3 ms·
why dont they address the server and encrypt the user address at the server level, so a network eavesdropper would only see traffic too and from servers but not
by xanth 13y ago
why dont they address the server and encrypt the user address at the server level, so a network eavesdropper would only see traffic too and from servers but not the particular addresses being addressed. The user puts in an address e.g. yaName@yaDomain.com the sender and receiver address (maName & yaName) are then stripped on sending the D-mail and encrypted with the D-mail servers private key the receiving server (maDomain) then goes through the public private key exchange with the sender (yaDomain) thus securely passing the user address between the two servers without the eavesdropper knowing from what user the D-mail originated and to what user the D-mail was addressed to. This system would become more secure the the greater the number of users on each domain.
To add extra security batch sending by the server would make it even more secure
e.g. every 3min || when unsent messages to domain x > 999 --> send D-mails.
this would add latency and create bandwidth spikes but would negate time based inference attacks.
edit: relevant xkcd; http://xkcd.com/927/ http://xkcd.com/927/