3 ms·
I'm not sure I buy the reasoning on "surface area", at least not the specific comparisons in the article. It seems unfair to count Chrome but not Unix. For th
by methehack 11y ago
I'm not sure I buy the reasoning on "surface area", at least not the specific comparisons in the article. It seems unfair to count Chrome but not Unix. For that matter, shouldn't we count the surface area of everything that touches the email as it hops around, including routers, etc? And isn't that the whole problem with email that the protocol does not require secure transport? So, seems like the only way to make that even vaguely secure is to use PGP (or something) on top, in which case who cares about mutt...
- mike_hearn 11y agoRight. "Let's switch from an email client written in a safe high level language that's also running inside multiple sandboxes and which has a full time security team (e.g. gmail) to ...... a mail client written in C" Doesn't seem like a great approach.
- sahara 11y ago(Preemptive N.B.—I'm far from an expert, but I'm very interested in seeing this aspect of the topic discussed further by folks who might be experts.) Isn't the general premise here that one can choose to package up any program in as many deeply nested (virtual or physical) sandboxes as one would like, but there's an inherent benefit to the piece of software inside all those boxes exposing to one's adversary as few avenues as possible to attempt to escape them (specifically as it pertains to people in the business of painting targets on their backs e.g. Soghoian)? Put another way, of course Gmail and Chrome have dedicated security teams, but they won't ever have prevent $GIVEN_INFOSEC_RESEARCHER's box from getting owned teams.
- benmmurphy 11y agoC is not too bad in this situation. If you implement DEP + ASLR correctly and do not give the attacker access to an interpreter (javascript/fonts/xslt/etc) then it is quite difficult (impossible except for luck?) for an offline attacker to gain code execution. You need to leak information about the programs memory layout in order to bypass DEP but how do you do that with an email? The best vector is probably taking control of the IMAP/POP server Mutt is connecting to and finding a vuln that will leak an address back to the server and another vuln that will take control over the instruction pointer. Or alternatively hope there is some broken shell command injection lurking in Mutt.
- siegecraft 11y agoYou want to reduce the "surface area" of your email client so that the act of viewing an email doesn't own your system. It has nothing to wo dith the privacy of your email.