3 ms·
> Running your own SMTP server at home is a pain in the ass, so it will never be widely adopted. It is, but it doesn't have to be. Someone could make a <$100 d
by anf 10y ago
> Running your own SMTP server at home is a pain in the ass, so it will never be widely adopted.
It is, but it doesn't have to be. Someone could make a <$100 device which has a power backup for running through power outages and a backup network connection via the cellular network, which should provide high enough uptime for all practical purposes. Messages between mail servers are encrypted most of the time, more and more so every year [1]. This is a technical solution for a legal problem, though.
I'm not sure if I understand the system you are proposing, but email protocols seem secure enough now as they are now, it's just the third party principle that doesn't align with the obvious expectations of privacy in mail [2]. To me, it's pretty clear that my email account is like a PO box. Just because my email is held by a third party doesn't make it any less private than being delivered to my home, just as mail arriving at a "third-party" PO box isn't all that different from my mailbox.
1. https://www.google.com/transparencyreport/saferemail/ https://www.google.com/transparencyreport/saferemail/
2. http://techcrunch.com/2014/04/30/google-will-also-stop-scanning-google-apps-inboxes-for-ads/ http://techcrunch.com/2014/04/30/google-will-also-stop-scann...
- civilian 10y agoHuh. I like your PO Box analogy. We should get the USPS to run mail servers.
- mindslight 10y agoIt is not "a legal problem". It is a problem with legal, technical, governance (and probably more types of) approaches. If you're working on a legal solution I'll support you, just like if someone else succeeds in neutering the traitors in DC/VA, I'll cheer them on. But I am not a lawyer nor a soldier, so I'll remain focused on finding technical solutions. Protocols "seem" secure enough, because you don't seem to be focused on the technicals (which is fine, as per what I just said. Just don't nay-say). For example, even if messages are encrypted between servers, the graph of who is talking to who is still revealed to a passive adversary, and this problem only gets worse with individually-run servers.
- anf 10y agoHiding "who is talking to whom" against a global passive adversary is an active area of research and I don't know of any solution that is backwards compatible with email. Is this so of the one you are suggesting?