7 ms·
Mail-in-a-Box Security Guide
- howeyc 11y agoMy email is not secure, for a number of reasons. Here are a couple. 1) I have yet to find anyone willing to accept email from me that has been encrypted before I send it and must be decrypted by them (GPG for example). 2) It is stored in plaintext on a server I do not control (I send it to someone who uses one of those big hosts like Google, Yahoo, etc). Sending it over the wire in plaintext is probably being less of an issue now (as it seems the most used hosts are doing TLS), but that doesn't really help with bullet #2. I think the best bet is attempting to communicate with others using some other application that is not email based (like textsecure for example). Not sure how to get regular email from corporations via another means though (monthly bills for example).
- walterbell 11y agoBills are often available via web download, an open-source personal archiver could be built for popular service providers. https://ipgmail.com/ https://ipgmail.com/ on iOS is usable for encrypted mail by mere mortals, when configured to attach the public key to outgoing emails. A robust, free offline mail archiver for Windows is http://www.mailstore.com/en/mailstore-home-email-archiving.aspx http://www.mailstore.com/en/mailstore-home-email-archiving.a..., aggregates and searches local and cloud mail.
- raphar 11y agoAnyone knows if there Is an alternative to this software? Having read their webpage, it appear to be good to consolidate all your accounts & mailboxes (new and old). But you end up with a new propietary mail storage and with propietary software that runs on windows :(
- walterbell 11y agoOn Linux, http://recoll.org http://recoll.org can provide the full-text search function, but you'll need other programs to consolidate the email and import/export between cloud services. http://alternativeto.net/software/mailstore-home/ http://alternativeto.net/software/mailstore-home/
- ketralnis 11y agoI'd like to use this, but AFAICT there's no way for me to ensure that the app--or future updates to the app--don't send my private keys off to a third party. Even accidentally, say as a debugging core sent on crash
- jerf 11y ago"Sending it over the wire in plaintext is probably being less of an issue now (as it seems the most used hosts are doing TLS)," Unfortunately, no, TLS in the SMTP world is basically a joke, security-wise. It can inconvenience a passive interceptor, but crumbles in the face of an active adversary, due to the fact that $NOBODY does cert checking, and consequently, nobody can do cert checking, because it would break their mail server, because nobody does cert checking properly.
- e12e 11y agoI've been thinking about experimenting with enforcing cert-checks on incoming tls/smtp. Possibly with a plain text smtp mx as fallback (through some kind of try-again-later greylist-like magic). Providing a fallback would negate the security benefit, obviously -- but might gather enough data for a whitelist (ish) of servers/sending domains which we can demand valid certs for. I'm not too concerned about bouncing valid email, as long as it doesn't create loops. Nor am I that worried about missing emails. As long as all the senders are a) mailing-lists that either should do the right thing, or will actually change to do the right thing if an error is reported, b) big free services like gmail/yahoo/outlook that might be divided into groups of "does the right thing" and "blacklist"/bounce to let any friend know that they need to send from "free service y, not x" -- and c) friends that run their own email servers and can be beaten (eh, educated) to compliance. I'd really not like to rely on some random CA list, though. I'm personally a cacert.org-fan/user -- but I suppose one might try to lean on DANE to avoid that particular hairball -- to some extent. It's either that or manual whitelist+trust on first use/some kind of pinning.
- jcrites 11y agoOne of the biggest security gaps in SMTP is that failing to establish TLS will result in falling back to plaintext; it's opportunistic TLS. Senders and receivers don't perform path validation because a validation failure will not stop a message from being sent -- it will just be sent with plaintext. The missing piece is widespread support for a way for receiving mail servers to declare that they support TLS (and optionally identify their CA or pin their certificate), such that it will instruct senders to connect with mandatory TLS instead of opportunistic TLS. With a protocol like this in place, senders can begin performing path validation of the receiver's certificate when they connect, but only for receivers who declare it, allowing an incremental nonbreaking rollout. Once widespread support is in place, we can begin making an effort to require validated certificates. By the way, you might be interested in Google's email transparency report, where they publish statistics on TLS adoption: http://www.google.com/transparencyreport/saferemail/ http://www.google.com/transparencyreport/saferemail/ I'd be interested to chat with anyone about email security and ideas to improve it; feel free to reach out. I would gladly put my support behind and implement a proposal that will solve these problems.
- peterwwillis 11y agoYou do realize the entire internet is run on servers and network devices you do not control, right? A bunch of intermediary relay mail servers of course all store and forward your mails. But there's also a couple dozen firewalls, traffic shapers, tunnels, bridges, routers, and managed switches that all have your e-mail. Who cares about disk storage when your e-mail is stored in 15 network device caches? Mail has never really been secure, from the days of Incan relay runners passing messages across thousands of miles, to the Pony Express, to the current US postal service. Unless you put an encrypted letter in your envelope, it can (and regularly does) get intercepted by malicious actors. We've gone this long with it being insecure, so I don't see what the big fuss is with the internet all of a sudden. Also: mail should be easy and universal. That's really the point of mail: that you can send a message to anyone, anywhere in the world, with one system, and it just works [while remaining inexpensive]. Anyone messing with it should always keep that in mind.
- howeyc 11y agoMaybe you commented after the title changed? Original title was "How secure is your email? here's email-in-a-box" (at least that's what I remember it was). My comment was basically "email is not secure." I think we agree on that point.
- peterwwillis 11y agoYes. I guess I was just (badly) making the point that since it's impossible to just communicate with one server you control, a secure mail paradigm should include servers we do not control.
- rlpb 11y ago> We've gone this long with it being insecure, so I don't see what the big fuss is with the internet all of a sudden. Dragnet surveillance was never practical before, due to the ongoing manpower required. With the Internet, that's changed.
- romseb 11y agoWith applications like Textsecure a lot of sensitive metadata accrues, still. One way around this can be https://bitmessage.org https://bitmessage.org
- tracker1 11y agoThis project is pretty awesome... though I'm not clear on what happens after you are setup. Does mail-in-a-box then provide the scripts to perform regular software updates and any configuration migrations between versions? There's more to running software than the initial setup... A complete Mail solution in a Unix-like environment consists of a lot of disconnected programs with their own configurations that are difficult to get running, and even more difficult to maintain without a full time systems administrator in place. I mentioned in another discussion recently how much I would love to see something akin to SmarterMail available as a simple package install Cross-Platform (one of the best mail server softwares out there imho, from a setup/upgrade POV) but commercial and tied to Windows for deployments... If I didn't have to work for a living, I'd probably start something like this. Mail services are usually made far more complicated than they should be, and I understand there are a lot of desired features... but I do feel that having a good module/plugin system that one could be developed that isn't the pain that current solutions are. To me a current mail solution should provide, SMTP, POP3, IMAP, WebMail, and WebAdmin at a minimum... Value adds would be easy multi-domain support, easy to configure AV/Spam plugins, Calendars + Sharing and Group Contact Sharing. Honestly, the only solutions with a relatively easy setup for this are for Windows... All the nix solutions are cobbled together bits that are very hard to upgrade and maintain versions and require a lot more breadth of knowledge than a single product. I've tried many of the systems for nix and they mostly suck in practice.. some more than others.
- joshdata 11y ago> Does mail-in-a-box then provide the scripts to perform regular software updates and any configuration migrations between versions? Yes it does.
- tracker1 11y agoThanks... I ran my own mail server for a number of years, but with only a handful of accounts, it finally became far easier to just outsource... I've been thinking of doing something like mail-in-a-box on a cloud/vps host, but the time/frustration in maintaining such a thing has kept me away.
- 11y ago
- userbinator 11y agoI never expect email to be secure; if it was necessary to transfer sensitive data via email, I'd just encrypt it with something like PGP.
- tomkwok 11y agoThis reminds me of Google Has Most of My Email Because It Has All of Yours [0]. [0]: https://news.ycombinator.com/item?id=7731022 https://news.ycombinator.com/item?id=7731022
- jwr 11y agoI am so glad this is finally happening. The mail-in-a-box project is something I think has been needed for many years now. I run my own mail server, but few people have the know how to run one, and so too much mail ends up either at Google (being harvested for ad targeting) or at crappy E-mail providers with lousy security practices.
- dmix 11y ago> I think has been needed for many years now Mail-in-a-box has been around since 2013. So it's been a few years now :)
- teekert 11y agoThis is great. On Ubuntu I always use "apt-get install mail-stack-exchange" which leaves you with STARTTLS enabled SMTP, IMAP, POP3 and, with the removal of 1 #, 587 submission. the users are the normal users of the system which automatically have a Maildir created upon receiving their first mail. This solution also gives you webmail though and DKIM. Very nice, I use the OwnCloud webmail which works ok for me (less features but very, very much better looking than Roundcube and I can sync calendar and contacts to the same server!) I think it is very important that projects like this one exist, they take the annoying details out of running your own server software. Thanks a lot!
- plg 11y agoWill this work on Debian Jessie?
- jedbrown 11y agoIt's interesting that this does not encrypt at rest (e.g., via dm-crypt). I'd rather not rely on Digital Ocean to protect access to their backups and prevent data from leaking to other droplets. Also, it requires a somewhat sophisticated attack to obtain the dm-crypt key from a running VM. https://news.ycombinator.com/item?id=6983097 https://news.ycombinator.com/item?id=6983097 https://www.digitalocean.com/company/blog/transparency-regarding-data-security/ https://www.digitalocean.com/company/blog/transparency-regar...
- cmdrfred 11y agoI just setup my own mail server with iredmail. I would've used this if it was available.
- rc4algorithm 11y agoI hate to be obstinate, but: 1) Most robust "security" of this form is negated if you're running it on a budget VPS. Those things are often extremely and unavoidably insecure for reasons out of your control (out-of-date VM software, insecure control panels, incompetent VM neighbors, etc.). 2) OpenBSD is probably the best option for this. Just use OpenSMTPD and choose a simple secure IMAP server from the ports. OpenBSD is perfectly suited for simple, security-critical applications like mail servers.
- frik 11y ago> OpenSMTPD Isn't it a SMTP server? If so that's just one of many parts of an email server.
- rc4algorithm 11y ago> and choose a simple secure IMAP server from the ports.
- frik 11y agoThanks a lot for this. This might be handy next time. I was thinking the other day: A simple open Go/Rust based self contained mail server (SMTP, IMAP) with a straight forward deployment would be a thing.