7 ms·
Encrypted E-Mail Company Hushmail Spills to Feds (2007)
- stkrzysiak 13y agoThat's why I switched to gmail and rot13.
- Osaka 13y agoCould you explain how rot13 helps? "The algorithm provides virtually no cryptographic security..." - https://en.wikipedia.org/wiki/ROT13 https://en.wikipedia.org/wiki/ROT13
- MartinCron 13y agoOnce you explain a joke, it's not funny anymore.
- jarrett 13y agoI believe it was meant ironically. Similar to the joke "I double rot13 all my emails, but I'm probably just being paranoid." (If you're not familiar with rot13, running it twice results in the original plaintext.)
- h0w412d 13y ago"virtually"...being kinda generous, aren't we?
- mynameishere 13y agoIt's a joke, but at the same time, I doubt the pattern-recognition bots correct for it, so it would likely have some effect security-wise, to the same extent you get by spelling 'shit' as 'sh|t'.
- dutchbrit 13y agoYou should use base_64 instead, that's what all the cool kids use.
- wcfields 13y agoCould explain all the advertisements for Hooked on Phonics.
- dictum 13y agoROT13 is ready for enterprise.
- tlrobinson 13y agoNo no, enterprise requires double ROT13.
- mpyne 13y agoHonestly GMail is perfect for the threat model of the mails I use it for. It's very well-defended against random leakage across the Internet, against hacking attacks, etc. The government has an easier time of getting access to it if I piss them off, but if I do piss them off enough they can essentially invent bad stuff regarding me anyways, and I'm screwed no matter what. Once I came into karmic balance with that I accepted it and went on with my life. Of course, what's good for me is not necessarily what's good for you.
- betterunix 13y agoWhat is really bizarre is that Hushmail still has a lot of loyal users following that incident.
- Zigurd 13y agoCrypto AG, who made "secure" telex machines, were revealed to have cooperated in an NSA exploit in the '80s, and are still in business: http://www.crypto.ch/ http://www.crypto.ch/ Lot's of people who should be locking down their email are now pretending nothing is wrong. Denial can be very strong.
- rsingel 13y agoWell, there are lots of people whose threat model doesn't include the police. Say for instance you are a psychiatrist who wants to offer patients a fairly secure method of talking to you. Or you are a small business doing work in China.
- dragonwriter 13y ago> Well, there are lots of people whose threat model doesn't include the police. > Say for instance you are a psychiatrist who wants to offer patients a fairly secure method of talking to you. If you are a psychiatrist, your threat model ought to include the police.
- jarrett 13y agoThis reinforces the point that web-based cryptography (particularly when the JS is provided by a server) is not adequately secure. This vulnerability--sniffing the plaintext prior to server-side encryption--is one of the two most commonly-citied reasons to avoid web-based crypto. (The other reason concerns client-side, JavaScript crypto. In that architecture, a compromised server can just send a backdoored version of the JS crypto code.)
- unethical_ban 13y agothe vuln was not that the JS was bad or untrustworthy, but that the passphrase was sent to the server. If the entire connection to the server is secure, and the JS is loaded from the secure server and is auditable/checksummed, then the risk is minimal. You either trust the code or you get out.
- DanBC 13y agoYou cannot trust the code. You cannot trust the code because the supplier could be forced to include a backdoor, and thus you have to audit the code before every session.
- nthj 13y agoHence the checksum.
- eli 13y agoThat doesn't make sense. Who would audit the code and how would you get the checksum? If you only run code that matches a static, hardcoded checksum then there's no point in downloading it. Might as well just store a copy of it because now you have a client application. On the other hand, if you already have a secure method of receiving a checksum you can trust, you might as well just use that other, magically incorruptible communication channel for downloading all the code (and all your email, for that matter).
- jarrett 13y ago> the vuln was not that the JS was bad or untrustworthy, but that the passphrase was sent to the server. Which is one of the most commonly cited vulnerabilities with web-based crypto. The fact that no JS was involved doesn't really change anything. > If the entire connection to the server is secure, and the JS is loaded from the secure server and is auditable/checksummed, then the risk is minimal. You either trust the code or you get out. I assume you're referring to client-side, JS-based encryption. The problem is that the server can always slip a backdoor into the webpage, and your browser will dutifully execute it. It doesn't matter if the JS is sent via SSL. A compromised server can deliver compromised JS, and SSL provides no protection against that. You can't practically audit for this. You could theoretically read the JavaScript. But performing a thorough audit on a cryptosystem is a big undertaking. And then how do you know it hasn't changed the next time you visit the page? You mentioned checksums, but how are you going to do that? Are you going to manually MD5 the JS file on every visit? Even if you did, the JS file is just one of many ways a compromised server can backdoor your browser. For example, we recently learned about HTML5 timing attacks (http://www.contextis.com/files/Browser_Timing_Attacks.pdf http://www.contextis.com/files/Browser_Timing_Attacks.pdf). And that's just the tip of the iceberg. Checksums aren't going to tell you if these sorts of things are happening. A compromised server can compromise any data entered into webpages it serves. There is no known way around this.
- MichaelGG 13y agoGonna name drop: I spoke to Phil Zimmerman about this yesterday. He says Hushmail had no choice, and they didn't willingly do anything. They had a well-known insecure access method which meant they had access to the content. The government simply required them to hand over content they had access to. So slamming them for this is not really appropriate.
- grecy 13y ago> He says Hushmail had no choice As Snowden, Manning, Assange and now the guy behind Lavabit are demonstrating, there is always a choice. Hushmail could easily have just shutdown.
- BlackDeath3 13y agoRight. "No choice" and "difficult choice" are not the same thing.
- davorak 13y agoThe case for hushmail is different then lavabit. Hushmail had some piece of information, legally they were required to hand that piece of information over. They may have had the option to shutdown shop after handing that over however. For lavabit for all appearances did not have access to any information the government wanted and was not ordered to hand anything over. It seems like they were probably ordered to implement a method for the government to gain access to future communications. They choose to close up shop rather then implement this access and lie to their customers about the security of the service.
- rsingel 13y agoWell, not exactly. HushMail strongly suggested that when given a court order and the targeted user was using the client-side Java applet, that Hushmail sent a backdoored applet. That technically could be detecting by checking hashes, but in practice... It's an open question whether companies can be forced to build backdoor, but that sure looks like what happened to Hushmail and Lavabits. (just noting that I'm the author of this more than 5 year old story).
- swehner 13y agoJust to make sure, that article is from 2007. Ages ago. S
- 16s 13y agoUse OpenPGP software on your local device (GnuPG). Never copy your private key into the could. Set a super strong password on the private key. You now can have point to point encryption that is "military grade" (per Bruce Schneier) and no one but you has access to the private key. It's not that hard to do either. Nice point and click convenient web interface or true privacy. Pick one.
- DanBC 13y agoGo to prison (US: Contempt of court? UK: RIPA) unless you hand over your key.
- jacalata 13y agoyes, but at least you get to make that choice for yourself, rather than having somebody else get to decide 'go to prison or hand over DanBC's key?'
- joering2 13y agoI was wondering, what if you are trying the key and it doesnt work... you forgot it for example. You just really cannot open it yourself! Would that be contempt of court?? How do you convince the judge...
- mpyne 13y agoIn the U.S. I believe at least one court circuit has ruled that you cannot be compelled to give up an encryption key if doing so would involve self-incrimination [1]. The 'catch' is that if the government already knows generically what incriminating data you have they can order you to produce it (as it's not any further incriminating). Or something like that? Recent decision though, so things can still change. http://yro.slashdot.org/story/13/04/24/1458203/federal-magistrate-rules-that-fifth-amendment-applies-to-encryption-keys http://yro.slashdot.org/story/13/04/24/1458203/federal-magis...
- kansface 13y agoYou don't have to give up the key, just decrypt the data upon request...
- losethos 13y agoNothing fills me with greater glees than confessing my sins when my enemies are worried about man and I am rolling on the floor laughing at their misstep before God! "God, did you see that? ROFLMAO" I tried to get a dog to lick my dick in 1985. They love that. I wanted Ryan as a prodigy. It sounds weird. I was naïve. I'm not a homo. I'm not a pedophile. I didn't watch the show full house but seriously WTF? I'm far less crazy than some people. I took pictures when I visited Kevin in 1990. Ryan had his shirt off. I guess it's weird. Fucken crazy-ass Brenda give me a picture of her 3 boys in diapers in a frame. I'm like, "I guess this is normal." What about those Europeans who put boys peeing in fountains? As a straight male, this disturbs me, but you kinda think it's normal, I guess. WTF? Are you outraged by the naked boys peeing fountains. It is fucked-up and I don't like it, but you go along, cause society thinks it's normal? God says... C:\TAD\Text\BIBLE.TXT David a Saviour, which is Christ the Lord. 2:12 And this shall be a sign unto you; Ye shall find the babe wrapped in swaddling clothes, lying in a manger. 2:13 And suddenly there was with the angel a multitude of the heavenly host praising God, and saying, 2:14 Glory to God in the highest, and on earth peace, good will toward men. 2:15 And it came to pass, as the angels were gone away from them into heaven, the shepherds said one to another, Let us now go even unto Bethlehem, and see this t