8 ms·
If you NEED encryption, don't use email. From: https://blog.fastmail.com/2016/12/10/why-we-dont-offer-pgp/ https://blog.fastmail.com/2016/12/10/why-we-dont-off
by bigbrooklyn 10y ago
If you NEED encryption, don't use email.
From: https://blog.fastmail.com/2016/12/10/why-we-dont-offer-pgp/ https://blog.fastmail.com/2016/12/10/why-we-dont-offer-pgp/
What's the tradeoff?
If the server doesn't have access to the content of emails, then it reverts to a featureless blob store:
Search isn't possible
Previews can't be calculated
If you lose your private key, we can't recover your email
Spam checking on content isn't possible
To access mail on multiple devices, the private key needs to be shared securely between them
update:
want->NEED
- Dolores12 10y ago>Spam checking on content isn't possible How does encrypted spam work? Spammers encrypt message with your public key?
- mike-cardwell 10y agoAt the moment, encrypted spam doesn't exist. But only because there aren't enough people using encryption to make it worthwhile for the spammers to invest time doing it. Theoretically, a spammer could scan the public keyservers for email addresses and public PGP keys and then send encrypted spam to all of those people. If ever a well targeted spam mailshot was sent, that would be it. But would you really want to get on the bad side of thousands of tech nerds?
- imaginenore 10y agoSearch and previews should be possible on the client side, but then you need a standalone app, not a web interface.
- bigbrooklyn 10y agopossible, but very expensive even on small datasets
- Alex3917 10y agoSearch is still possible. You can stem words and store their weights without storing the actual unencrypted text. This isn't perfect security, but it's good enough that it would be difficult for the government to successfully use the search metadata in a case against you without a lot of other evidence. This is what we do on FWD:Everyone for email threads shared within private repositories.
- hiddencost 10y agoDO NOT DO THIS. Statistics is more powerful than you'd expect. Also, the wrong rare word could absolutely be grounds for a very intrusive warrant.
- Alex3917 10y agoSecurity is rarely good or bad in an absolute sense, but rather is judged by considering the assets under protection and the threat models you're protecting against. Just because certain people need the sorts of protections provided by Lavabit doesn't mean that products like Gmail are bad or insecure. They're each secure for the use cases they're targeting.
- simcop2387 10y agoI've never tried it but I'd bet you could use instead use a key derived from the master somehow to salt a hash for all the stems too. I think that'd let you still do the search and possibly have a good index for it still but it'd add some hurdles to the whole thing so that you couldn't make a lot of good guesses about the actual contents of the emails. It would still leak information a out related emails (say there's a thread discussing a unique term in it), but it'd still be better than otherwise.
- Alex3917 10y agoIn theory you could HMAC all the stems, but at that point you really need to ask yourself what threat model you're trying to protect against. E.g. keeping only the stems is more than enough to prevent competitors from learning anything useful about your business if your database gets compromised, but using an HMAC probably isn't going to significantly slow down a state-level actor who has a warrant or zero day for your web servers. So on the balance I think the technical debt that would be introduced would likely make the overall system less secure, at least for most use cases.
- leonatan 10y agoDon't forget "authorities can't snoop your mails and will take us to court because we can't decrypt it."
- kybernetyk 10y agoWell, you could always use an old school local email client and would get search and previews for free. And some 3rd party not being able to "recover" my private correspondence sounds more like a feature than an issue.
- drdrey 10y ago> Spam checking on content isn't possible But it's still possible to fight spam based on other features: https://atscaleconference.com/videos/how-whatsapp-reduced-spam-while-launching-end-to-end-encryption/ https://atscaleconference.com/videos/how-whatsapp-reduced-sp...
- unknownsavage 10y ago> If you want encryption, don't use email. That's total nonsense. > Search isn't possible It absolutely is, in both theory and practice. The server stores an encrypted index, and the client walks it (requesting parts as needed). It's going to little slower, and a lot more complex but it's doable. > If you lose your private key, we can't recover your email This is a damn feature. I had my icloud account social engineered (someone walked into an apple store claiming to be me and they couldn't get their iphone syncing to "their account"). I'll never again trust another company with my private stuff. > Spam checking on content isn't possible This is probably your best point. It's definitely harder to do well > To access mail on multiple devices, the private key needs to be shared securely between them This is a non-issue. It can easily be derived from a password
- mtgx 10y agoAlso search that only uses email titles is still at least 70% as useful as full title+body search. So I wouldn't count this as such a terrible non-feature of e2e encrypted email.
- EdHominem 10y agoOnly if you leave juicy content in the unencrytped subject. Also, "What? subjects and recipients are unencrypted!?" -- Every User Ever
- sdenton4 10y agoYou can encrypt the metadata on the server, and enable local search on the metadata to avoid keeping the full mailbox on a phone, for example
- FunnyLookinHat 10y ago> > Spam checking on content isn't possible > This is probably your best point. It's definitely harder to do well I think it's possible, just slower and more complex (like search) - and would have to occur upon unlocking your inbox.
- imglorp 10y agoI would argue the biggest downside to encrypted email is the sender, recipient, date, and size are known to all intermediaries. First of all, sometimes knowing who you talk to is more important than knowing what you say. Traffic analysis lets you draw all kinds of conclusions. Secondly, there are two parties, so double the chances for rubber hose cryptography. An opponent can approach either party and ask for details, so both parties are trusting the other can't be broken by the opponent. Of course, we should all be encrypting everything anyway, no point in giving out free message bodies.
- dexterdog 10y agoIf you don't trust the other party you should not be sending him sensitive data. He has to be able to see it so of course he will be able to reveal it.
- alephnil 10y agoIt is not that you don't trust your party, but that anyone with access to the servers or network between you can learn about who you are communicating with and when. Such metadata are often more useful to use against someone than the actual content.
- revelation 10y agoGee, if only we could execute code on the client! That would be very empowering in this situation. I guess it's not possible, then.
- kobeya 10y agoThis is all ridiculous. Download, index, and process your mail locally. Problem solved.
- KirinDave 10y agoIf we had more systems capable of resisting a local search and seizure this might be the case but as it stands almost none do.
- nickpsecurity 10y agoOh no, you're describing the solution rather than the problem: a global search, copy, and seizure converted to a local one that happens on per-target basis. Way better than mass collection with FISA warrants and systems like QUANTUM.
- wheelerwj 10y agoIs QUANTUM the Swedish one or is there a new one?
- nickpsecurity 10y agoIt's the NSA system that operates globally that can automatically fire attacks at systems based on patterns the operations people put in. Almost all the European countries are part of a SIGINT-sharing alliance per one slide. The exceptions were Switzerland, Iceland, and one I can't remember.
- jasonkostempski 10y agoI think email needs to stop being treated like a database. It should be used for sending and receiving messages, the rest should be handled by other software... like a database for example.
- pmontra 10y agoI'm downloading my mail from POP3 servers, so I'm searching locally. I'm copying access password to my tablet and phone (K9 client) and I don't keep more than a few dozen of messages there because the POP3 mailboxes are cleaned up when I download from the laptop. I backup my mail to a remote server, encrypted with duplicity. I understand that this is not acceptable for 99.99+% of people, even the technical ones, but I think I could use a fully encrypted mail store. No problem with the mail provider ending up as a blob store: privacy-wise it's what they should be anyway. No harm to their business, if all the money they make are from users and they're not selling data. The only problem is centralized spam checking. Running an antispam engine locally wasn't very effective years ago and Thunderbird was sub par. Is there anything that's on par with email providers right now?
- Sami_Lehtinen 10y agoI personally think it's funny that people mix secure communication and email. Secure system should be built to be secure. Email isn't a good option for that. Most systems are designed to be insecure and email is just a great example.