5 ms·
It wouldn't be resilient to interception of mail going to and coming from lavabit however, since email is essentially a plaintext public protocol.
by computer 13y ago
It wouldn't be resilient to interception of mail going to and coming from lavabit however, since email is essentially a plaintext public protocol.
- marssaxman 13y ago...which is why you encrypt the contents before you send it, yes?
- wmf 13y agoConsidering that most other people don't use email encryption, no.
- jethro_tell 13y agoThis is why the speculation that even with encrypted emails, to and from address is in the clear and that could be valuable info to government. So we're back to meta data in plain text both in transit and storage.
- devindotcom 13y agoWhat? I don't think this is true at all. Plaintext data, email or not, can be protected with robust encryption. Your end security is the main consideration, but that has nothing to do with the protocol or content, really.
- jarrett 13y agoThe difficulty is that most recipients of your message will not be willing to use whatever crypto technology you've chosen. PGP is probably the most popular email encryption system, but good luck finding people who use it. I work in the software industry, and I don't regularly correspond with a single person whom I know to use PGP.
- grey-area 13y agoIt'll be interesting to see whether companies start to shift to using encrypted email over the next few decades - it's not that hard to set up if you know the counterparty will be using encryption of the same kind, and if it's not a service bought in from an external company you can fairly sure it is secure. Companies could at least insist that intra-company email is encrypted, which would be a huge amount of their normal communications, and then extend that outside their boundaries with partners who also accept (say) S/MIME. At present I sign my mails but like you have no clients who use encryption.
- SoftwareMaven 13y agoKey exchange is still a huge issue. Sure, you can post a public key online, but I have no guarantee it is actually your key. How do I do business with somebody new? The core problem with widespread crypto use today is not encryption, it's trusted key exchange.
- ashray 13y agoThis is a really interesting problem that needs to be solved. We need some sort of P2P secure protocol to exchange keys between people. Bypassing all sorts of stuff and connecting directly and sharing over an encrypted channel. This sounds really tough the way the internet works right now but I think solutions will come up now that there is a real need for them.
- icebraining 13y agoPut the fingerprint in your business cards? In fact, maybe we finally found a reasonable use for QR codes.
- mr_spothawk 13y agoThat's a cool idea. I'm totally gonna do that :)
- rdl 13y ago
- casca 13y agoThis is somewhat true. RFC3207[1] describes opportunistic TLS encryption for SMTP communications. Our postfix deployment uses this and a fair amount of our email is sent over TLS-encrypted SMTP. Of course, an MITM attack could hide the STARTTLS option and there are questions around the strength of the CA cert infrastructure, but SMTP is not just plaintext. [1] https://tools.ietf.org/html/rfc3207 https://tools.ietf.org/html/rfc3207
- kgo 13y agoThe problem is that you don't sent to the destination SMTP server. You send to your SMTP server. That goes at least one hop via SMTP and eventually ends up on the destination's domain server. So even if I setup and host my own SMTP server, and even if I verify the TLS certs on my side, I have no way to verify that I'll get (1) A TLS connection (2) with an authenticated cert all the way to the ultimate destination. It's beyond my control to ensure that I'm secured when emailing to an arbitrary domain with arbitrary configuration.
- mtrimpe 13y agoIt's quite likely however that Lavabit, being a service that focusses on privacy, delivers enough emails directly to the target server over a secure protocol to cause problems for the NSA in this investigation.
- sneak 13y agoThe problem is that all of the people you correspond with use gmail, which participates in PRISM. No amount of transport encryption or storage encryption on your own end will stop Google from sharing that data with US authorities.
- MrKurtz 13y ago"Participates" is the wrong characterisation, they are under the jurisdiction of FISA orders, if the NSA wants to call that PRISM, it's their business. Also worth mentioning is that providers in non-US countries are subject to their respective country's surveillance efforts, so either way it's a red herring argument.