PDA

View Full Version : Online Anonymity - Instant Messaging



bigtuna
04-24-2014, 07:31 PM
Online Anonymity - Instant Messaging - 2.0 - NO GMAIL ACCOUNT REQUIRED.
note: Instant Messaging v1 (http://brotherhoodofpain.com/showthread.php?13675-Online-Anonimity-Instant-Messaging&p=176188&viewfull=1#post176188) is available below and shows an example of using a burner gmail account

Coming Soon:
Instant Messaging for Mobiles (~60% this has been the bane of my existence)
What is PGP? A guide on how to securely have email conversations (~40%)
What is VPN and why do I need it? (0%)

REQUIREMENTS

Tools:
Pidgin
http://www.pidgin.im/
OTR
https://otr.cypherpunks.ca/
https://otr.cypherpunks.ca/binaries/windows/pidgin-otr-4.0.0-1.exe

Steps:
Install Pidgin
Install OTR

Jabber Account

To setup a free jabber account, use the service provided by http://uprod.biz/
Setup account settings as follows:
http://uprod.biz/Pidgin.png
Any username, Any password, set domain to uprod.biz, leave resource blank, remember pw, and create account on server. If the username has already been registered, try another one.
now you have a free jabber account that you can use OTR with

OTR Settings

Navigate to Tools -> Plugins -> Off the record messaging and enable
Settings
Select the email account youre using -> Generate a fingerprint (Your unique key)
Check - Enable Private Messaging
UnCheck - Automatically initiate private messaging
Uncheck - Require Private Messaging

Check - Don't log OTR conversations - why would you want to log?
Check - show OTR in toolbar
Finished with setup

Add person you want to chat with, enable private messaging, authenticate each other, and talk with complete sense of security
My public xmpp is [email protected] if yall are bored

PAiN
04-24-2014, 07:41 PM
Great post. Thanks for this brother.

bigtuna
04-24-2014, 07:46 PM
part of a set i'm working on. (pgp, vpn, pw, encryption)

bigtuna
04-28-2014, 04:47 AM
Online Anonimity - Instant Messaging.

NOTE: This is a very basic tutorial, gmail accounts are NOT the only way to use pidgin and OTR
REQUIREMENTS

Gmail Account
Tools:
Pidgin
http://www.pidgin.im/
Download Link (http://downloads.sourceforge.net/project/pidgin/Pidgin/2.10.9/pidgin-2.10.9.exe?r=http%3A%2F%2Fsourceforge.net%2Fprojec ts%2Fpidgin%2F&ts=1398367724&use_mirror=softlayer-dal)

OTR
https://otr.cypherpunks.ca/
https://otr.cypherpunks.ca/binaries/windows/pidgin-otr-4.0.0-1.exe

Steps:
Install Pidgin
Install OTR
SETUP

BASIC
Protocol = XMPP
Username: "Username" @gmail.com - only include the username without the quotes
Domain: gmail.com
resource: whatever you want.
pw: gmail pw
Check or uncheck remember password box, personal preference.
User Options:
Local Alias = if you want a local alias
Leave new mail notifications and use this buddy icon for this account untouched

Advanced
connection security = require encryption
connect port : 5222
connect server: talk.google.com
uncheck show custom smileys
uncheck allow plain text
do not check create new account on server
save

OTR Settings
Navigate to Tools -> Plugins -> Off the record messaging and enable
Settings
Select the email account youre using -> Generate a fingerprint (Your unique key)
Check - Enable Private Messaging
Don't Check - Automatically initiate private messaging
Don't check User-Dependent Require private messaging
Check - Don't log OTR conversations - why would you want to log?
Check - show OTR in toolbar
Finished with setup





Communicating

Start up a chat with a buddy you want to talk to.
click OTR at the top menu-bar and press initiate private conversation if it has not been initiated already. The message below should appear
(Unverified conversation with [email protected]/XXXXXXXX started. Your client is not logging this conversation.)
There are three methods of authentication
Question&Answer: User A will enter a Question and Answer. User B will have to provide the answer (case-sensitive)
Shared Secret: Have a phrase or word that you both previously agreed on. Enter it.
Manual fingerprint Verification: Verify both users fingerprints (key generated in the OTR setting section above)

Once verified, "The privacy status of the current conversation is now: Private" should appear

There you go. All done. Secure messaging.
If you are using gmail, messages that are sent with OTR with show up garbled in the gmail chat history.

TheTrain
04-28-2014, 09:31 AM
I like this a lot, this is still leaving a print on the computer though correct? What temp internet files? Forgive my ignorance brothers! Still this is the closest thing to secure email then I'd imagine

bigtuna
04-28-2014, 09:47 AM
I like this a lot, this is still leaving a print on the computer though correct? What temp internet files? Forgive my ignorance brothers! Still this is the closest thing to secure email then I'd imagine


There are portable versions of pidgin that are on the web. You can simply add it to your USB drive and you should be good to go.

As for installed versions of pidgin, if you check "Do not log conversations" no logs are made.

I'm planning on doing a writeup about tails in a little after I finish my section on PGP

20Guage
04-29-2014, 05:12 AM
Excellent post brother! I dig not needing a Gmail account

animal87
04-29-2014, 05:35 AM
I'm gonna figure it out soon. It's always good to be safe as possible.

bdad
04-29-2014, 06:36 AM
There are portable versions of pidgin that are on the web. You can simply add it to your USB drive and you should be good to go.

As for installed versions of pidgin, if you check "Do not log conversations" no logs are made.

I'm planning on doing a writeup about tails in a little after I finish my section on PGP

Will definately be bookmark material.

20Guage
04-29-2014, 12:31 PM
I personally think it is good to connect to a vpn or two first for extra security

bigtuna
05-02-2014, 11:20 AM
I personally think it is good to connect to a vpn or two first for extra security

do you go by Guage on other forums? jw, name seems familiar as well as typing style

VPNs are good, I am finishing up a current writeup on them right now but it is impossible for anyone else to read messages between the users, users are forced to go through authentication to prove they are who they say they are, and attempts at forged OTR are futile