Inspiration

The motivations for truman are that:

  1. Most of our digital communications nowadays passes through third parties who have questionable views on user privacy;
  2. Most (including myself) are reluctant to switch to more private, distributed platforms due to their lack of certain functionalities, among other problems;
  3. Even if a desirable platform is found, the act of accessing such a platform may arouse unwanted attention in surveillance-heavy countries, or even completely banned.

With truman, we would like to be able to send coded messages that can a) be automatically and deterministically decoded only with the knowledge of a shared secret that is not known a priori, and b) be sent in cleartext over a third-party channel without arousing suspicion over the fact that there may exist a coded message.

The concept of truman as a deniable encryption tool that steganographically hid its messages was heavily inspired by image steganography tools such as OutGuess, as well as the flaws of it. While steganography in images may be detected by analyzing histograms, natural language is much more "natural" and hence variable in terms of generation, leading to analysis techniques on it being less effective; hence the concept of truman. The drawback of our approach is that the amount of data that can be hidden is very small relative to the size of the enclosing data; however, with refinement this can probably be improved considerably.

Etymology

The namesake of truman is former U.S. president Harry S. Truman, who was the first to coin some variant of the term "plausible deniability", used to describe certain aspects of American foreign policy during the mid to late 20th century, specifically its participation in covert operations overseas while denying the existence of such operations.

What it does

truman implements deniable encryption (in the spirit of its name), encoding 7-bit ASCII messages into a larger message which can be transmitted in cleartext through some communication tool (like Discord). As the message is encoded in natural language, it is more difficult to detect whether there is encrypted data hidden in the first place, hence the encryption being "deniable". Key exchange is performed manually by hiding the public key in numeric parameters (which you can, for example, disguise as a conversation on statistics), while ciphertext is embedded in regular, textual messages by modifying the words to use particular synonyms, which are known to both parties from a shared thesaurus (currently under development).

How we built it

The backend was written in C++, making heavy use of OpenSSL for encryption functionality. A frontend in Qt was in progress but was not completed due to time constraints.

Challenges we ran into

The main issues have been time pressure, as well as unsatisfactory documentation of OpenSSL which made implementing encryption more time-consuming than expected. There was also the issue of certain libraries not compiling due to missing headers (probably due to a kernel version difference), which required manually modifying some files to get rid of problems. There was also a decent amount of math involved.

What's next for truman

The natural next step will be to, of course, finish the frontend. Besides that, truman would benefit massively from the development of its own text generation (currently it relies on introducing modifications in user-supplied text); I envision this would be best implemented with a Markov chain text generator, which was certainly outside the scope of what could be accomplished during the time of the hackathon. The ability to automatically import a thesaurus from existing datasets (e.g. WordNet), perhaps using SQLite, would be helpful as well.

Built With

Share this project:

Updates

Submission history