Live data from Hacker News

It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

27months.com

11–20 of 53 posts

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#11
"Server software and all packages are open source."

From what source and how were they validated, both from a secure checksum perspective and code audit? Was a full application pen-test done on each package after installation and configuration? Additionally, what controls are running server-side to audit memory execution and modifications on disk? Is Tripwire being used as an example? How about Wireshark? Is it being used to monitor all traffic from the host NICs with alerts sent out if it spots any non-encrypted traffic or traffic to IP addresses not explicitly white-listed? How about ongoing monitoring for zero-days for each of the packages used?

Nothing I read in the article leads me to believe there is any NSA proofing here whatsoever. Making something secure isn't about finding a "secure" data center and hosting a solution yourself. In fact, self hosted solutions can be some of the toughest to secure because you must have a broad and deep knowledge of security as it relates to the entire environment and then keep up with package changes in a way which results in auditing each and every future change. Honestly, no one has time for that and even if secure at x point in time, it won't be at y point, say when a Hartbleed level vuln is announced for a package used while the author is on vacation and can't reach his servers to appropriately mitigate.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#12
I'm really surprised this could be NSA-Proofed without the use of true end-to-end encryption tech. There is no mention of PGP for instance.

Using PGP (with a locally stored private key) is one of the best option I'm aware of to secure emails and continue to use email cloud clients like gmail or yahoo.

The only caveat is that you loose search which is one of the requirements in the article.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#13
This is a post from 2013, any pointer as to how this could be improved in this post-CISA world? The part about the location seems to still be relevant.

As for spooky23, while most your email recipients might be NSA accessible, maybe not _all_ of them are. If you manage to keep your email account confidential, then peeping toms only have a partial view of your social graph (the part that is in your compromised correspondent inbox).

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#14
post #2

How do you prevent mail that you send from going to recipients whose mail is not hosted in your magical Icelandic data bunker? End of the day, all of this stuff is nonsense. The only thing standing between your stuff and unauthorized access is your contract and the actions of the third party running the datacenter. The only way you can exert any meaningful control over your data is to host it yourself... as in have c…

Then you have to make sure all your hardware wasn't Carly Fiorina'd through an NSA shipment interception.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#15
No, e-mail was not originally designed for you to host it yourself. E-mail was designed for a system operator to maintain a server for many other users.

Aside from the many maintenance problems of hosting e-mail yourself, the biggest problem here is the distance: Iceland is far away from the user in the USA. Latency doesn't matter so much for e-mail, but connectivity does, and if there's a problem with a transatlantic link (which does happen on occasion) there goes your most important communications medium.

Finally, the biggest fallacy with e-mail is that it is ever secure. It's never secure. The mail on your client devices is unencrypted, and if you ever reply, forward, or send an e-mail to anyone it's very likely for the whole thread go over an unencrypted relay and be stored temporarily, not to mention the logs, and the unencrypted storage on the destination, etc.

Your physical mail isn't secure in the postal service, and neither is your virtual mail in the e-mail service.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#16
In marketing speak "NSA proof" is the new post-Snowden[1] "military grade encryption"

Email is hard to secure and identified personal accounts are difficult to keep private.

The "better" answer is to do what those on Wall St figured out after various scandals and Sarbanes-Oxley - if you want something to remain private keep it off email.

[1] Sorry.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#17
post #16

In marketing speak "NSA proof" is the new post-Snowden[1] "military grade encryption" Email is hard to secure and identified personal accounts are difficult to keep private. The "better" answer is to do what those on Wall St figured out after various scandals and Sarbanes-Oxley - if you want something to remain private keep it off email. [1] Sorry.

>Email is hard to secure

Email is trivial to secure. Just need to be able to exchange OOB one RSA key.

But being able to securely communicate with "isis_recruiter34@jihadistan.jihad" don't give you much when LEO knows that you are communicating with each other.

Nowadays you need security, anonymity and usability - which are often with contradicting requirements.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#18
My biggest gripe is not the server (I run my own), it's the client(s). Currently I use Trojita on the desktop and K-9 on my mobile. I never managed to get PGP to play with Trojita, so for signing/encrypting/decrypting I have Claws installed as well. Trojita often randomly hangs and needs to be killed. K-9 is functional, but is to mail what Gimp is to painting..

Mailpile (I'm a backer) might be interesting, but is still unstable and the future isn't certain for happy reasons (i.e. 'paternity leave'). Stumbled upon Whiteout from the references in the mailpile blog, only to learn that the company behind that effort is dead. No clue if or how this project will continue.

I regularly see (new) mail clients mocked as 'unnecessary', but I'm still waiting for a decent one. Mail as a medium works incredibly well for me, but it feels unpolished to use whereever I am.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#19
In his "overview of features" he is missing one very interesting and valuable security gain when you host your own mail server:

- local mail delivery does not traverse any network

So if you are user A on a mailserver and your wife/friend/uncle is user B, when you send mail to them that mail is simply a local copy operation (provided they don't POP or IMAP it to a local mailtool).

That's pretty interesting, I think.

It may interest you to know that no piece of rsync.net company email has ever traversed a network - everyone logs in via SSH and uses (al)pine and all internal mail is just local copy ...

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#20
post #16

In marketing speak "NSA proof" is the new post-Snowden[1] "military grade encryption" Email is hard to secure and identified personal accounts are difficult to keep private. The "better" answer is to do what those on Wall St figured out after various scandals and Sarbanes-Oxley - if you want something to remain private keep it off email. [1] Sorry.

While "NSA proof" might be marketing speak, there are new innovative solutions that make it easier to secure email data and harder for entities such as the NSA and others to hack into the email.

One such end-to-end email encryption solution can be found at www.jumble.io

The "better" answer of not putting sensitive information into email is true for all industries, however, more companies are installing end-to-end email encryption solutions to comply with SOX and mitigate risk in the event of a breach.

Post reply on HN