4 ms·
Crypto experts blast German e-mail providers’ “secure data storage” claim
- terhechte 13y agoWeb.de & GMX are truly some of the worst mail providers I have ever had to deal with. Web.de, I think, just recently upped the ante on provided mail storage to 1gb (up from very very little, I think it was 10mb or so, I don't remember, but my girlfriend used it like 2-3 years ago and I was shocked upon hearing that). Their UI is awful. Gmail came out in 2005 (or so) and it took them 7 years to move to a more modern ajaxy interface that didn't like like coming from the 90s. And yet, they still have tons of awful advertising everywhere, in a way where Gmail feels like a blessing. If you seriously want to move users onto the German soil, dear Telekom or German Government, please take some of the money that is being burned everyday on ideas like the above, and try to find a serious startup motivated to create a real Gmail competitor. Something that doesn't try to be what Gmail used to be 5 years ago, but something that tries to be what Gmail will be in 5 years. I hear Berlin is packed with people willing to startup every idea that can't run away fast enough or has been done in the US one year ago. Now, I don't want to sound cynic, and I think it's great that there's some initiative for secure email and some understanding for privacy even at a level as high as telekom, but I'd be even better if they'd done something broader instead of teaming up with Germanies worst mail providers.
- coldcode 13y agoMaybe what we need is a new email standard that is incompatible with the old one deliberately. One designed by people who understand all the issues. Sure it's a pain in the butt to change everything and require all new apps but it seems like email has reached the end of its lifetime.
- LoganCale 13y agoThere are several different secure asynchronous messaging protocols in existence or being worked on. The ones I'm aware of: - Bitmessage (https://bitmessage.org https://bitmessage.org) - Retroshare (http://retroshare.sourceforge.net http://retroshare.sourceforge.net) - Pond (https://pond.imperialviolet.org https://pond.imperialviolet.org)
- onli 13y agoBitmessage is pretty neat. Have a look. And the community around it is capable enough to offer some nice services like a bm-mail-gateway [1] (and the software to host that yourself, if you want to). [1]: https://bitmessage.ch/ https://bitmessage.ch/
- junto 13y agoThe problem with all of these is that it needs a buy in from the biggest providers like Google, Yahoo and Microsoft. With a wide consortium, working towards an open standard that didn't have any insecure backwards compatibility, was just as easy to use, was decentralised, and was open source for all to see, this could work. The beauty of such a move is that there would be a huge economic benefit, as companies across the globe would start building server and client software to sell to as massive growing market.
- zokier 13y agoThe problem is more multifaceted than just "email is broken". One fundamental problem currently is webmail. People are accustomed to that but providing secure comms over web is currently tricky if not impossible. So even if we had a new fancy email standard, it wouldn't help if anyone cant't access it securely because current web standards are not up to it. Another problem would be key management. I find it difficult to believe that we could build any sort of secure system without some keys, and those keys need managing. I'd love to see widespread adaptation of HSMs, but to accomplish that it would need support from the hardware all the way to the browser (or what ever client software). Even something like TPM would be nice if actually adopted (and made trustable). Then relating to key management is the issue of trust. How do we verify the keys? The current CA system definitely seems bust, so we need something different no matter what's the email standard.
- kybernetikos 13y agoI think key management is a really big problem, as I say in my blog post 'I shouldn’t be trusted with anything as precious as my own private key'. http://kybernetikos.com/2013/06/22/how-do-we-make-encryption-more-accessible/ http://kybernetikos.com/2013/06/22/how-do-we-make-encryption... I'm not so sure about the problems with webmail. I don't see why they would be significantly different from the problems associated with serving a web banking site, and there are plenty of those.
- zokier 13y ago> I don't see why they would be significantly different from the problems associated with serving a web banking site, and there are plenty of those. With web banking usually the bank has legitimately access to all information they are presenting to you via web. In email your email-provider shouldn't have access to your unencrypted mail.
- Retric 13y agoPresumably you could use client site JavaScript to decode your message. However, that brings up key management issues.
- maaku 13y agoHave you looked at pond?
- kabdib 13y agoMicrosoft has been trying to do that for well over a decade :-)
- SEJeff 13y agoHe said one designed by people who understand the issues. MAPI/NSPI are quite awful protocols. The openchange[1] team has reverse engineered pretty much all of it. I helped edit the very first release doc a few years ago as Julien (the lead openchange dev) is French and not a native English speaker. [1] www.openchange.org