5 ms·
I've only read the RFCs for email protocols once, so someone correct me if I'm wrong. But the only way email is ever going to be truly secure is if extensions a
by dbond 13y ago
I've only read the RFCs for email protocols once, so someone correct me if I'm wrong. But the only way email is ever going to be truly secure is if extensions are added to the current protocols to add end to end encryption of the message body. Otherwise there's always going to be a third party arm for law enforcement to twist where the message is in plain text for a short time.
Also you can't trust the guy, I'd trust him to host illegal material because he wants it to stay up, but what happens when governments start offering bribes to hand over my emails?
- ecaron 13y agoI imagine that it'll be something involving browser-JS-baked PGP and an optional client-side driven indexing service (like a Sphinx search agent running in the task bar.) It'll weave in some sort of "Hey, you're emailing a service provider that doesn't support PGP enforcement - supply recipients public key, send unsecured message, or ask them to switch to MegaMail?"
- dbond 13y agoYea, I'd imagine it to be a shinier version of hushmail with lots of sketchy marketing thrown in...
- Zigurd 13y agoIt seems like it could be done with a service offering public key info, and using key signing and web-of-trust to keep the keys reliable, and encrypting in open source client software not provided or updated by the mail service provider. That still leaves the service open to being strong-armed into sending you malware. And, of course, your mail headers are in the clear. But, apparently, to the Lavabit people, what I've outlined here isn't sufficient, and the implication is that the NSA and/or FBI has ways of compromising all email providers no matter how they operate.
- dbond 13y agoThis is why it really needs to be done at the protocol level, an email provider can't change the behavior of my desktop client and the process could be completely automated for the average user.
- Zigurd 13y agoI'm not sure of the relevance of the protocol IF the service remains store-and-forward. Silent Circle and Lavabit seem to think it's better not to use email at all. An open Skype-like system is probably pretty good. Keys are ephemeral, and transferring encrypted files in audio-video sessions makes it hard to MITM.
- dbond 13y agoEmail is pretty bad, but its not going anywhere so we should try to fix it. The service would remain store-and-forward but the content would be encrypted throughout, something which is not currently possible without both parties knowing how to setup and use PGP.
- jadeddrag 13y agoI think you're looking for bitmessage which is an email replacement that hides the header and content, and is inspired by bitcoin.
- lessnonymous 13y agoYou can already encrypt email bodies end-to-end using PGP. The unsolved problem is the (queue dramatic music) METADATA!!! For an email to get from your computer to the recipients, it has to have metadata that the intermediate computers understand: The SMTP protocol is designed to deliver your email by relaying it any which way it is set to. So when you send it, it goes to your office SMTP server, which then might relay it to your head office SMTP server, which then might relay it to the recipient's spam filtering service, which might then relay it to the recipient's head office, which might then relay it to your recipient's office from where the recipient retrieves the email when they're good and ready. SMTP is not ever going to be secure. Even if you use TLS (which most mail servers do by default these days) you're only encrypting the message-in-transit so any of the myriad of systems between each SMTP server can't read it. All it takes for the NSA to read your metadata (and cache your encrypted message) is to compromise one of the SMTP servers it passes through. Then they can compel you to decrypt it using any method they have at hand. The secure way to send email is to have your computer connect directly to your recipient's computer over an encrypted transport layer (TLS) and possibly for your recipient to authenticate to accept that connection (so AFK means no email). You'll have to know your destination point's IP address somehow. (DNS sounds fine, after all it's just a phonebook. However requesting an IP address could easily be logged and so you've leaked metadata again) This means you can't send an overnight email and expect someone to get it in the morning when they switch on their computer. If you want to do that it needs to sit on a server somewhere. And that server is subject to attack. So for convenience, we could build a server designed to accept any of these messages from anywhere. But it also needs to accept messages to anywhere as it can't be allowed to know who the recipient is. That's metadata. The problem now is how do I get my messages from my server? The server isn't allowed to have my key, so it can't go and attempt to decrypt every waiting message (or decrypt every envelope). At some point, you'll have to either give up convenience (can't get email unless you're both online) or security (you'll have to trust something you're not in control of). I'd be stocking up on tin cans. And string.
- Spooky23 13y agoActually, its really simple. You operate your own mail system, and require secure network access to use it. For example, The social security administration requires each state to do this for the state employees who handle disability-related business. Those employees must use their mail system.