The Wayback Machine - https://web.archive.org/web/20110721205017/https://guardianproject.info/blog/

Announcing ObscuraCam v1 – Enhance Your Visual Privacy!

We’re very happy to announce the beta release of ObscuraCam for Android. This is the first release from the SecureSmartCam project, a partnership with WITNESS, a leading human rights video advocacy and training organization. This is the result of an open-source development cycle, comprised of multiple sprints (and branches), that took place over the last five months. This “v1″ release is just the first step towards the complete vision of the project.

The goal of the SecureSmartCam project to to design and develop a new type of smartphone camera app that makes it simple for the user to respect the visual privacy, anonymity and consent of the subjects they photograph or record, while also enhancing their own ability to control the personally identifiable data stored inside that photo or video. Also, we think an app that allows you to pixelize your friends, disguise their faces and otherwise defend their privacy just a little bit, is a lot of fun and helps raise awareness about an important issue. In this first release we have focused on ‘obscura’ by optimizing the workflow of identity obfuscation in still images. Future releases will look at ‘informa,’ the process of properly gaining and recording informed consent from subjects, while also moving to video.

Quick Download Links

For those of you who just want to get to it, head over to the Android Market to grab the latest version of the app. You can also scan the QR code to the left, and it will take you in that direction.

For those without access to the Android Market, you can get the ObscuraCam.APK file from our public builds folder. The official signed release binary is also available here. For these options, be sure to check back for updates, because the app will not auto-update itself.

The “Cameras Everywhere” Initiative

In January, WITNESS launched their Cameras Everywhere initiative, in which they ask:

As more and more people film people speaking out and taking a stand against human rights crises, how can we protect victims and witnesses and ensure informed consent as much as possible? As more and more footage circulates from human rights crises around the world, how does powerful footage reach audiences in comprehensible ways that move people to action? And how do we know how to trust that footage?

Critical issues to address in this realm include safety and security in the use of video; ethical questions raised by the widespread capacity to shoot and circulate human rights video; challenges around the authenticity of video and the preservation of evidence; and the need for effective documentation around the use of video in advocacy.

Through our collaboration, WITNESS has decided to move beyond just awareness, training and advocacy, and instead help design a next generation of Camera app software that is not just intended to share and capture more, but is meant to allow its operator to stop, think and be empowered to control the media they are capturing.

A Primer on Visual Privacy and Anonymity

Visual Privacy is the relationship between collection and dissemination of visual information, the public expectation of privacy, and the legal issues surrounding them. It relates particularly to the increasing presence of large-scale still- and video-camera networks in everyday life. This not only includes those surveillance-oriented networks under the control of corporations and governments, but also applies to the vast new network of citizen-controlled media capture devices such as smartphones and handheld cameras that has created a peer-to-peer, social-networking based surveillance. At the same time that these networks have exploded in size, face detection and recognition technologies have also improved considerably while policy regarding the privacy and fair use of such systems and content, as well as the rights of those imaged by such networks, are topics that are not resolved. What results is a situation in which massive amounts of media are being captured every day with little to no protection of individual rights to privacy or anonymity – something that is especially detrimental to human rights efforts.

As Sam Gregory of WITNESS points out, most contemporary discussions around anonymous communication on the Internet focus on the data protection side – for instance options for data encryption or censorship circumvention. In the case of media content, a largely unaddressed question arises: what about the rights to anonymity and privacy for those people who appear, intentionally or not, in visual recordings? Visual privacy and anonymity may sound like a contradiction in terms, but people often wish to speak out and to ‘be seen’ while at the same time concealing their face and identifying surroundings. As human rights documentation and organizing increasingly involves media capture, how are people enabled to make purposeful choices about when they speak out and what degrees of anonymity they hold onto for themselves? Conversely, people caught in the background of a video or still may be unaware that they are even being filmed in that moment and have no option to protect themselves – particularly true in mass protest settings where the wave of group solidarity may overwhelm any sense of personal privacy. For those speaking out from marginalized positions, personal safety is a very real risk.

Some examples where visual privacy and anonymity is being diluted in the name of features or security:

  • The persecution later faced by bystanders and people who stepped in to film or assist Neda Agha-Soltan as she lay dying during the 2009 Iranian election protests.
  • Facebook’s opt-out feature for auto-detection and tagging of faces
  • British Columbia’s privacy watchdog OKs the use of facial recognition technology to identify rioters from video and still images of Vancouver’s 2011 hockey riots.
  • Viewdle’s Social Camera automatically tags your friends in photos based on the social networking profile pictures they have published

While some of these examples might seem harmless, or even a useful feature for law enforcement, the main issue is that the subjects of these photos and videos are never asked if they wish to participate in them, not to mention whether they want their photo published online in the first place. The permanence of media on the Web means that any uploaded content can be poured over again and again to identify individuals – either by old-fashioned investigative techniques, but crowd-sourcing, or by face detection /recognition software.

How ObscuraCam Helps

Part of the problem currently surrounding visual privacy and anonymity is the fact that many of the tools and applications that people use on an everyday basis do not have features built in to protect privacy. As a result, everyone with a smartphone, tablet or laptop – not to mention an actual video camera! – captures raw, unedited content that exposes the identities of participants and bystanders present at sensitive events or activities.

ObscuraCam is a mobile application for Android that makes it easy for anyone to protect the identity of individuals or groups represented in their photos by building obfuscation and redaction directly into the app. It can be used on photos taken directly from the app itself, or on any photo that your mobile device has access to, including local memory card images or linked Picasa albums. By moving a usually cumbersome post-production process into the daily workflow of those capturing sensitive images, it’s our hope that visual privacy will be respected when it really matters.

Using ObscuraCam

ObscuraCam features a simple, touch-based user interface for easy manipulation and redaction of images, as well as an automated removal of identifying metadata stored in the photo itself. The following steps walk through the process of capturing and sharing an obscured photo using ObscuraCam.

  1. From the application home page, choose to either capture a new image or choose an existing image from your existing collections. These options just launch your standard Camera and Gallery application. When the photo is imported, identifying EXIF metadata stored in the file itself, such as GPS location, camera make and model or timestamp, will be removed.
  2. After you capture or open an image with ObscuraCam, it is automatically scanned to detect faces. Any faces detected are marked as tagged regions in an image, and the user is able to create as many additional tagged regions as they wish – either via the menu or by long-pressing the desired region. By default, tagged regions are set to be obscured via pixelation.
  3. Once a tagged region has been created, the user can interact with that region by simply touching it to bring up a contextual menu.
  4. Options available from the contextual tagging menu include:
    • Edit – select to scale and move tagged regions
    • Redact – select to fully redact tagged region and replace with black space
    • Pixelate – select to selectively obfuscate identities of persons or situations
    • bgPixelate – select to easily obfuscate everything BUT the tagged region
    • Mask – select to pin a set of ‘groucho marks’ glasses on the tagged region – not only a bit of fun, but useful for quickly defeating facial recognition schemes.
    • Delete – delete the current tagged region
  5. Once you’re done selecting and obfuscating tagged regions, you can use the options from the main application menu to see a preview of the finished image, save it to your local memory, or share the picture with any application on your handset that is configured to accept images. This includes applications like Facebook, Twitter, or the default Messaging app. 

Share With Us and “Save Your Face”!

As impediments of visual privacy continue to expand, help us get the word out that we can take back control over our online identities with ObscuraCam! We’ve set up a Facebook Page where you can share your creations with us, and with eachother!

Source Code & Issue Reporting

We’re big fans of open source and living in public. As consistent with all our projects, source code for the SecureSmartCam project, along with the ObscuraCam release, is available online at GitHub.

We also use GitHub to manage our development milestones and active bugs / issues. If you encounter any bugs or issues when testing out this beta build, please report them directly to us in the comments below or by filing directly on the Issues page.

 

Lil’ Debi: Easy Installer for Debian on Android

Have an Android phone and want an easy Debian chroot running it?

Alpha test our new app, Lil’ Debi. It builds up a whole Debian chroot on your phone entirely using debootstrap. You choose the release, mirror, and size of the disk image, and away it goes. It could take up to an hour, then its done. Then it has a simple chroot manager that mounts and unmounts things, and starts/stops sshd if you have it installed. You can also then use ‘apt-get’ to install any package that is released for ARM processors. This includes things like GPG, Tor, TraceRouteTCP and other security and crypto tools.

Project and source are here:
https://github.com/guardianproject/lildebi

Have a look at our automatic build bot for the latest binary installer APK here: https://guardianproject.info/builds/lildebi/

Check the GitHub wiki for tips on using it. If you don’t know what you need this for, then you probably should not install it (for now).

Orbot 1.0.5.2 now available

Our flagship app, Orbot: Tor on Android, has been updated to version 1.0.5.2. It is available in the Android Market, or through direct download from the Tor Project’s website.

This release fixes a number of long standing bigs, includes the latest and greatest release of Tor itself, cleans up the user interface a bit, and adds some new advanced options (you can specify your exit node country!). It also fixes an issue with our “Tor Everything” capability, that allowed some Android system network traffic to leak and bypass the Tor routing. Finally, it provides for compatibility for CyanogenMOD 7, as well as Android Gingerbread and Honeycomb.

Enjoy and stay safe out there!

CHANGELOG

1.0.5.1/.2
- small updates to layout of main screen to fit smaller screens
- fixed preference setting of EntryNode torrc value

1.0.5
- added exit node and “StrictExitNode” preference
- fixed tor binary installation issue related to max resource size and compression
- updated “start on boot” code to test for proper launch event
- updated to Tor 0.2.2.25-alpha binary
- moved back to single notification bar id to avoid double entries
- cleaned up progress dialog and alert handling to avoid leaky windows
- Merged __sporkbomb’s patch for how transproxy all works; now does “everything but Tor”
- Added new toolbar notifications and alerts for displaying notifications and Tor messages
- Removed unused Socks client code from android.net package
- Updated wizard to show link to Gibberbot (formerly OTRchat) chat app
- Bundled iptables 1.4.7 for ARM instead of relying on installed version
- Fixed various issues related to iptables, transproxying for CyanogenMod7/Android 2.3.*
- Changed how settings changed are processed through the control port (batched instead of one by one)
- Stopped app by app flushing of iptables rules, in favor of complete flush of ‘nat’ and ‘filter’ type
- removed useless log screen (logs can be viewed/retrieved using ‘alogcat’ 3rd party app)

Announcing: SQLCipher for Android, Developer Preview r1

After some major breakthroughs during last week’s development sprint, we’re extremely excited to announce SQLCipher for Android, Developer Preview r1. SQLCipher is an SQLite extension that provides transparent 256-bit AES encryption of database files. To date, it has been open-sourced, sponsored and maintained by Zetetic LLC, and we are glad to be able to extend their efforts to a new mobile platform. In the mobile space, SQLCipher has enjoyed widespread use in Apple’s iOS, as well as Nokia / QT for quite some time. Given that Android by default provides integrated support for SQLite databases, our goal was to create an almost identical API for SQLCipher, so that developers of all skill level could use it, without a steep learning curve.

If you are impatient, you can just get right to the SDK download here:
SQLCipher for Android, Developer Preview r1 (0.0.2)

In an environment where mobile data privacy is increasingly in the headlines, this project will make it easier than ever for mobile developers to properly secure their local application data, and in turn better protect the privacy of their users. The data stored by Android apps protected by this type of encryption will be less vulnerable to access by malicious apps, protected in case of device loss or theft, and highly resistant to mobile data forensics tools that are increasingly used to mass copy a mobile device during routine traffic stops.

However, while the core SQLCipher database is vetted and market-ready, the Android support libraries in this release are still very much alpha quality, hence the Developer Preview label. This R1 release should not be integrated into critical or production software. Our goal is to give Android developers early access to the technology, so they can provide feedback on our approach, and help us deliver the right offering for securing mobile data. We expect to release a market-ready version this summer, and will be publicly iterating through the codebase until then.

An Illustrative Terminal Listing

A typical SQLite database in unencrypted, and visually parseable even as encoded text. The following example shows the difference between hexdumps of a standard SQLite db and one implementing SQLCipher.

~ sjlombardo$ hexdump -C sqlite.db
00000000 53 51 4c 69 74 65 20 66 6f 72 6d 61 74 20 33 00 |SQLite format 3.|

000003c0 65 74 32 74 32 03 43 52 45 41 54 45 20 54 41 42 |et2t2.CREATE TAB|
000003d0 4c 45 20 74 32 28 61 2c 62 29 24 01 06 17 11 11 |LE t2(a,b)$…..|

000007e0 20 74 68 65 20 73 68 6f 77 15 01 03 01 2f 01 6f | the show…./.o|
000007f0 6e 65 20 66 6f 72 20 74 68 65 20 6d 6f 6e 65 79 |ne for the money|

~ $ sqlite3 sqlcipher.db
sqlite> PRAGMA KEY=’test123′;
sqlite> CREATE TABLE t1(a,b);
sqlite> INSERT INTO t1(a,b) VALUES (‘one for the money’, ‘two for the show’);
sqlite> .quit

~ $ hexdump -C sqlite.db
00000000 84 d1 36 18 eb b5 82 90 c4 70 0d ee 43 cb 61 87 |.?6.?..?p.?C?a.|
00000010 91 42 3c cd 55 24 ab c6 c4 1d c6 67 b4 e3 96 bb |.B?..?|
00000bf0 8e 99 ee 28 23 43 ab a4 97 cd 63 42 8a 8e 7c c6 |..?(#C??.?cB..|?|

~ $ sqlite3 sqlcipher.db
sqlite> SELECT * FROM t1;
Error: file is encrypted or is not a database

(example courtesy of SQLCipher)

Details for Developers

We’ve packaged up a very simple SDK for any Android developer to add SQLCipher into their app with the following three steps:

  1. Add a single sqlcipher.jar and a few .so’s to the application libs directory
  2. Update the import path from android.database.sqlite.* to info.guardianproject.database.sqlite.* in any source files that reference it. The original android.database.Cursor can still be used unchanged.
  3. Init the database in onCreate() and pass a variable argument to the open database method with a password*:
  • SQLiteDatabase.loadLibs(this); //first init the db libraries with the context
  • SQLiteOpenHelper.getWritableDatabase(“thisismysecret”):

*Note: we are working on some dialog builder helper methods for password and PIN input, password caching, and other features that we would like to standardize across all applications that use SQLCipher.

Compatibility

The Developer Preview implements SQLCipher v1, is compatible with Android 2.2 & 2.3, and works only within one process (you can’t pass a Cursor from a remote Service to an Activity).

Notepad + SQLCipher = Notepadbot

Notepadbot is a sample application pulled from the standard Android samples code and updated to use SQLCipher. You can browse the source here and download the apk here.

Final Notes

It’s important to note that this project is not intended to be a distinct, long-term fork of SQLCipher. We’ve been working closely with the SQLCipher team at Zetetic and fully intent to closely maintain the project as SQLCipher evolves, re-integrating changes in upcoming releases such as SQLCipher v2.

The Android support libraries are licensed under Apache 2.0, in line with the Android OS code on which they are based. The SQLCipher code itself is licensed under a BSD-style license from Zetetic LLC. Finally, the original SQLite code itself is in the public domain.

Downloads and Source

Our Foolish Hackday!

We had a great group of people show up at our April 1st “Don’t Be Fooled” Hackday here at the OpenMobileLab in New York. There were users, there were devs, and all sorts of other people in between. We tracked some of the brainstormed ideas on an open etherpad at: http://piratepad.net/bQPFn6FOhN (text of this pasted in below).

The main outputs of the hacking were LilDebi, an updated Debian installer for Android, the beginnings of a Bitcoin digital currency client, and another called UpOn App, which uses the accelerometer and white noise generators in the device to stop your cellphone from spying on you.

Thanks to all for coming, and hope you enjoyed the donuts and beer!

 

 

The Pirated Pad Hackday Idea Tracker!
I. UpOn
  • phone that goes on and off airplane mode, based on gyroscope face up and down
Research
  • need to look into e911 requirements
  • is Airplane mode a don’t broadcast, but receive is on type mode?
  • can we detect radio signals at all
  • scanning engine for radio communications (cv ettercap)
Ideas
  • Kickstarter projects for faraday cage mobile phone case
  • little phone ornament that lights up on radio signals (they have these today!)
      • discuss the kickstarter project for designing a faraday cage mobile phone case… or did someone already do that?
      threats
      • can baseband exploit / lawful intercept activate on report
      • habitual paranoia
      • create a physical switch on the battery cover
      • sell faraday cases cell phone
      • turn off and on the phone , but necessarily super protect
      II – Anonymous Currency [BitCoin]
      a. Bitcoin for Android
      • Android BitCoin wallet
      • qrcodes for half-offline transactions
      b. Bitcoin in General
      • Laundromat to maintain anonymity of BitCoin pseudonyms
      • trust laundromat a few cents at a time
      • trade keys in realishtime
      III Building CyanogenMod from Source!
      • Seems like a fun experiment for the day
      • Can we drop in SQLCipher?
      • Possibly work on exploring OWNER module issues with current kernel
      • Yes, we need to figure out how to dynamically load kernel modules
      IV. Debian Autoinstaller
      • can you simplify the installer in the market
      • checkout the QT market installer
      V. How to Build Stuff
      • Gradle for building apps, or “ant release”
        VI. Port Ghostery to Firefox for Android
        • blocks cookies, tracking, etc
        VII Securely Reporting Photo/Video/Audio