7 ms·
> If you want encryption, don't use email. That's total nonsense. > Search isn't possible It absolutely is, in both theory and practice. The server stores an
by unknownsavage 10y ago
> If you want encryption, don't use email.
That's total nonsense.
> Search isn't possible
It absolutely is, in both theory and practice. The server stores an encrypted index, and the client walks it (requesting parts as needed). It's going to little slower, and a lot more complex but it's doable.
> If you lose your private key, we can't recover your email
This is a damn feature. I had my icloud account social engineered (someone walked into an apple store claiming to be me and they couldn't get their iphone syncing to "their account"). I'll never again trust another company with my private stuff.
> Spam checking on content isn't possible
This is probably your best point. It's definitely harder to do well
> To access mail on multiple devices, the private key needs to be shared securely between them
This is a non-issue. It can easily be derived from a password
- mtgx 10y agoAlso search that only uses email titles is still at least 70% as useful as full title+body search. So I wouldn't count this as such a terrible non-feature of e2e encrypted email.
- EdHominem 10y agoOnly if you leave juicy content in the unencrytped subject. Also, "What? subjects and recipients are unencrypted!?" -- Every User Ever
- sdenton4 10y agoYou can encrypt the metadata on the server, and enable local search on the metadata to avoid keeping the full mailbox on a phone, for example
- FunnyLookinHat 10y ago> > Spam checking on content isn't possible > This is probably your best point. It's definitely harder to do well I think it's possible, just slower and more complex (like search) - and would have to occur upon unlocking your inbox.
- amenghra 10y agoYou can mostly get rid of spam by requiring the sender to perform a proof of work if they aren't in your contacts list. I.e. whitelist of senders + proof of work or some kind of configurable per domain quota/proof of work.
- askmike 10y agoI guess that gets rid of all other email as well..
- dexterdog 10y agoHow often do you get email from somebody that you've never gotten email from before?
- gtCameron 10y agoExactly once for each contact that has ever sent me an email
- ardivekar 10y agoMaybe a two-way 'add contact' feature would be useful, like a facebook friend request.
- eriknstr 10y agoSure but then it's not standard e-mail any longer.
- e12e 10y agoI remember having a server side system for generating cryptographic email aliases along the lines of: base64encode(hmac("new-sender@example.com+valid-to+01012018", key))+user@mydomain.com Truncated to something like fvv544+user@mydomain.com that would only be valid when sent with the from-adress new-sender@example.com (along with some clever magic to avoid email loops! :-) I think maybe it was authored by ESR (Eric Raymond) in python - but Google only turns up various dkim schemes... New senders would have their mail held back, and get a "please reply if you are human"-message - a reply (to the "magic" reply-to alias) would release the held mail and whitelist the sender. A greylist variant of sorts.
- baudehlo 10y agoFwiw search that way is (I think) patented by Proofpoint. So it might be hard to implement.
- kmonsen 10y agoIt is smart to not speculate on patents. You have now possibly poisoned everyone reading this thread.
- baudehlo 10y agoIf patent law worked like coodies that comment would be awesome.
- gregshap 10y agoThe interpretation of IP law, at least internally at many big software companies, does in fact work like coodies. Hence things like "clean room implementations" of algorithms, modules, API interfaces etc.
- vidarh 10y agoClean room matters for copyright. It doesn't help for patents, as patents protects the idea, not the expression of it so expressing the same idea in a different way doesn't help. With a patent you want to know the specifics of the original to ensure you make yours sufficiently different to sidestep the claims. Where not knowing helps with patents it is in that if you infringe, wilfull infringement increases damages up to threefold.
- vidarh 10y agoWillful infringement allows the court to give judgements for up to triple compensatory damages in the US, so sometimes not knowing can be valuable.
- bigbrooklyn 10y agoThese are just minor problems. End to end encryption should not be forced upon users, but should be used selectively. You don't want to lose your entire inbox because you wanted to send a few encrypted emails. > The server stores an encrypted index, and the client walks it (requesting parts as needed). It's going to little slower, and a lot more complex but it's doable. How slow would this be with thousands of emails on a mobile device ? > This is a damn feature. I had my icloud account social engineered (someone walked into an apple store claiming to be me and they couldn't get their iphone syncing to "their account"). I'll never again trust another company with my private stuff. Most email providers don't have retail stores where this type of attack can happen. > This is a non-issue. It can easily be derived from a password What happens if this password got into the wrong hands or even lost? Is it possible to change? Must I re-encrypt every single email ?
- sulam 10y ago> Most email providers don't have retail stores Lots do, though, and the ones that don't often offer customer support over the phone. And anyway, social engineering doesn't only happen in stores or when talking to CS.
- Neliquat 10y agoReally? Name any of the top 10 email providers that have stores, or a responsive 800 number for email support. I'll give you Apple, but they are the clear outlier. MS, Google, have stores, but not with email support, and questionable phone support at best for any non enterprise product.
- sulam 10y agoAT&T? I don't have a list of top 10 email providers, but them and Verizon and Yahoo have all had people report social engineering attacks against them to gain access to accounts.
- DrJosiah 10y ago> How slow would this be with thousands of emails on a mobile device ? Not that much slower than email is now. A B+tree index of (for example) 1 gb of total content and index is only about 1-2 gigs in size. You could just store that shit on your phone encrypted. Or 1-5 megs of index on your phone, with 2 round-trips for any email/first page search result per word. > What happens if this password got into the wrong hands or even lost? Is it possible to change? Must I re-encrypt every single email ? Overall yes, re-encryption is necessary. But that can be a batch process done while your phone is charging and on wifi over night. Is a drawback, but re-keying always is. But just because you got to change the keys every once in a while, doesn't mean you toss the locks.
- eternalvision 10y agoRegarding Apple and security, their policy via AppleCare seems to be to ASK (over the phone, for instance) for your cleartext computer administrator password before you send in your laptop for repair, without any warning whatsoever of the implications.
- TheOsiris 10y agoI spilled soda on my mac once, and took it to the repair shop. the receptionist there asked me for my password. I laughed and I said of course not. she was shocked and asked: well, how are we going to test the new keyboard. I don't know maybe try to type random things in the password field?
- true_religion 10y agoWhat if they install the keyboard but the drivers fail? Won't they need the admin password in order to complete the job?
- vertex-four 10y agoIf a keyboard needs drivers other than USB-HID, someone's doing something wrong.
- sandworm101 10y agoI thought that too, until i bought a cheap netbook that came with windows (7? Student edition? I cannot remember). I plugged in a mouse and windows said it needed to connect to the internet to download the driver for my MS optical mouse. I practically fell out of my chair laughing.
- dagw 10y agoThe "driver" is for adding a gui for doing things like customizing buttons and sensitivity and stuff, not to make the basic mouse work.
- brianpgordon 10y ago> > Search isn't possible > It absolutely is, in both theory and practice. The server stores an encrypted index, and the client walks it (requesting parts as needed). It's going to little slower, and a lot more complex but it's doable. Are you suggesting that to search your mailbox, the client should download every single encrypted message in the entire mailbox and decrypt them all locally to search them? If not, how does the server get this "encrypted index" without having your private key?
- dleslie 10y ago> > Encrypted Index This is not the same as the content.
- drdaeman 10y agoWell, the client has to fetch message once, decrypt it, and upload updates to the index (kept on server). I guess, it is a reasonable sacrifice for privacy, unless you want searches to be able to search within attachments including documents in big archives.
- Groxx 10y agoIt's still likely too large to really consider for mobile use, but yes - far better than downloading everything.
- quanticle 10y agoThe search doesn't happen on the server. The client (e.g. desktop client) indexes the messages and encrypts the index. Then, when another client (e.g. mobile client) wants to search for a message, it downloads the index, searches it, and then pulls down the appropriate message(s).
- ynik 10y agoIf an attacker can tell which part of the index was modified, that gives them enough information to decrypt the index and e-mails. Clients would always have to download+upload the full index (which needs to be re-encrypted with a new IV). This is a huge problem - the index can easily be hundreds of MB for a large mailbox.
- HappyTypist 10y agoAdding to the iCloud story, I forgot my security questions and I was able to have the AppleCare agent over the phone reset it for me after talking about what apps I've purchased recently.
- granda 10y agoI have experience at Apple with Account Security and that's a clear violation of SOP. That's a coaching opportunity for the advisor.
- hackuser 10y ago> I have experience at Apple with Account Security and that's a clear violation of SOP It should be technically impossible. If it's a matter of choice for tech support reps, it's not secure for many reasons.
- wheelerwj 10y agoIt's icloud, not personal device storage. It has to be possible if you want recoverable content. If you don't like it, you can back up locally to itunes.
- wfunction 10y ago> The server stores an encrypted index, and the client walks it (requesting parts as needed). It's going to little slower, and a lot more complex but it's doable. Going on a tangent, but do you know of any services that offer such a thing?
- Groxx 10y ago> > To access mail on multiple devices, the private key needs to be shared securely between them > This is a non-issue. It can easily be derived from a password How does that change the equation? You're still exposing the thing-that-decrypts to multiple devices, thus (many!) more threat vectors. Lose one, and you lose them all, which is the point of the claim.
- danielpatrick 10y ago...so use unencrypted email? The point is, some is better than none. More is better than some. So many people here pointing out holes that make it worse than a theoretically perfect system even though it's leagues ahead of where we are now.
- Groxx 10y agoNo, the (implicit) point in the start of the thread is that multiple other encrypted mediums don't leak as much. Use them instead. If you care enough to use encrypted email, you should probably seriously consider abandoning email. (signing is different - that's proof of identity and non-modification, useful in many non-private scenarios)
- fiatpandas 10y ago>I had my icloud account social engineered (someone walked into an apple store claiming to be me and they couldn't get their iphone syncing to "their account") Were you using 2-factor?