4 ms·
So this allows potential crackers to save every copy of every encrypted email, allowing them to be cracked in the future when there is increased computer power
by ugexe 13y ago
So this allows potential crackers to save every copy of every encrypted email, allowing them to be cracked in the future when there is increased computer power and more advanced cracking techniques/rainbow tables?
- qznc 13y agoHow would you prevent this? It is not prevented by SMTP and not by this p2p approach.
- ugexe 13y agoThis puts your email in everyone's hands, it's just encrypted so it probably can't be read without the key (yet). Regular email does not do this.
- qznc 13y agoSo its "everyone" for p2p vs "many secret services" for SMTP. On the upside, it gives every user a good incentive to use good encryption.
- Karunamon 13y agoOn the positive side, it's unlikely "everyone" who isn't a government agency with billions of dollars of taxpayer money to waste has the time, storage, and compute resources to mount the kind of attack you're talking about. I know NSA is the topic of the day, but they're kind of a special case here. They're the single most powerful and well funded adversary the average crypto user will face.
- tedunangst 13y agoUntil you break up and your ex decides to publish your key in revenge. Unlike a password, you can't change a key and revoke access.
- Karunamon 13y agoWhy on earth would you let someone who is not you anywhere near your private key? No security system in the world can fix user fail.
- ugexe 13y agoThe difference is when your ex releases your key and you are using this system then everybody can read your email instead of just the NSA and the recipient.
- 18pfsmt 13y agoSo, what you are saying is that nobody else, but you, should ever have access to your private key, right? I'm pretty sure that's PKI 101, which I think was Karunamon's point; and, I'm pretty sure the solution to your proposed 'weakness' in this system is not technical.
- ugexe 13y agoHe edited his post and my reply doesn't make sense in context now
- tedunangst 13y agoSince people share passwords with (at the time) trusted people quite frequently, it seems like a scenario one should plan for.
- adouzzy 13y agoBut there would be millions of emails. If meta data is concealed, how would the crackers which email is valuable? As long as it is not possible to crack a proportion of the total traffics, I think it is safer this way.
- pampa 13y ago> If meta data is concealed, how would the crackers which email is valuable? From the protocol doc: "When an email is sent then the email’s hash is added to the DHT in the key that matches the recipient’s address; the mail is then transferred in a BitTorrent like fashion." How does that conceal metadata? If you dont have plaintext From: and To: fields, it doesnt mean the metadata is concealed. Metadata is not whats IN the communication, it is the data that you collect OBSERVING the communication. Without special measures to provide anonymity, it is no different than an OTR-encrypted chat or PGP email.