5 ms·
Did you read what Mailpile is doing? Basically making PGP easy to use which solves the lions share of the issues at stake here with the NSA and your complaints
by modoc 13y ago
Did you read what Mailpile is doing? Basically making PGP easy to use which solves the lions share of the issues at stake here with the NSA and your complaints.
- FedRegister 13y agoExcept it doesn't solve the traffic analysis problem. It doesn't because it can't. Out of the list posted by the GP the following aren't fixed by mailpile and can't be because it has to use SMTP: modern content encapsulation / PKI / mandatory authentication / SPAM control.
- cwp 13y agoWhat do you mean by modern content encapsulation?
- FedRegister 13y agoMIME blows
- Shish2k 13y ago> making PGP easy to use which solves the lions share of the issues Does it encrypt the "from" and "to" headers?
- JshWright 13y agoThe NSA doesn't care what's in my message. They care who sent it, who received it, and when it was sent. None of those things are protected by PGP. Heck, they often get the source IP address and subject line, which is just a bonus.
- harrytuttle 13y agoYes. Being a bit Theo de Raadt here, but it's a stupid proposition which makes security guarantees that are disingenuous. a) This assumes that everyone is going to be using Mailpile or something which makes PGP easy to use. This is unrealistic. The moment you fart out an email to gmail, it's useless. b) this assumes people actually understand PKI. This is unrealistic. Most people can't even manage their own data let alone a mail server hosting environment or a private key securely. c) Security is still optional. It uses the same insecure protocols as a baseline. d) It doesn't solve endpoint / mailbox security. e) There is no technical information or credibility. It's not been field tested, no security reviews have taken place. f) PGP only encrypts the contents, not the envelope. The envelope is enough to warrant digging out the $5 wrench and whacking you with it until the key appears. I'm proposing verifiable mandatory protocol level encryption and authentication end to end (MUA to MUA) which is the RIGHT solution. If there is the ability to plausibly deny a message then that's even better (which goes against sender verification so this should be choosable). The only thing going for it is it looks like a reasonable webmail client (probably better than roundcube)
- bio4m 13y agoExactly this. Mailpile sounds like a good idea in principle until you start looking at the underlying tech. They explicitly say they will not be implementing a MTA. Since an eavesdropper knows who youre sending to and what the subjects are youre a bit vulnerable to a literal brute force attack: http://xkcd.com/538/ http://xkcd.com/538/
- crocowhile 13y agoIt seems to me the mailpile people are quite aware of what they are building and do not oversell their product. They even talk of risk assessment right in the indiegogo webpage. Regarding your points: a-d) I assume that mailpile to mailpile communications will be PGP armed by default. It's enough for them to clear this unambiguously (for instance with a STAR next to "secure" addresses or a popup that says "you are sendind a message to a gmail account, be aware that...) e) alright f) there are other quite trivial ways to protect identities, such as a pen-name and a starbucks connection. Those are quite useless, however, if the message is not encrypted.
- harrytuttle 13y agoWell your point F nullifies your point about A-D does it not? As for a second point F, the identity can be derived from the unencrypted headers in PGP. Before PGP: From: bob@alqaeda.org To: bill@gmail.com Subject: The snow this year is better at Innsbrook. But not at St. Moritz. After PGP: From: bob@alqaeda.org To: bill@gmail.com Mime-shit.... DEFKJiwfou3hoqwdnhoqiwfhoqifowqihwqoidhqwod== PGP is an encapsulation and the MTA still needs the recipient and sender to work properly. Hmm.
- TeMPOraL 13y ago> atob("DEFKJiwfou3hoqwdnhoqiwfhoqifowqihwqoidhqwod==") "AJ&,¢í᢬*ᢨ£ ¢ ¨ØjÂ" :(. Here's me hoping you hid a joke in that base64.
- crocowhile 13y agoNo, it does not. Take this message: From: anonymous_acct_101@mailpile.is To: anonymous_acct_77@mailpile.is Mime-shit.... DEFKJiwfou3hoqwdnhoqiwfhoqifowqihwqoidhqwod== This is quite a secure message and it would be as easy to send as any other email with mailpile or similar services. My point is that security is not a black&white concept. There is a continuous of security, and part of the job of mailpile could be to give a "security score" to your message before you hit the send button, similarly to what we do when we calculate entropy on password and give a "security score" on the password. A password with a good score does not guarantee the security of your login but at least it will help you understand more about the entire process.