4 ms·
"Emails are synced from the users’ email accounts via IMAP to the box and are stored in plaintext in a secure storage area on the box" I've seen a better (open
by slug 13y ago
"Emails are synced from the users’ email accounts via IMAP to the box and are stored in plaintext in a secure storage area on the box"
I've seen a better (opensource) approach to use gpg to securely store email: upon receiving a message, if not already encrypted, use the public key of the account recipient to encrypt it. This way, all email is encrypted with your pgp key. The downside , which this box is trying to solve, is that the (imap) client will need to do the decryption, so it's not transparent to the user. There's also filters for well known MTA (exim,postfix,etc) that will encrypt/decrypt using pgp or s/mime (user/host) keys upon connection.
I see another problem with the 'box' approach, it will need the plain-text passphrase, so if someone steals or has access to your (mail)box, all your email is plain-text and you will have to revoke the pgp key.
Not only that, if you are not aware of the intrusion, someone can impersonate you, since they can sign any message/document with those credentials.
How about redundancy/backups? If the net connection goes down or box/house stops working, what happens to the emails?
- radiospiel 13y agoThe assumption about this box is that it is in a reasonably safe place. Also, everything on the box is stored encrypted, you need a master key to unlock the box and get it running. Note: This is not spy stuff. This is a reasonably secure environment for your email (and as secure as the average's persons desktop is)
- slug 13y agoMy point was that for a non-pgp aware imap client to read the encrypted emails, the passphrase needs to be somewhere, probably in RAM all the time, making it a target, so if there's an exploit, having it encrypted or not is moot. It solves the 'steal box' problem and since it's not spy stuff, we don't have to worry about cold boot attacks ;) On a desktop, the pgp credentials either exists momentarily (user input) or through an agent, so at first sight it would seem that would be safer, although then we could also argue that a desktop is probably not as safe as this box due to all the other software that is run by the user.
- radiospiel 13y agoUltimately this is a decision between usability and security, and I am afraid there is no good answer here. We still do our best to prevent key theft, even in the case of someone hacking into a running box. There is only one process with access to the keys, which runs in a separate system account (each software component runs under its own account anyways) and which is not accessible from the outside. Still, one could potentially hack into the system and become root.. but this is less likely to happen on a separate box than on a full-blown desktop (with the average user giving out his/her root password whenever some installer asks for it).