2 ms·
I think that is the point, a Googler who is moonlighting for spooks in any country can spy on their behalf. In other words, people are cautiously pointing out i
by CodeWriter23 9y ago
I think that is the point, a Googler who is moonlighting for spooks in any country can spy on their behalf. In other words, people are cautiously pointing out it is not “only someone with the key” who can gain access to your emails.
- dpark 9y agoI get that, but an account “reset” is always possible. Even if Google encrypted all of your mail and other content with a key you exclusively control, it would always be possible to simply drop the encrypted data, update all keys/passwords, and regain access to any incoming email. This is a smaller attack surface but still significant. It’s also not actually possible to be an email provider and have no access to read plaintext and the point of send and receive. It can be encrypted at rest but you have to allow read for transmit which means a Googler working for the “spooks” could simply intercept there instead of at rest.
- camiller 9y agoWell, you should be able to encrypt the subject/body of the email without encrypting the headers, so the mail vendor never sees the content of the email, only the to/from addresses and such. But that encryption has to happen in the browser/application. ie Mailvelope plugin for Chrome and others like it. and I think there is an android mail client that will also do pgp/gpg encryption/decryption.
- dpark 9y agoSure. You could absolutely have an entirely different protocol that doesn't work with all the existing email clients/services out there. It's certainly been done multiple times. Obviously it's not caught on, though, because compatibility is sort of a big deal.
- CodeWriter23 9y agoI agree with your point. I also feel people think this is a panacea. The reality is this will just move the attack vector from phishing or key logging to an HID server feature in RAT software.