4 ms·
The concept is very interesting - apparently, each "doll" or layer is encrypted, and only the target can decode the message - so I guess the equivalent of the M
by guylhem 12y ago
The concept is very interesting - apparently, each "doll" or layer is encrypted, and only the target can decode the message - so I guess the equivalent of the MX would be the outmost doll, while the equivalent of a To: field would be the innermost doll.
This reminds me of something else I've found quite interesting - the idea of publishing pubkeys or at least their hashes as DNS records (yes, unsafe unless there is DNSSEC etc, but that would be much better than now), so that the sender could encrypt the message automatically, without requiring the user to select say GPG target keys.
I wonder if that's what they will be using. Do they have technical documents or RFCs?
A new and non backward compatible email system using that (say even running on a different port) would indeed be quite interesting, but I wonder if there wouldn't be weaknesses that would make spam a problem as serious as in 2004/2005 (or maybe SPF is yet another of their "dolls"?)
Edit: about anonymous remailer and tor, it doesn't look the same to me. Say I publish 2 keys, one for my domain, one for my user. Everything one wishes to send to my domain is encrypted first with my key, then with my domain key, and then signed with the sender domain key (to add equivalent of SPF). Once it arrives, the equivalent of an MTA can try and decrypt that - if it suceeds, it can then put it in a spool of mail "not fetched yet" (so to as add a layer of protection against a malveolent sysadmin - the user could download all the encrypted mails in the spool and try to decrypt them itself)
The only thing that would be seen (besides the DNS lookups, but they could be cached by the client with a TTL) would be that domain A is sending a message to domain B.
- pinkyand 12y agoThe doll concept sounds awfully close to either tor or anonymous remailers(which are much more private). But anonymous remailers had much trouble with authorities so i wonder how that will work.
- higherpurpose 12y agoI think they said in this video that the model is somewhat similar to Tor: https://www.youtube.com/watch?v=hRwArF3BAZk https://www.youtube.com/watch?v=hRwArF3BAZk For something that actually works over Tor (or something very similar), there's Adam Langley's Pond: https://pond.imperialviolet.org/tech.html https://pond.imperialviolet.org/tech.html
- codys 12y agoYep, I was imediately reminded on onion routing (which is what tor uses) when reading the article.
- icelancer 12y agoSpeaking of: Were the anon.penet.fi days REALLY 20 years ago? Good lord. they were.
- e12e 12y agoAre there any (new) technical info on this? I recall it's been discussed here before[hn] -- and as then -- I don't really see what's wrong with anonymous remailers (the old kind). I suppose DKIM and DNSSEC might form the foundation for additional standards to augment mixmaster remailers: DKIM should allow for rudimentary SPAM filtering on the "in" side of the remailer network/onion -- and DNSSEC might be one way to at least get "any" domains "remailer" public key (so that you could send eg all gmail mail to eg: reamailer@gmail.com, with the actual mail wrapped inside) -- and "any" standard mail client could wrap up mail like that (as a minimum, optionally with an additional remailer added). I don't know how big the need for is DKIM (from an anti-spam view) -- how many receive gpg-encrypted and signed spam anyway? As I've mentioned before, I think this has similar problems as remailers -- as far back as 1996 intelligence agencies were running quite a few of them[1] -- and I imagine that would be the case going forward as well (ditto for tor nodes). I don't think that makes these things a wasted effort, just not a silver bullet. Either way, having eg Apple Mail, Thunderbird and Gmail (yes, the webmail) automatically wrap any outgoing mail in a remailer-like envelope might not be a bad idea at all. And once wrapped, everything smtp (with the exception of content-based spam filtering at the intermediary servers) works just like it always has. [1] http://www.hypertekst.net/misc/anon-remail/ http://www.hypertekst.net/misc/anon-remail/ [hn] https://news.ycombinator.com/item?id=6642106 https://news.ycombinator.com/item?id=6642106 https://news.ycombinator.com/item?id=6671219 https://news.ycombinator.com/item?id=6671219
- mike_hearn 12y ago> I don't know how big the need for is DKIM (from an anti-spam view) -- how many receive gpg-encrypted and signed spam anyway? Modern spam filters (at sites like Gmail) rely very heavily indeed on the notion of reputation. Without something like DKIM it's hard to calculate accurate reputations: you can do it but it relies on lots of hacks and heuristics. So reputation mechanisms of some form are pretty vital.
- e12e 12y agoMy point was that spammers typically wouldn't gpg encrypt mail to the recipient, even if just through a generic mixmaster wrapper service (the service could filter on content and dkim as normal on the incomming side). So if setting up such a network, i don't know if dkim would be useful on the "inside" and/or for opaque/encrypted-to-recipient messages. I suppose one could simply recommend smtp servers to clear-sign any trusted (originating at smtp servers domain) mail and stash server gpg keys in dns...
- mike-cardwell 12y agoI store the fingerprint and URL to fetch my public PGP key in a DNSSEC protected DNS record. It's called PKA: mike@blob:~$ dig +short txt mike.cardwell._pka.grepular.com "v=pka1\;fpr=35BCAF1D3AA21F843DC3B0CF70A5F5120018461F\; uri=http://grepular.com/0018461F.pub.asc" mike@blob:~$ My HN profile is GnuPG signed. You can automatically fetch my key using my PKA record and verify it by running it through the following command: sed 's/^[ ]*//'|gpg --verify-options pka-lookups --keyserver-options \ auto-key-retrieve --verify
- Joeri 12y agoSpam could be prevented by attaching an encryption cost to each message. It would make bulk mail prohibitively expensive. Inside companies you could have a trusted mail concept to allow mails to entire departments, but as soon as a mail leaves the domain a proof of work is implied.
- eli 12y agoThe bad spammers are using botnets. This would be extremely difficult to implement and would mostly hurt mailing lists.
- mike_hearn 12y agoSpam filtering is not about blocking bulk mail.