6 ms·
Lavabit appeal against data handover
- themartorana 13y agoI can't figure if this spells the beginning of - forgive me - "Email 2.0", which is inherently encrypted and secure (starting with the Dark Mail Alliance, perhaps), or if the general public's lack of understanding about the wild insecurity of email, mixed with a no-so-small amount of apathy means nothing will change at all? It would be nice to look back on this in 2 years with a "what were we thinking?" attitude towards email as it currently exists, as we all moved to a better solution invented by smarter people than me.
- dhimes 13y agoAs usual, some well-meaning and knowledgeable folks are going to have to take the lead on this. Kind of like the free software movement. Most people won't know or care or know that they should care.
- digitalengineer 13y agoBut most companies do. There's an opportunity right there. I'm sure we'll see standard encrypted communications in a few years.
- Joeboy 13y agoIndeed, I think it may be problematic that the arguments for encryption have tended to focus on dissidents and people with dramatic reasons for needing privacy. Large companies with mundane privacy expectations might have been a better bet in terms of spurring uptake.
- Zikes 13y agoThat would still require a large amount of trust in those companies and that they are not breached or subpoenaed, though. It would not be far-fetched at the moment to imagine that Google has been explicitly barred from implementing a feature in GMail that would prevent them from being able to provide the contents of a person's mailbox to the NSA or FBI if requested.
- Zigurd 13y ago> It would not be far-fetched at the moment to imagine that Google has been explicitly barred from implementing a feature in GMail that would prevent them from being able to provide the contents of a person's mailbox to the NSA or FBI if requested. Indeed you have to wonder why not one major email provider has offered a paid option for secure mail. As others have pointed out, that still leaves meta-data in the open. But secure-payload plus pseudonymous, deniable identities makes targeting difficult and unreliable. That would be a big improvement.
- runn1ng 13y agoWe need some decentralized way to send e-mail. Oh wait, there is such a way. It's absolutely decentralized, everyone is free to join and use it and add encryption on top, and it's called SMTP.
- Zikes 13y agoOne of the flaws in that is that while you can encrypt the information in the email body, you can't obscure the metadata like who the sender and recipient are, when it was sent and received, etc.
- fossuser 13y agoI think combining pgp with tor solves that problem, the issue is main stream usability. Even beyond that a bigger core problem is that many (most?) people communicate outside of email because it's too slow. Facebook chat, google hangouts, iMessage, SMS - these are the real things that matter to secure today. As much heat as cryptocat has taken - I think they have the right idea and are working on an important problem (whispersys too). Security should be built in and easily adoptable. It should be equivalently usable to what people are already communicating with or they won't use it.
- Zikes 13y agoThe sender and receiver are still necessary for the SMTP protocol to work, as the mail servers need to access that to know where to route the email. At best, tor+pgp would allow you to create a pseudonymous email address (or series of addresses), but there would still be nothing stopping people from looking at your mailbox and seeing what other addresses you've communicated with, even if they can't decipher what those communications are. The SMTP protocol itself needs rewritten to function more like tor, so that each intermediary is incapable of seeing the complete picture.
- MichaelGG 13y agoNot that I disagree with your sentiment, but how is that "inherently encrypted and secure"?