From 4f5bf8afa598a143544df37f7e6476d0b05df702 Mon Sep 17 00:00:00 2001 From: varac Date: Tue, 21 Jun 2016 11:25:12 +0200 Subject: Revert "added cardiff2015 slides" This reverts commit 13fb30c8fc72e45a2dfb170322deff4b9ffd82bc. --- cardiff2015/slides/index.html | 296 ------------------------------------------ 1 file changed, 296 deletions(-) delete mode 100644 cardiff2015/slides/index.html (limited to 'cardiff2015/slides/index.html') diff --git a/cardiff2015/slides/index.html b/cardiff2015/slides/index.html deleted file mode 100644 index 5f7f6a6..0000000 --- a/cardiff2015/slides/index.html +++ /dev/null @@ -1,296 +0,0 @@ - - - - - -LEAP/Pixelated Introduction - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- -
- -
-
-

LEAP Encryption Access Project

-
-
-
-

Bring back the 1990s!

-
-
-

What is Federation?

-

-
    -
  • user → provider → provider → user
  • -
  • eg: SMTP, XMPP
  • -
-

-
-
-

Better federation

-

-
    -
  • The users should be protected from the provider.
  • -
  • The provider should be protected from users.
  • -
-

-
-
-

What does
LEAP do?

-
    -
  1. -LEAP Platform:
    a toolkit to make it easy for you to run a service provider.
  2. -
  3. -New protocols:
    so that users don't need to trust the provider.
  4. -
  5. -Bitmask client:
    a client that works smoothly with any compatible provider.
  6. -
-
-
-

LEAP Platform

-
sudo gem install leap_cli
-leap new example --domain example.org
-cd example
-leap add-user --self
-leap cert ca
-leap cert dh
-leap cert csr
-leap node add blueberry services:openvpn \
-     ip_address:1.1.1.1 openvpn.gateway_address:1.1.1.2
-leap node add raspberry services:couchdb,webapp \
-     ip_address:1.1.1.3
-leap init node
-leap deploy
-
-
-
-

New Protocols

-
    -
  • -Soledad: searchable client-encrypted synchronized database.
  • -
  • -Bonafide: secure user registration, authentication, password change, etc.
  • -
  • -Key management: precise rules for OpenPGP best practices, automated.
  • -
-
-
-

Bitmask client

-
- -
-
- -
-
-
-

Current Services: VPN

-
    -
  • Easy to use.
  • -
  • Route all your internet trafic through an encrypted channel.
  • -
  • Prevent eavesdropping (thiefs in the public network, police, ...).
  • -
  • Circunvent internet censorship.
  • -
  • Prevent leaks (DNS, IPv6, ...).
  • -
-
-
-

Current Services: email

-

- Work in progress -

-
    -
  • Easy to use.
  • -
  • End-to-end encryption.
  • -
  • Automatic key discovery and validation.
  • -
  • Backwards compatible with email and current OpenPGP usage.
  • -
  • Service provider has no access to user data.
  • -
  • Strong protection for metadata, when supported.
  • -
  • Cloud synchronized for high availability on multiple devices.
  • -
-
-
-
-

Our goals:

-
    -
  • Mass adoption
  • -
  • Increase the cost of dragnet surveillance
  • -
-
-
-
-
-

Pixelated Useragent

-
    -
  • Bitmask client and Email Client combined.
  • -
  • Modern, good looking UI.
  • -
  • Integrated search, search index encrypted
  • -
  • Tagging
  • -
-
-
-
-

Activist Setup

-
    -
  • Useragent needs to get installed locally
  • -
  • Private Keys on local device
  • -
-
-
-

Organisation Setup

-
    -
  • Multi-User encrypted Webmail
  • -
  • No Installation, access via browser
  • -
  • Private Keys on the server
  • -
  • Activist Setup possible on individual choice
  • -
-
-
-
-
-

Metadata

-
    -
  • Simple Mail Transfer Protocol from 1982 (!)
  • -
  • Email exposes lots of metadata (Date:, From:, To:, Subject:, Useragent:)
  • -
  • "Memory Hole" proposal to hide metadata in gpg encrypted mail
  • -
  • Enforce Transport Security whenever possible.
  • -
-
-
-
    -
  • -
-
-
-
- -

 

-

 

- -
-
- -
-
- - - - - - - - -- cgit v1.2.3