Information Leakage Article Index for
Information
Website Links For
Information
 

Information About

Information Leakage




Designers of secure systems often forget to take information leakage into account. One classic example of this is when the French government designed a mechanism to aid encrypted communications over an analog line, such as at a phone booth. It was a device that clamped onto both ends of the phone, performed the encrypting operations, and sent the signals over the phone line. Unfortunately for the French, the rubber seal that attached the device to the phone was not airtight. It was later discovered that although the encryption itself was solid, if you listened carefully, you could hear the speaker, since the phone was picking up some of the speech! Information leakage can subtly or completely destroy the security of an otherwise Bulletproof system.

Generally, only very advanced systems employ defenses against information leakage - there are three main ways to do it:

  • Use Steganography to hide the fact that you're transmitting a message at all.

  • Use Chaffing to make it unclear to whom you are transmitting messages (but this does not hide from others the fact that you are transmitting messages).

  • For busy retransmitting proxies, such as a Mixmaster node: randomly delay and shuffle the order of outbound packets - this will assist in disguising a given message's path, especially if there are multiple, popular forwarding nodes, such as are employed with mixmaster mail forwarding.