4 ms·
I don’t think the magic cookie was anything deliberately complex, but you’re right that guessing wouldn’t have been very practical.
by TomVDB 5y ago
I don’t think the magic cookie was anything deliberately complex, but you’re right that guessing wouldn’t have been very practical.
- dredmorbius 5y agoIn the early 1990s, all email was plaintext and transports were unencrypted. In the very early 1990s, PGP didn't exist, and the odds that the email content was independently encrypted were low. Any network sniffer or filesystem access would have exposed the cookie.
- Gys 5y ago> the early 1990s, all email was plaintext and transports were unencrypted. I thought all email is still plaintext? The protocol does not support encryption?
- dredmorbius 5y agoI was trying more to cover the distinction between in-flight and at-rest encryption rather than imply that contents are routinely end-to-end encrypted now. That's sometimes but not always the case. There is an increasing use of encryption-at-rest services (AFAIU Gmail is, though that's using a system-level, not user-level, key). There are some encrypted email services (e.g., Protonmail), in which contents are encrypted both in-flight and at-rest. Not especially relevant to the anecdote here, but a critical concern for messaging opsec: email metadata, including sender, receiver, and subject, are not encrypted at rest or to the originating, receiving, and possibly transit systems, may also leak information, and are often more valuable and useful than contents themselves. I find myself wondering if my correspondents who can't seem to provide contextually useful subject lines are actually doing me a favour, despite the annoyance factor ....
- JeremyNT 5y agoSMTP over TLS is very common today. It's not guaranteed, but many emails sent between major providers should actually be encrypted in transit. Gmail actually flags email that was received without TLS with a little red icon indicating its relative insecurity. Back in the 90s, though... not so much.
- dredmorbius 5y agoSMTP over TLS is first proposed in RFC 2487, dated January of 1999, AFAIU. https://datatracker.ietf.org/doc/html/rfc2487 https://datatracker.ietf.org/doc/html/rfc2487 Actual widespread implementation didn't occur until the 2010s. STARTLS Everywhere launched in 2014. https://www.eff.org/deeplinks/2020/04/winding-down-starttls-everywhere-project-and-future-secure-email https://www.eff.org/deeplinks/2020/04/winding-down-starttls-... Google have tracked the prevalence of TLS-based email connections ... since 2014: https://transparencyreport.google.com/safer-email https://transparencyreport.google.com/safer-email