3 ms·
I think requirement 2 is a problem here. If your cloud provider has the plaintext how can you trust it?
by ghubbard 14y ago
I think requirement 2 is a problem here.
If your cloud provider has the plaintext how can you trust it?
- josephby 14y agoThe solution doesn't have to protect against intercept-in-transit. For example, suppose that this was implemented on a VPS on some random hosting provider, and I own all of the code on the VPS. The hosting provider could record all email traffic coming into that box, but that problem isn't in scope (and could be addressed with, say, openPGP).
- ghubbard 14y agoJust store your mail in an EncFS or truecrypt container on your VPS then? Who/what are you trying to defend against?
- josephby 14y agoThat might work; can either of these be configured with separate encrypt and decrypt keys? Basically, if someone takes control of the hardware or software we're hoping that it would still be very difficult to get at the contents of the emails.