The TFC Project develops a paranoid secure messaging system.

As part of the project TFC (Tinfoil Chat) an attempt has been made to create a prototype of a paranoid-secure messaging system that would maintain the confidentiality of correspondence even if the end devices are compromised. To simplify the auditing process, the project's code is written in Python and is available under the GPLv3 license.

Currently popular messaging systems that use end-to-end encryption protect correspondence from interception on intermediate servers and from traffic analysis, but do not protect against issues on the client device side. To compromise systems based on end-to-end encryption, it is sufficient to compromise the operating system, firmware, or messaging app on the end device, for example, through exploitation of previously unknown vulnerabilities, through initial implantation of software or hardware backdoors, or through delivery of a fake update with a backdoor (e.g., under pressure from developers by security agencies or criminal groups). Even if the keys for encryption are kept on a separate token, with control over the user's system, there is always the possibility of tracing processes, intercepting data from the keyboard, and monitoring the output on the screen.

TFC offers a hardware-software complex that requires three separate computers and a special hardware splitter on the client side. All traffic during the interaction of messaging participants is transmitted through the anonymous Tor network, and the messaging programs are implemented in the form of Tor hidden services (users are identified by hidden service addresses and keys during messaging).

The TFC Project develops a paranoid secure messaging system.

The first computer serves as a gateway to connect to the network and launch the Tor hidden service. The gateway only manipulates pre-encrypted data, while the other two computers are used for encryption and decryption. The second computer can only be used for decrypting and displaying received messages, while the third is used only for encrypting and sending new messages. Consequently, the second computer has only the keys for decryption, while the third has only the keys for encryption.

The second and third computers do not have direct network connections and are separated from the gateway computer by a special USB splitter that uses the principle of “data diode” which physically allows data to flow only in one direction. The splitter permits only data to be sent to the second computer and only data to be received from the third computer. The direction of data in the splitter is restricted by means of optocouplers (simply cutting the Tx and Rx lines in the cable is insufficient, as a break does not prevent data transmission in the reverse direction and does not ensure that the Tx line will not be used for reading while the Rx line is used for sending). The splitter can be assembled from available components, the diagrams are attached (PCB) and are available under the GNU FDL 1.3 license.

The TFC Project develops a paranoid secure messaging system.

With this scheme, compromising the gateway will not allow access to the encryption keys and will prevent the continuation of the attack on the remaining devices. In the event of a computer compromise that hosts the decryption keys, information from it cannot be transmitted to the outside world, as the data flow is limited only to receiving information, and the reverse transmission is blocked by the data diode.

The TFC Project develops a paranoid secure messaging system.

Encryption is performed based on 256-bit keys using XChaCha20-Poly1305, with a slow hash function for password protection Argon2id. Key exchange is performed using X448 (Diffie — Hellman protocol based on Curve448) or PSK keys (pre-shared). Each message is transmitted in perfect forward secrecy mode (PFS, Perfect Forward Secrecy) based on Blake2b hashes, where the compromise of one of the long-term keys does not allow the decryption of previously intercepted sessions. The application interface is extremely simple and includes a window divided into three areas — sending, receiving, and a command line with a log of interactions with the gateway. Control is performed through a special command set.

The TFC Project develops a paranoid secure messaging system.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster