Live data from Hacker News

It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

27months.com

1–10 of 53 posts

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#2
How do you prevent mail that you send from going to recipients whose mail is not hosted in your magical Icelandic data bunker?

End of the day, all of this stuff is nonsense. The only thing standing between your stuff and unauthorized access is your contract and the actions of the third party running the datacenter. The only way you can exert any meaningful control over your data is to host it yourself... as in have computers and storage that hold your stuff running in your home.

Even then, making a statement like "I NSA-Proofed my email" is either self-delusional or clueless.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#3
The idea that putting your server in Iceland somehow makes it NSA-proof seems questionable. If anything, Google's servers in the US are likely better protected both legally and by Google's resources.

The FBI had little trouble getting access to Robert Ulbricht's servers, with the help of the Reykjavik Metropolitan Police.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#5
Seems like a pretty superficial take on the topic. In particular:

- No mention of reputation, the hardest part of self-hosting email

- Advises using StartSSL, so he hasn't purged his trust store of root CAs under the NSA's control (given StuxNet and the relationship between the US and Israel, Israel isn't a country that's free from NSA influence)

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#6
SMTP authentication is broken. Don't rely on it for confidentiality. There is no cert-pinning RFC for STARTTLS afaik, so stripping attacks on STARTTLS are still possible. And, by far the most important: most of the world uses a large E-mail provider. So, if you send a mail to someone using Gmail/Yahoo Mail/Outlook, your "confidential" data is leaked. And don't forget metadata leakage. Metadata is by far more interesting for the NSA than then the content of your mails.

I use Gmail + GPG (almost nobody uses GPG) in Thunderbird. When I truly need confidentiality over internet communication, I use Signal.

SMTP is just plain broken in a sense of security.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#8
post #3

The idea that putting your server in Iceland somehow makes it NSA-proof seems questionable. If anything, Google's servers in the US are likely better protected both legally and by Google's resources. The FBI had little trouble getting access to Robert Ulbricht's servers, with the help of the Reykjavik Metropolitan Police.

> The FBI had little trouble getting access to Robert Ulbricht's servers, with the help of the Reykjavik Metropolitan Police.

Notably in that case, the Icelandic police did not even seek a court order, as they didn't need to since the server was owned by a US citizen. They just got a letter from the US police and decided to perform a raid. So you're absolutely right.

I'd question the technical compentency of anyone who would claim to have "NSA-proofed" anything without expounding further on the threat model.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#10
Hi, Iceland checking in here. While we appreciate you hosting here, we're by no means any safer than other countries now. First I'll note that this posting is from 2013, so quite a bit has changed here since that time. IMMI (immi.is) is still being hashed out in parliaments and making slow progress. Meanwhile we've had some particularly ridiculous public spectacles regarding ppl hosting data here in Iceland thinking it was safe. Here's a few:

Silk Road Iceland http://www.wired.com/2014/09/the-fbi-finally-says-how-it-leg...

ISIS domain name take down http://english.alarabiya.net/en/media/digital/2014/10/18/In-...

Iceland ISP's block TPB http://grapevine.is/news/2015/09/16/icelandic-isps-will-bloc...

Iceland BGP route attack http://www.internetsociety.org/deploy360/blog/2014/02/bgp-hi...

Rememeber that ashley madison hack? our prime minister had credentials on it! http://icelandmag.visir.is/article/icelandic-minister-financ...

Iceland seeks to ban porn http://www.theguardian.com/world/2013/feb/25/iceland-seeks-i...

I won't even get into our limited internet connectivity and resulting high IP transit rates. I'm not saying don't host here in Iceland, but do some research first.

Post reply on HN