18-at-13.18.55.png?resize=648%2C523&#038;ssl=1" alt="Set your mac to automatically lock" width="648" height="523" srcset="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-18-at-13.18.55.png?w=660&amp;ssl=1 660w, https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/Screen-Shot-2017-03-18-at-13.18.55.png?resize=300%2C242&amp;ssl=1 300w" sizes="auto, (max-width: 648px) 100vw, 648px" /><figcaption id="caption-attachment-1683" class="wp-caption-text">Set your mac to automatically lock</figcaption></figure>
<p>With my iMac I use a Kensington lock to physically lock the machine to my desk. Make sure any external hard drives for your mac are also formatted with encryption &amp; set your encryption password on each of them. This means if any are lost or stolen, for example your time machine backup drive, they cannot be accessed by anyone but those with the encryption password. I encrypt all media including USB flash drives. It only takes seconds to mount them &amp; enter a password, but it does mean that your data is always much more secure. Get into the habit of encrypting &amp; you will massively reduce your exposure to hacking &amp; identity theft.</p>
<p>Something else I always do is use a small roll of black insulation tape to cover up the webcams on my laptops and desktops. You can peel it off easily if you require the webcam for facetime or skype, but most of the time I tend to leave the cameras covered. The camera can be used for spying by both governments &amp; criminals &amp; there have been many cases of people being recorded on their webcams &amp; then blackmailed. For the sake of a few pence, always have a roll of insulation tape and cover your webcams. You can even colour match the tape to your black Macbook/iMac bezel.</p>
<p>&nbsp;</p>
<figure id="attachment_1684" aria-describedby="caption-attachment-1684" style="width: 648px" class="wp-caption aligncenter"><img data-recalc-dims="1" loading="lazy" decoding="async" class="size-large wp-image-1684" src="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/FullSizeRender.jpg?resize=648%2C546&#038;ssl=1" alt="Insulation Tape over webcam" width="648" height="546" srcset="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/FullSizeRender.jpg?w=1024&amp;ssl=1 1024w, https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/FullSizeRender.jpg?resize=300%2C253&amp;ssl=1 300w, https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/FullSizeRender.jpg?resize=768%2C647&amp;ssl=1 768w" sizes="auto, (max-width: 648px) 100vw, 648px" /><figcaption id="caption-attachment-1684" class="wp-caption-text">Insulation Tape over webcam</figcaption></figure>
<p>With regards to securing your iPhone my main advice would be to set a fast timeout on your automatic screen lock. Never leave your phone unlocked &amp; make sure you get into the habit of locking the screen whenever you put the device down. Also make sure under your Touch ID &amp; passcode options in iOS settings, that you opt to require the passcode immediately &amp; that you opt to erase the device after 10 failed attempts. This means that in the event of loss or theft, the device will likely wipe itself before anyone can get your information &amp; identity from the device. You can also use iCloud to remotely message &amp; wipe your Mac&#8217;s &amp; iOS devices.</p>
<figure id="attachment_1685" aria-describedby="caption-attachment-1685" style="width: 576px" class="wp-caption aligncenter"><img data-recalc-dims="1" loading="lazy" decoding="async" class="size-large wp-image-1685" src="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/IMG_4281.png?resize=576%2C1024&#038;ssl=1" alt="iOS Touch id &amp; Passcode." width="576" height="1024" srcset="https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/IMG_4281.png?resize=576%2C1024&amp;ssl=1 576w, https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/IMG_4281.png?resize=169%2C300&amp;ssl=1 169w, https://i0.wp.com/www.johnlarge.co.uk/wp-content/uploads/2017/03/IMG_4281.png?w=750&amp;ssl=1 750w" sizes="auto, (max-width: 576px) 100vw, 576px" /><figcaption id="caption-attachment-1685" class="wp-caption-text">iOS Touch id &amp; Passcode.</figcaption></figure>
<p>Mac&#8217;s &amp; iOS devices now increasingly rely on cloud services to sync &amp; store your data. Ensure that you setup two factor authentication on your iCloud account, to make sure only someone with access to one of your physical devices can login to your iCloud account. Also, be aware that if iCloud is ever hacked &amp; the encryption keys that Apple hold are accessed, your iCloud data can be decrypted. Ensure that anything you offer up to the cloud is information which isn&#8217;t personally identifiable or potentially damaging. The cloud is ideal for mundane documents and data which isn&#8217;t specifically personal, but if it is something you want to keep private, don&#8217;t ever upload it to cloud services. I&#8217;ll cover this more in my next post regarding securing yourself online.</p>
<p>Finally, never give out your encryption password, it is the key to all of your data. Never use it for anything but encrypting, never use it with an online provider. If you do need to make a note of the password, codify &amp; hide it in a way that it can&#8217;t obviously be identified as a password. Always aim to physically keep hold of your devices. It is much harder to compromise your devices if they are always in your possession.</p>
<p>Never give out any passwords in email or over the phone. If someone calls asking for your account details, don&#8217;t give them out or ask them for their details and phone number &amp; offer to call them back. You can then check the number &amp; details online &amp; call a verified number.</p>
<p>Finally keep software up to date. There are zero day exploits being discovered and utilised daily. You massively decrease your attack surface if you keep software, services &amp; devices patched &amp; up to date.</p>
<p>I will add to this post as &amp; when I think of tips to help. If you have anything to add, please let me know in the comments. There will be loads that I have missed &amp; I expect this post will constantly evolve. I&#8217;ve also tried to keep the post as straightforward and non technical as possible. I want the basics to be adopted by everyone, so I&#8217;ve left out the in-depth discussions on things like AES &amp; encryption bit sizes.</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1682</post-id>	</item>
	</channel>
</rss>
