View Single Post
Community Council | Posts: 4,920 | Thanked: 12,867 times | Joined on May 2012 @ Southerrn Finland
#8
Originally Posted by szopin View Post
The idea is not about one-button-click secure from NSA solution, this will never happen, more about: is it even possible?
Actually this is something that I have been thinking about, it is far from impossible

An "one-click-safe-from-NSA-voicecalls" solution;
  • 1.) prerequisities; Both A&B subscribers have the encryption software installed in their devices
  • 2.) normal CS/PS voice call initiation
  • 3.) when both parties have verified that the other end is who it is supposed to be, they enter secure mode by starting the encryption application
  • 4.) the encrypting applications take over the voice channel, users are cut out from audio;
    - Layer 1 is audio modulation with fairly low bitrate and similar characteristics as speech range so that it passes reasonably unaltered through echo cancellation and other mangling that RAN does to it.
    - TCP/IP over that carries the connection data
    - SSL handshaking takes care of protecting the connection
    - finally the voice connection is now run on top of the secure connection
  • 5.) users have end-to-end encrypted voice channel for the duration of the rest of the call
There was a study and demonstration set up with N900 devices, I belive. It would be easy to have this kind of system on multiple platforms, you'd not be limited to use this only on Jolla-to-Jolla calls.


Originally Posted by szopin View Post
Some claim 'there is no NSA on Jolla', I would really like to believe it. How can (is it at all possible, skipping the obvious 'linux kernel openness vs billions of dollars NSA can pay for 0-days' dilemma) one check/investigate what is happening with his device. (yeah carrying Jolla + separate device for communication will not work, BTS usage will identify you instantly (jolla on wifi only, no data/roaming with macchanger every 5 minutes? I hope this is like Neo900 where you will be able to trust modem is actually OFF without removing the battery), but can jolla be 'safe' as for carrying corporate documents? I would not trust WP/iOS/Android for such)
The scenario I suggested above will of course not hide your device location, nothing can be used to do that if you want ot be on a public cellullar network, but there are ways of hiding who you are communicating with;
Imagine that instead of having a direct voicecall between A&B subscribers you could also set up the system so that both parties have their own connection point in their own controlled networks. After each party sets up connection to their own systems, call could be routed via TOR or similar approach between the connection points
 

The Following 3 Users Say Thank You to juiceme For This Useful Post: