20
CartoDrop mapping and reporting over Tor Nick Doiron - @mapmeld

CartoDrop: secure mapping and reporting over Tor

Embed Size (px)

DESCRIPTION

How can we make OpenStreetMap more secure for users everywhere? And could we make a secure reporting tool for mappers? Ignite talk at SOTMUS 2014 DC

Citation preview

Page 1: CartoDrop: secure mapping and reporting over Tor

CartoDrop

mapping and reporting over Tor !

Nick Doiron - @mapmeld

Page 2: CartoDrop: secure mapping and reporting over Tor

My background: maps

Page 3: CartoDrop: secure mapping and reporting over Tor

Carto and Crypto

At first glance, very different fields

Six months in, still different ¯\_(ツ)_/¯

Page 4: CartoDrop: secure mapping and reporting over Tor

Who needs crypto?

Page 5: CartoDrop: secure mapping and reporting over Tor

Not just NSA and USA

NSA gets capabilities through contractors

Software is resold to many countries

Government-run ISPs

Page 6: CartoDrop: secure mapping and reporting over Tor

With maps like these…

Human rights violations

Poaching and pollution

Systemic bribery

Political uncertainty

Voter suppression

Disease outbreaks

Page 7: CartoDrop: secure mapping and reporting over Tor

HTTPS?

HTTPS reveals

you and your domain

size of downloaded tiles

can’t read messages…

… unless someone gives up the key (ever)

Page 8: CartoDrop: secure mapping and reporting over Tor

build on Uncensorable Twitter

only protects distributor

Decentralize?

Page 9: CartoDrop: secure mapping and reporting over Tor

What does work?

Page 10: CartoDrop: secure mapping and reporting over Tor
Page 11: CartoDrop: secure mapping and reporting over Tor

Sounds tricky…?

Looks like Firefox

Orbot for Android

Page 12: CartoDrop: secure mapping and reporting over Tor

Disclaimer

Do use public WiFi

Don’t sign into your account

Don’t do illegal stuff

Don’t allow JavaScript

Page 13: CartoDrop: secure mapping and reporting over Tor

-> SecureDropDemo.org <- !

Designed for journalists, already on FirstLook and WildLeaks

Page 14: CartoDrop: secure mapping and reporting over Tor

Good and bad newsJavaScript? NO

APIs NO

Secure passwords YES

PGP encryption YES

Air gap docs YES

Page 15: CartoDrop: secure mapping and reporting over Tor

Maps break SecureDrop!Journalist needs to look up each coordinate:

without a visual

without software (can’t install on Tails)

without the web

Page 16: CartoDrop: secure mapping and reporting over Tor

Can we build crypto?

Page 17: CartoDrop: secure mapping and reporting over Tor

Building CartoDrop

OSM + NaturalEarth

Mapnik Python

Messages stay encrypted

Source’s identity stays protected

Page 18: CartoDrop: secure mapping and reporting over Tor
Page 19: CartoDrop: secure mapping and reporting over Tor

The <way/> forward

Page 20: CartoDrop: secure mapping and reporting over Tor

Speak Freely@mapmeldon Twitter & Keybase