This article will self-destruct: A tool to make online personal data vanish (w/ Video)

July 21, 2009 Vanish + Google Docs

Enlarge

Vanish + Google Docs

Computers have made it virtually impossible to leave the past behind. College Facebook posts or pictures can resurface during a job interview. A lost cell phone can expose personal photos or text messages. A legal investigation can subpoena the entire contents of a home or work computer, uncovering incriminating, inconvenient or just embarrassing details from the past.

The University of Washington has developed a way to make such information expire. After a set time period, electronic communications such as e-mail, Facebook posts and chat messages would automatically self-destruct, becoming irretrievable from all Web sites, inboxes, outboxes, backup sites and home computers. Not even the sender could retrieve them.

"If you care about privacy, the Internet today is a very scary place," said Tadayoshi Kohno, a UW assistant professor of computer science. "If people understood the implications of where and how their e-mail is stored, they might be more careful or not use it as often."

The team of UW developed a called Vanish that can place a time limit on text uploaded to any through a Web browser. After a set time text written using Vanish will, in essence, self-destruct. A paper about the project went public today and will be presented at the Usenix Security Symposium Aug. 10-14 in Montreal.

Co-authors on the paper are doctoral student Roxana Geambasu, Kohno, professor Hank Levy, and undergraduate student Amit Levy, all with the UW's department of computer science and engineering. The research was funded by the National Science Foundation, the Alfred P. Sloan Foundation and Intel Corp.

"When you send out a sensitive e-mail to a few friends you have no idea where that e-mail is going to end up," Geambasu said. "For instance, your friend could lose her laptop or cell phone, her data could be exposed by malware or a hacker, or a subpoena could require your e-mail service to reveal your messages. If you want to ensure that your message never gets out, how do you do that?"

Many people believe that pressing the "delete" button will make their data go away.

"The reality is that many Web services archive data indefinitely, well after you've pressed delete," Geambasu said.

Simply encrypting the data can be risky in the long term, the researchers say. The data can be exposed years later, for example, by legal actions that force an individual or company to reveal the encryption key. Current trends in the computing and legal landscapes are making the problem more widespread.

"In today's world, private information is scattered all over the Internet, and we can't control the lifetime of that data," said Hank Levy. "And as we transition to a future based on cloud computing, where enormous, anonymous datacenters run the vast majority of our applications and store nearly all of our data, we will lose even more control."

The Vanish prototype washes away data using the natural turnover, called "churn," on large file-sharing systems known as peer-to-peer networks. For each message that it sends, Vanish creates a secret key, which it never reveals to the user, and then encrypts the message with that key. It then divides the key into dozens of pieces and sprinkles those pieces on random computers that belong to worldwide file-sharing networks, the same ones often used to share music or movie files. The file-sharing system constantly changes as computers join or leave the network, meaning that over time parts of the key become permanently inaccessible. Once enough key parts are lost, the original message can no longer be deciphered.

In the current Vanish prototype, the network's computers purge their memories every eight hours. (An option on Vanish lets users keep their data for any multiple of eight hours.)

Unlike existing commercial encryption services, a message sent using Vanish is kept private by an inherent property of the decentralized file-sharing networks it uses.

"A major advantage of Vanish is that users don't need to trust us, or any service that we provide, to protect or delete the data," Geambasu says.

Researchers liken using Vanish to writing a message in the sand at low tide, where it can be read for only a few hours before the tide comes in and permanently washes it away. Erasing the data doesn't require any special action by the sender, the recipient or any third party service.

"Our goal was really to come up with a system where, through a property of nature, the message, or the data, disappears," Levy says.

Vanish was released today as a free, open-source tool that works with the Firefox browser. To work, both the sender and the recipient must have installed the tool. The sender then highlights any sensitive text entered into the browser and presses the "Vanish" button. The tool encrypts the information with a key unknown even to the sender.

That text can be read, for a limited time only, when the recipient highlights the text and presses the "Vanish" button to unscramble it. After eight hours the message will be impossible to unscramble and will remain gibberish forever.

Vanish works with any text entered into a Web browser: Web-based e-mail such as Hotmail, Yahoo and Gmail, Web chat, or the social networking sites MySpace and Facebook. The Vanish prototype now works only for text, but researchers said the same technique could work for any type of data, such as digital photos.

It is technically possible to save information sent with Vanish. A recipient could print e-mail and save it, or cut and paste unencrypted text into a word-processing document, or photograph an unscrambled message. Vanish is meant to protect communication between two trusted parties, researchers say.

"Today many people pick up the phone when they want to talk with a lawyer or have a private conversation," Kohno said. "But more and more communication is happening online. Vanish is designed to give people the same privacy for e-mail and the Web that they expect for a phone conversation."

The paper and research prototype are available online at http://vanish.cs.washington.edu.

Source: University of Washington (news : web)


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 3.9 /5 (17 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • Ethelred - Jul 22, 2009
    • Rank: 4.7 / 5 (3)
    I see the SPAMMER has returned after its account was deleted.

    Which reminds me that we have at least two Spammers that are abusing the PM service. We need a way to shut them off.

    Ethelred
  • SmartK8 - Jul 22, 2009
    • Rank: 1 / 5 (1)
    Ethelred: You mean like a forum psychiatric technician ? By the way, it is funny how he never even drops two lines in his comment. He's still keeping his 50% ratio. I guess, it's a matter of spammer job pride; or whatever.
    Update: I forgot to mention. Amazing concept. I will give it a try and then my own implementation :D
  • RJ32 - Jul 22, 2009
    • Rank: 1 / 5 (1)
    Sounds like a winner.

July 21, 2009 all stories

Comments: 3

3.9 /5 (17 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Security Alert: Beware of SMS Messages That Can Take Control of Your Phone
    created Apr 20, 2009 | popularity not rated yet | comments 0
  • Two Robot Chefs Make Omelets
    created Dec 04, 2008 | popularity not rated yet | comments 0
  • Foldable phone opens into large OLED screen
    created Nov 24, 2008 | popularity not rated yet | comments 0
  • Sign language over a mobile phone
    created Aug 22, 2008 | popularity not rated yet | comments 0
  • Video: Swine flu health tips
    created Apr 30, 2009 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Help with a camera choice
    created Nov 18, 2009
  • casio calculator that's similar to TI-89
    created Nov 08, 2009
  • Advice on what cell phone to get
    created Nov 08, 2009
  • Changing the language options on your phone.
    created Nov 03, 2009
  • HP strange RPN operation???
    created Nov 02, 2009
  • Databases in physics
    created Oct 31, 2009
  • More from Physics Forums - Computing & Technology

Other News

China is the world's largest emitter of the greenhouse gases blamed for global warming

China harnesses mountain wind power

Technology / Energy

created 27 minutes ago | popularity not rated yet | comments 0

In the mountains above the southwestern Chinese town of Dali, dozens of new wind turbines dot the landscape -- a symbol of the country's sky-high ambitions for clean, green energy.


Ubisoft steps up videogame fitness with virtual coach

Technology / Software

created 47 minutes ago | popularity not rated yet | comments 0

French videogame powerhouse Ubisoft will have a virtual fitness coach whipping Wii users into shape starting Tuesday.


Hackers leak e-mails, stoke climate debate

Technology / Internet

created 11 hours ago | popularity 4.3 / 5 (17) | comments 8

(AP) -- Computer hackers have broken into a server at a well-respected climate change research center in Britain and posted hundreds of private e-mails and documents online - stoking debate over whether some scientists have ...


plug-in hybrid electric vehicle

Pulling the plug on hybrid myths

Technology / Energy

created Nov 19, 2009 | popularity 3.8 / 5 (12) | comments 17

(PhysOrg.com) -- Whether you call them myths, urban legends, fables or old wives' tales, there's a lot of misinformation out there about plug-in electric hybrid vehicles. These vehicles, abbreviated PHEVs, ...


UK police make 2 Trojan computer virus arrests

Technology / Internet

created Nov 18, 2009 | popularity 5 / 5 (1) | comments 10

(AP) -- A couple suspected of helping spread some of the Internet's most aggressive computer viruses has been arrested in the English city of Manchester, police said Wednesday.