Saturday, August 22, 2009

HOW TO HIDE ANYTHING

HOW TO HIDE ANYTHING
-
How to send information that no-one can read without encoding it and without anyone being able to prove you have hidden it.

Some years ago some friends were earning large sums in cash in Amsterdam. Unfortunately too many people knew that fact. Due to the difficulty of banking large quantities of small bills they used to leave the money in their apartment. This worked basically because there was always some one at home guarding it. In the end they made so much money they decided to retire to a sunnier clime.

They went on a shopping spree and bought all those things they did not expect to be able to find in the Caribbean - and I mean boxes and boxes of trinkets of all descriptions.

When visited, getting through the apartment door was difficult, and there was no place to sit down in any room: apart from the toilet!

That night they went out to celebrate before saying final good byes. When they got home at 2am they found that the house had been ransacked.

Every box or case had been opened and gone through for hours. The thieves had also destroyed and pissed on the stuff. It was later understood why no money had been had been stolen despite the raiders several hours of searching!


How could this happen? What extremely clever place did they hide their money? The answer is that the money was not hidden at all! It was no more hidden than a sunken treasure ship.

There was simply so much stuff to go through that the thieves did not have the time and energy to find it. The money was a needle in a haystack! If you placed the needle yourself it is not difficult to find it (as long as they haystack is not radically altered - like my wife does to my desk) but if you have no idea where it is you have a virtually impossible task.

Sometimes it is suspicious or illegal to hide things. The immigration officer wants to know why you have someone else's passport photos inside your sock rather than in your wallet. The judge threatens to imprison you if you do not hand over all relevant business papers. And in France encryption is forbidden by law. So take a very big album of photographs: photography is your hobby. Or give the judge so many irrelevant papers that it will take him 10 years of looking to find the paper that he wants.

Even where encryption is legal it can make a file or message stand out. It may be lower profile not to encrypt email but to deluge with it: the recipient ignores all messages except those which begin with "PT" for example. Also for the uninitiated encryption software can be a nightmare to install.

That said I still highly recommend the use of public key encryption like pgp9.9.i which is available free and can be down loaded from the Internet at < from outside the USA and within the USA. But as part of the needle in the haystack philosophy you should routinely encode all messages not just important ones. In this way the enemy a) does not know what messages are worth trying to decode and b) cannot accuse you of trying to hide specific information because you send everything in code! This can be useful if it ever comes to a court case.

Next step is not to send important information as an email message but as an encrypted file attached to an encrypted email message. Any file can be attached: even a database file containing a large number of names and addresses. The message with the file will still only take seconds to transmit. I suggest that a large file is made to look smaller by using a file compression tool like ZIP. Personally, I recommend LHA. This will shrink a file to about 10% of its normal size: thus making is less interesting to snoops and a faster transmission tim. Usually, you will have a compressed file with the following file ending: .LZH. This is a give away. However if you stipulate the file suffix yourself you can have any suffix you wish.
For example:

C:>\dbase\clients.dbf A:\rabbit.gif

This will compress your database file called clients on the hard disc to 1/10 of its size on a floppy disk where it will be known as "rabbit.gif". If you include this with other animal photos files no one will know that a data file is compressed and hidden among a bunch of animal graphics files with similar names: "lion.gif", "zebra.gif", "sheep.gif" and perhaps 10,000 others copied from a CD. Graphics files tend to be big too. Having compressed your database file and renamed it with a suitable file suffix and bunched together in a directory with hundreds of similar looking but innocent files it is now time to compress the entire directory and then encrypt it. If you encrypt and then compress it will not be obvious to the casual observer that encryption has been used. Then attach it to an email and send it to an anonymous email address that you have just set up for that very purpose. These can be obtained free on line through
http://www.hushmail.com or http://www.safe-mail.net.

Now anyone can download your message anywhere simply by accessing the anonymous email address. Smuggling information over boarders has never been easier or safer. Nothing needs to go anywhere or be in anyone's pocket or computer anymore.

Another highly recommended product is called Steganos. Steganos is a high powered easy to use encryption program that will automatically encrypt your files and hide them IN PLAIN LOOKING FILES. In other words should anyone look at your files on your computer (or USB,) all they would SEE is a picture file. Even if they open the picture file all they will see if the picture you took, e.g., you and your love on the local Amsty boat ride! It can only be decrypted with your secret password WITH THAT PARTICULAR file.

Another recommended product is https://www.ironkey.com

Until next time - SSshhh

1 Comments:

Blogger Quantum_Flux said...

Haha, so now I know exactly what to look for.

9:07 AM  

Post a Comment

<< Home