3 ms·
I think the biggest barrier to entry of any new and secure email protocol will be GMail. GMail (and similar services) are what most people seem to use at this p
by SomeCallMeTim 13y ago
I think the biggest barrier to entry of any new and secure email protocol will be GMail. GMail (and similar services) are what most people seem to use at this point.
And GMail won't update to 3.0 in any meaningful way, no matter what, since they want to be able to mine the data in your email, so they will still be storing it on their servers "in the clear." Which means the next time NSA hacks their servers, they'll still be able to read all the email.
Best case is that email 3.0 will interoperate with 1.0, or GMail at least accepts 3.0, if only to unencrypt it on their servers. Short of that, it would take a compelling use case to convince people to leave GMail, so we'd be right back to where we are with email 2.0: No critical mass of adoption, meaning 98% of the email you receive and write is unencrypted.
- ChuckMcM 13y agoI agree with the barrier. I wonder if the NSA has made surmounting that barrier possible. If the friction to getting a 'secure' email experience is low enough, people will put up with having two for a while. As for connecting them. I could handle just being able to communicate with my security conscious friends on this platform. That might make it a niche play early on but so was email.
- Semaphor 13y agoCall me cynical, but for all the public outrage worldwide I'm pretty sure that even that outcry comes from a minority.
- ChuckMcM 13y agoI think it is quite rational to be cynical about it, but before you completely write it off, consider what the cynics said about email when it was small. Basically email was characterized as a way for nerds to exchange jokes that either everyone had already heard, or nobody understood. I recall that in 1979 exactly nobody in my family (except me) had a network email account (on USC-ECLC no less) and they didn't care. What my family had worked for them and it was just sillyness on my part to think that email added anything to the mix. What mattered though was that enough people had email accounts that they could get more done, more efficiently, than people without email. Every year that converted more and more people to the idea that email was something they should have, by 1999 everyone thought they should have one even if they weren't sure why. I see similar thinks with a reconstructed email system that is free from surveillance. People being able to joke about things or discuss things and not find themselves unable to board a flight because they joked about something the TSA considered suspicious. You and I may not have had that experience yet but folks have, and it is getting more common not less common. We just had a law enforcement officer drive up and shoot a kid dead because he was carrying a toy gun. He thought the gun might be real. I say that "Clubs in NYC are the bomb!" I don't want someone detaining me for four hours asking me what exactly I meant by that. As few as 3 years ago I would not have considered a system like this something that "regular" people would want to use, and that would inhibit adoption and use. But now I am not so sure about that. I agree that the 'outrage' is a minority, but it is coming from more people than it ever has before. At some point the minority is large enough to be a 'useful subset' and once it becomes self supporting I've seen otherwise "useless" products become part of everyday life. It is that change, that I wonder about here.
- r00fus 13y ago> GMail at least accepts 3.0, if only to unencrypt it on their servers. This. I assume Google will be very eager to adopt "3.0" simply to absorb the data and make it available to the Android/AI bots that really run the place (Larry, Sergey and other googlers are clearly just physical manifestations). Google doesn't seem to me to be the kind of organization to fear adoption of external ideas - they just co-opt them.
- opendomain 13y agoI wonder if it would be possible for Gmail 3.0 if they agreed to 'read' your email ONLY while you are reading it so they could display advertising. For example, the email is encrypted on the server, but a client has to eventually decrypt it (so you can read it) - if we could trust google bots to grab relevant keywords on the fly for the content but keep no history then it may be good enough privacy.
- cantrevealname 13y ago> GMail won't update to 3.0 in any meaningful way, no matter what Perhaps this problem can be addressed by having a plugin/add-on/extension that decrypts the mail within the browser. GMail, Yahoo, or other mail providers that don't adopt this new and secure email protocol won't get the plaintext of your message, and preferably not the metadata either. This requires that the new protocol use a converter or proxy or something to be able to talk to the existing email infrastructure. I'm sure this idea has occurred to the Silent Circle and Lavabit guys.
- diydsp 13y agoMaybe people could run a local app/filter that extracts keywords from our own mail and shares them with google. Leave the power completely in our hands to give to google what we feel like giving them.
- dmix 13y agoThis patchwork approach to attempting to solve a large broken system has visibly failed analogously to politics, in terms of preventing the threat of mass-surveillance. I don't see how this is any different. We need new technology to solve new problems. Decentralization. Changing behavior is not easy, but sometimes necessary. Everything else being proposed seems half-assed (for lack of a better word) and easily circumventable by a resourceful adversary. As long as Google (or whomever) holds all the cards and has a lot to lose by not complying to threat of force (for ex. shareholders and stock prices), then we won't get anywhere.
- vidarh 13y agoThere are two parts to e-mail security: (EDIT: To the security of the information in any particular message, there are additional issues regarding e.g. routing to prevent leaking information) The contents. You can secure that with pgp etc. today, and gmail can do nothing about it, and there a browser plugin that "hides" the mess would be workable. The metadata. Here gmail etc. is a problem. The best we can do are remailers that anonmize the sender. In the case of e.g. Gmail, the recipient at Gmail will obviously still be in plain text, but we can obscure the sender by encrypting forwarding information and setting the To: field to a remailer. A plugin could handle that too. Of course any such plugins would either need the cooperation of the webmail providers (yeah, right) or would need to deal with breaking whenever they change their UI.
- junto 13y agoI think that the greatest barrier will be Exchange and other corporate email servers software. Without corporate buy-in, this will never take off. Corps "need" to have an overview of the messages unsecured. There is no such thing as personal privacy in the corporate world, only corporate privacy.
- balabaster 13y agoI disagree somewhat with this, if it needs to be secure end to end, then the server just needs to support that protocol. The question is, if you don't want to leak any metadata, then how do you put it in the right mailbox? You need a pub/sub type protocol where you can go in and grab the messages meant for you, but the server must not know they're meant for you and you must be able to do so completely anonymously. How do you achieve that? Exchange certainly can't be configured for that, so you need to replace it with an entirely new (and hopefully open source) mail server that supports most of the Exchange functionality - server push etc.
- junto 13y agoIndeed. The two requirements aren't complementary. Therein lies the problem.