6 ms·
How can Virtru help email users who are concerned with government surveillance activities that have been revealed in the last year?
by lemonlyman87 13y ago
How can Virtru help email users who are concerned with government surveillance activities that have been revealed in the last year?
- jgilpin 13y agoEncryption has been used in the past to keep emails secure from surveillance(PGP), but it has always been cumbersome to setup and use on both ends. Virtru's focus has been to make powerful encryption available to everyone by making it easy to use and with the services you and those you communicated with already use. Right now we have Chrome/Firefox support as well as an iPhone app...but many other clients soon.
- mnrasul 13y agoPGP - one can store the keys on one's own server. In Virturo, it appears it has to be on Virutro servers. So hypothetically, we could have a Lavabit moment.
- jgilpin 13y agoSee my other comment about Virtru and allowing for self-hosted keys. We also don't host the content, so different laws apply..I think znelson commented on that somewhere in the thread already.
- ravenac95 13y agoI think it's been iterated before, but in the future we intend to open source our key serving software. There's still much work to be done on that front. We love PGP's crypto, but we found a few problems with it in general: 1) It's hard for the normal person. (The user experience for PGP is just horrendous) 2) Before you send an email to someone you have to know their public key. With that said, we have done some research on integrating PGP like public key encryption along with our current key serving mechanism. With public key, using Virtru will be essentially equivalent to holding the keys yourself. Look for more of this in the future :-)
- znelson 13y agoHey, that's a great question. We've put a lot of time and effort into thinking about this and have been working with some key people in the industry who have a lot of experience in this area. We've comprehensively addressed this issue on our blog. Here's the direct link: https://blog.virtru.com/faq-on-government-surveillance/ https://blog.virtru.com/faq-on-government-surveillance/ Let us know what you think.
- cschmidt 13y ago> Q. What would Virtru do if it received a request > from the United States government for encryption keys? > A. We will require the government to go to court, > and if we can, we will notify you. To me that seems naive. You won't be able to notify anyone if you get a National Security Letter (NSL). Lavabit had turned over encryption keys for individual users, because they had to [1]. They only shut down when the government wanted their SSL key, to give access to everyone. How are you any different? [1] http://en.wikipedia.org/wiki/Lavabit http://en.wikipedia.org/wiki/Lavabit
- znelson 13y agoUnlike lavabit we're not a content provider and therefore not bound by the same laws. We're just a third-party provider that holds the keys. #7 on the blog post here goes into more details: https://blog.virtru.com/faq-on-government-surveillance/ https://blog.virtru.com/faq-on-government-surveillance/
- DHowitzer 13y agoHi, it's Will Ackerly here. We've thought a lot about the National Security Letter scenario, and so, we're going to be pushing to our website a Canary (in the coal mine) icon, linking to a statement declaring that we have never received an NSL. Our special counsel on privacy (Tim Edgar, who used to work at ACLU) came up with the idea for us, which I believe Apple is using through regular reports (not a literal canary icon on their website).
- cschmidt 13y ago