19 ms·
Mailpile – taking e-mail back
- Fuzzwah 13y agoI think these 3 guys convinced me to chip in for this project mostly due to their hair.
- mikegioia 13y agoI'm surprised how fast it happened! With 22 days left it may get high enough for them to bring on another developer.
- tokenizer 13y agoSo will this bypass prism-like surveillance methods?
- JshWright 13y agoNope. You can't encrypt the message headers, so the To/From addresses, subject line, sender's IP (usually), and timestamp will all be recoverable.
- alan_cx 13y agoIm not sure anything can or will. IMHO, the plus for this is that if more and more people move to encrypted communication across the board, it will a) increase the work load of the likes of the NSA and GCHQ, and b) send a message to government. Nothing, of course, will work as well as people actually voting for real change. Of course the tragedy of that is that after the scary Bush years, the US people thought they were voting for changes, and all they got was more of the same. I despised Bush, but like we Brits used to say about Thatcher, at least we all knew where we stood. (Blair was our Obama, we thought we were voting for change.) Sooner or later, we will realize we need to break away from our traditional parties, and vote for something very different, instead of voting int he same thing over and over again because we are too scared of fundamental change, and frankly risk. For now, we are all too spaced out with our retail and media narcotics to notice or want to change.
- swdunlop 13y agoNot at all. "Mailpile will download your e-mail from a mail server much like Thunderbird or Mail.app and process it locally." PRISM and other efforts at tracking associations operate at the server and header level, this is not a useful countermeasure. It may reduce the amount of mail you leave on the server -- but so would a reasonable mail reader configuration.
- aravenel 13y agoIf it makes it easier to use encrypted email, then it does a little--any emails with someone with whom you have exchanged keys would be encrypted, and thus while they do indeed still fly across insecure channels, they are (presumably) uncrackable. Obviously, the vast majority of emails would still be unencrypted, and this does nothing for metadata. But anything that makes encryption less cumbersome to use is a good thing in my book.
- harrytuttle 13y agoHow many times do people have to say this: There is no such thing as secure email. Assume everything is being read. You can't bolt security on (SSL, mailbox encryption, PKI). You have to design it in from the start. SMTP/IMAP etc have crudely hacked on TLS implementations which aren't even guaranteed to be operational site to site. PGP is just an encapsulation which is rarely used. It's a mess. This is just a repackaging of the pile of hacks. We need to start again and do it properly and consider: encryption, modern content encapsulation (better than mime), authentication, PKI, secure storage, mandatory authentication/authorisation and SPAM control.
- harrytuttle 13y agoTo downvoters: do the honour of explaining yourselves.
- modoc 13y agoDid you read what Mailpile is doing? Basically making PGP easy to use which solves the lions share of the issues at stake here with the NSA and your complaints.
- FedRegister 13y agoExcept it doesn't solve the traffic analysis problem. It doesn't because it can't. Out of the list posted by the GP the following aren't fixed by mailpile and can't be because it has to use SMTP: modern content encapsulation / PKI / mandatory authentication / SPAM control.
- cwp 13y agoWhat do you mean by modern content encapsulation?
- FedRegister 13y agoMIME blows
- 13y ago
- devx 13y agoWhy even bother with S/MIME? How long until the government corrupts the certificate for it if Mailpipe becomes as important to them as Lavabit was, in the future? And I hope their PGP implementation is really user-friendly. This sounds like more of the same of what we've had so far, perhaps with the ability to become a little more mainstream, but I don't see any breakthroughs in terms of encryption here, like say the way Bitmessage is. I think that if we want NSA-proof secure messaging we'll need to come up with new stuff, and not just use the same old PGP with centralized email databases. This could definitely be a (very short-term) win against NSA if say Gmail implemented PGP in a very user-friendly way, but for something starting from scratch, I'd rather it was a breakthrough in security.
- mikegioia 13y agoWhy even bother with S/MIME? How long until the government corrupts the certificate for it if Mailpipe becomes as important to them as Lavabit was, in the future? The way I see it, Mailpile won't be issuing certificates for people to use, they merely enable you to use your existing certificate infrastructure. I have a machine with a certificate authority that issues S/MIME certs for us to use internally for sensitive emails. Currently we use Thunderbird and Mac Mail to handle this but people like web mail and we need a system that can run a web interface (or phone app) to handle these certificates.
- noselasd 13y agoI'd say the people that can set up and manage their own CA, and the people that need a new mail client to be able to send/receive encrypted email are non-overlapping groups. If you're right - what does Mailpile solve ?
- mikegioia 13y agoThe reason why I need something like Mailpile (and the problem they will hopefully solve) is to have a client-side app with a user-friendly system for managing S/MIME certificates. I can set up the CA and generate user (employee) certificates on my own, there's no way the end-user should have to do that. But what's frustrating right now is that the current tools for configuring S/MIME signing and encryption for email either (a) don't exist, or (b) are heinously complicated to use. Have you ever tried getting S/MIME certificate auth set up in Mac Mail? It's doable but I had difficulty walking my tech-savvy brother through the process over the phone. If Mailpile has a simple method of selecting a certificate file for an email account then the hard part is done IMO. The process just becomes IT issuing new certificates every year to employees, and employees uploading said certificates through their (web) mail app. The biggest value here is having a web mail client, hosted locally, that can support PGP/SMIME in a user friendly way. Then signed/encrypted emails are that much easier to configure for the masses.
- jvehent 13y ago* User-friendly support for both OpenPGP and S/MIME encryption and signatures * A very fast, scalable search engine I'd like to know how they achieve both without having the keys, and without shipping code (JS, java applet) that has access to the keys. Also, excuse my lack of trust, but why should I trust a SaaS created by a Google employee, as opposed to trusting a SaaS created by Google ? That makes no sense to me. If you're worried about privacy, store your own emails. Period.
- HerraBRE 13y agoThis is not a SaaS. This is an open source mail client you run yourself. So that's why. :-)
- jvehent 13y agoI had missed that. Thanks for clarifying.
- mikegioia 13y agoI don't understand, are you generally concerned that Mailpile's web JS can search emails, and therefore has access to private user keys/certificates? I mean, doesn't that just come to whether or not you trust the javascript that Mailpile is writing? I don't think this any less secure than say Thunderbird with respect to PGP/SMIME.
- dangerlibrary 13y agoUnless I'm misunderstanding, the goal of the Mailpile project is to create a user-friendly client for an arbitrary (including self-hosted) email server.
- umsm 13y agoI would like to mention that the details of this project seem a little sparse. For a truly secure solution, this system will need to (1) define a secure standard and (2) allow domain owners to personally host this system which can connect to legacy mail servers as well as the "new" secure standard. This way, when persons communicate within the same email domain and between secure systems, the communication can be considered secure. Just my 2 cents I guess. A system like this can succeed, but I think it's too early to judge.
- aidos 13y agoCongratulations on getting the funding. I really hope that over the next 22 days it's pushed much higher so you can develop the product faster. I installed the current version last week to have a play. Even in its current state it's very promising - too far away to really be used yet but once it matures it could be a great product.
- tim_hutton 13y agoTitle as submitted: "Mailpile is funded - secure email for everyone"
- HerraBRE 13y agoHey all! Mailpile tech lead here. Just wanted to say THANKS to those of you who helped make this happen so quickly. Improving e-mail security, flawed as the underlying protocols may be, is long overdue. We don't promise perfection, but we do have clear ideas about things that can be improved and how. We strongly believe in a pragmatic, backwards compatible approach that helps people slowly migrate to better habits. For some background on the wider philosophy of the project, check out the slides from my OHM presentation where I launched this: http://mailpile.is/files/OHM2013%20-%20Rescuing%20e-mail%20from%20the%20cloud.pdf http://mailpile.is/files/OHM2013%20-%20Rescuing%20e-mail%20f... - this project is as much about rebooting FOSS e-mail development and fostering decentralization, as it is about encryption and security. We will be posting more details to our blog at http://www.mailpile.is/blog/ http://www.mailpile.is/blog/ as soon as we get stuff written down. :-)
- ebbv 13y agoThis seems drastically overpriced. $4k/month for a year just to develop a webmail CLIENT? Crowdfunding really is the modern pyramid scheme.
- pessimizer 13y agoI'd charge twice as much.
- deleted 13y ago[deleted]
- tlrobinson 13y agoI wonder how much Google has spent developing Gmail.
- puzzlingcaptcha 13y ago$4k/month before taxes.
- ghc 13y agoOkay, so we're crowd-funding an email client now? Is there any reason to not just put up all of my random project ideas on indiegogo and see if they get funded? If I'm having trouble financing the development new features for my SaaS application, should I just create a funding project for it? Because I'm really not seeing the difference between that and this...I wish someone could explain this phenomenon to me.
- 21echoes 13y agoif you think there's potential demand for your product from the sorts of people who fund projects, then by all means you should ask.
- nollidge 13y ago> If I'm having trouble financing the development new features for my SaaS application, should I just create a funding project for it? Sure, why not? No one is stopping you. > I wish someone could explain this phenomenon to me. Many people invest small amounts of money in a person or group of people. There are risks, like any investment, and the payoff is a product which the investors will find useful or entertaining.
- Zoomla 13y agoit is not really an investment, it is more like charity... you more then likely never get more then what you paid for and you have a risk of loosing it all.
- nollidge 13y ago> you more then likely never get more then what you paid for They tell you beforehand exactly what the payoff will be. If that doesn't sound economical to you, you don't pay in. There's absolutely no deception here. There's no promise of riches. There's just a promise of a product that is worth what you paid for it. > and you have a risk of loosing it all. ...which is exactly like every other investment in the history of commerce.
- deleted 13y ago[deleted]
- mope 13y agoGreat work guys, it would be great this takes off and introduces PGP to a wider audience. Maybe one day we can stop sending electronic postcards to each other. Now if only someone would restart Mixminion development...
- madcat123 13y agoIt seems to me it's time email followed the file-sharing industry and moved to a distributed, peer-to-peer system. End-to-end encryption and no servers to shut down... There's a couple of research papers on the topic: http://www.computer.org/csdl/proceedings/cse/2008/3193/00/3193a203-abs.html http://www.computer.org/csdl/proceedings/cse/2008/3193/00/31... http://www.freepatentsonline.com/y2009/0144380.html http://www.freepatentsonline.com/y2009/0144380.html
- ptaffs 13y agoas ever, the criminals and terrorists have already solved the problem; they communicate privately using closed community forums (search for "carding/carder forums"). The people left using SMTP e-mail are mostly PETA, EFF and other political groups the government is interested in monitoring.
- brown9-2 13y agoSo there are no actual "perks" for the $1 and $8 contribution levels listed under the "Select a Perk" table? $1 Binary E-mail User: You're part of the revolution, baby! - the revolution that started in the 1960's with the creation of the first e-mail systems. $8 Futurist Telegrapher: Having not spent a dime on webmail for the last decade, you've realized that the telegraph operators of the world have been keeping copies, and it's time to change that. Thanks for helping us help you! So what do the contributors actually get for $1 or $8?
- roryokane 13y agoThey get nothing. I think those “reward” levels are just a cute way to trigger anchoring (http://en.wikipedia.org/wiki/Anchoring http://en.wikipedia.org/wiki/Anchoring) and make the job of choosing how much money to give easier by suggesting some choices. In fact, the $13 contributors don’t get anything extra either – they get “access to Mailpile's online source code”, but that’s already available at https://github.com/pagekite/Mailpile https://github.com/pagekite/Mailpile.
- bane 13y agoMaybe the better solution is a completely new distributed delayed messaging system that works just like e-mail, but fixes all the crustiness and problems that we know about these days. There's very little that's more demoralizing then spending months cultivating a relationship with somebody in a company you want to work for, getting glowing recommendations, prepping yourself diligently for the interview then showing up to a cattle call where half the interviewers can't even be bothered to show up and the recruiters are a blind mess the entire day. You aren't even being treated with basic human dignity at that point, there's no respect for your time and you've just wasted a good deal of effort to get into a hiring process where the candidates are selected for non-interview talents anyways...like what school they graduated from or the roll of some dice.
- soapdog 13y agoGenuine question: If this is open source, how come USD23 gives you access to source code? I think this is a great product and will contribute but I could not understand this part the about source code
- 616c 13y agoWhat bothers me a little is this is basically a reinvention of the wheel for sup-mail, developer by a Twitter developer and was/is very cool (I use it on Mac occasionally for backups of email I have in a Maildir). Maipile would add the web interface, and they just started transitioning to that idea in the sup community, calling it heliotrope. https://github.com/sup-heliotrope/ https://github.com/sup-heliotrope/
- samuelfine 13y agoEach time someone attempts to make email more secure, the HN response is "no use! need to start from scratch, do it right!" So, I guess what I'm saying is: 1) Are you working on an inherently-secure messaging protocol? Awesome! Link to the project? 2) If you're not, shut the fuck up. Any improvement is better than no improvement, and dismissing any attempts to fix some of these problems while you wait for The Perfect Solution™ is why we're in this mess in the first place.
- meapix 13y agoRay Tomlinson screwed us all up
- orestmayski 13y agoI have no idea what the end product will actually look like, but I have the greatest hope for it.