Live data from Hacker News

A Hacker's Replacement for Gmail

dbpmail.net

211–218 of 218 posts

Re: A Hacker's Replacement for Gmail

#211
post #194

Earlier quoted context omitted.

got a hash of the boot partition, validate when it comes back up.

How do you know that you're not logging in to a vm, with all the data mirrored from your physical server?

This is reasonably clever, but how do you get a full disk mirror from a server you can't get into without powering off, if you do power off, the amount of time the system is down is a tipoff to the target as to what's going on.

Assuming however it could somehow be pulled off; I guess potential ways to mitigate would be to keep a copy of the exact hardware characteristics of the system you originally have, kernel log on bootup, precise size of disks, chipsets of all the various controllers and compare when the system reboots. It would however be possible though extremely hard to get an exact duplicate of all of these at the virtualisation layer level.

You could call the virtualisation layer in the cpu requesting access to virtualise a subsystem, clock the data bus speeds... There should be some overhead from virtualisation that wasn't there when dedicated...

It's an interesting problem. I'll think more about it.

Re: A Hacker's Replacement for Gmail

#212

Earlier quoted context omitted.

Pidgin is predominantly developed for Linux, where they would have to support Gnome, KDE and probably at least one other mechanism. Sure, that could be done, but it is a lot of work to do that sensibly on all platforms, and, more importantly, of questionable sense: I would classify the logs of my conversation as much more relevant to a potential attacker than the mere password to my XMPP account.

All of this is true. But when the Pidgin devs state things like "there's no way" and "it's just as secure" (as they do on the wiki), that's just incorrect. An intellectually honest description would note that many platforms offer protection, but it's not standardized across Linux (I'm assuming). The logs of the conversation can be protected in the same way, so I'm not sure what that has to do with anything. (Although…

The wiki explicitly says (under “Is that the final word?”):

> No. The Pidgin developers are generally open to, and would encourage integration with keyrings (KeyringSupport).

and then goes on to state that this is difficult to do, since Pidgin runs on so many different platforms, then stating again that they will happily accept such patches.

However, I find it understandable, that the devs don’t go out of their way to support use-cases they don’t feel necessary to support. On their systems, they trust the filesystem and are happy with that, if others don’t have that level of trust in their computer, that’s fine, but not necessarily their problem.

My point about the logfiles was that to store these in the keyring (rather than a key to the encrypted files) would probably annoy the keyring somewhat (at least the poorer implementations thereof), given that it is intended for use with few-byte passwords and not multi-megabyte logfiles.

Re: A Hacker's Replacement for Gmail

#213
post #208

Earlier quoted context omitted.

Is mailgun a US-based company that would comply with a national security letter if faced with one?

What about Digital Ocean or another VPS provider? What is to stop them from just handing the NSA a copy of my server image complete with all email history, address book, and authorized PGP keys? I'd have even tagged and indexed all the mail for them!

Yes, that's the point. If you are worried about Google cooperating with the NSA, and you decide to roll-your-own mail solution, but are using US-based services like MailGun, you are doing it wrong. :)

Moving to a self-hosted solution (even a US one) offers you more privacy protection options than Gmail/Hotmail, that's for sure. But since physical access is everything, using a US-based VPS provider means there is only a small speedbump between the government and your mail. Using a US-based service like Mailgun, while extremely cool, removes even this speedbump, since they will presumably be forced to cooperate in the same way that Google or Yahoo do.

The best option would be to host your own mail with a VPS with a very strong privacy record, explicit statements about not cooperating with US inquiries, based and hosted in a country with strong privacy protections.

Re: A Hacker's Replacement for Gmail

#214

Earlier quoted context omitted.

All of this is true. But when the Pidgin devs state things like "there's no way" and "it's just as secure" (as they do on the wiki), that's just incorrect. An intellectually honest description would note that many platforms offer protection, but it's not standardized across Linux (I'm assuming). The logs of the conversation can be protected in the same way, so I'm not sure what that has to do with anything. (Although…

The wiki explicitly says (under “Is that the final word?”): > No. The Pidgin developers are generally open to, and would encourage integration with keyrings (KeyringSupport). and then goes on to state that this is difficult to do, since Pidgin runs on so many different platforms, then stating again that they will happily accept such patches. However, I find it understandable, that the devs don’t go out of their way t…

The wiki does mention some info, yes. But it also makes a false comparison, noting how you can extract passwords on a system, and implying that the level of security is identical. That's 100% false, and to suggest so is being very misleading.

As far as logs, do what everyone does when you can only store a bit of material: Store your bulk encryption key there.

Re: A Hacker's Replacement for Gmail

#215
post #194

Earlier quoted context omitted.

How do you know that you're not logging in to a vm, with all the data mirrored from your physical server?

This is reasonably clever, but how do you get a full disk mirror from a server you can't get into without powering off, if you do power off, the amount of time the system is down is a tipoff to the target as to what's going on. Assuming however it could somehow be pulled off; I guess potential ways to mitigate would be to keep a copy of the exact hardware characteristics of the system you originally have, kernel log…

Please note that as soon as you've typed in the key needed to unlock the disk in the vm, your data is compromised. So any verification you attempt, has to be made from the unencrypted boot image...

As for time needed, assume this: The attacker sets up a physical server that can accept the same physical disks as your server (with hotswap), with an additional disk (or ssd) for booting into a hypervisor, sets parameters for this hypervisor to closely mirror that of your server. The attackers server would typically be faster than yours -- it is/can be bought some time after your server was, so this should almost be universally possible.

The attacker boots the vm server, sets everything up; then kills power to your machine, moves the disks over. Your downtime: the time it takes to move the disks (literally).

Good luck differentiating between this and legitimate downtime.

I still think reading the encryption keys from RAM after cooling them with some co2 would be the more likely attack, but it's a fun thought experiment...

Re: A Hacker's Replacement for Gmail

#216
post #128
post #39

Earlier quoted context omitted.

Does anyone know, if I used z-push for a product, would I be liable for not buying a license from Microsoft, for Exchange ActiveSync? It seems they are fairly litigious with activesync patents.

The protocol is patented [0]. If you want to offer your product in the US (and other places that care about software patents), you need a license. Also note that Z-Push is AGPLv3 software. Unless you can get it under another license from Zarafa, you have to release your product with an AGPL-compatible license. [0] http://www.microsoft.com/en-us/legal/intellectualproperty/IP...

thanks

Re: A Hacker's Replacement for Gmail

#217
post #153

Earlier quoted context omitted.

I've been using FastMail for a while and I like it a lot. Actually I love the fact that it uses folders instead of tags. The only problem I have with FastMail is that I've been receiving an increased amount of spam in my inbox.

Did you set up the advanced spam filtering and then train it on all of your folders? I also set the super-advanced options and changed the thresholds to around 3.0 (instead of the default, which was I think 5.0), which really helped. It's better than when I hosted on gmail, but I'd say 5-10 per day still get through and have to be reported, after about a month on fastmail. That's only a couple of percent, though (sca…

I contacted support and they did setup the super-advanced options for me. It seems to be much better now.

Re: A Hacker's Replacement for Gmail

#218
post #215

Earlier quoted context omitted.

This is reasonably clever, but how do you get a full disk mirror from a server you can't get into without powering off, if you do power off, the amount of time the system is down is a tipoff to the target as to what's going on. Assuming however it could somehow be pulled off; I guess potential ways to mitigate would be to keep a copy of the exact hardware characteristics of the system you originally have, kernel log…

Please note that as soon as you've typed in the key needed to unlock the disk in the vm, your data is compromised. So any verification you attempt, has to be made from the unencrypted boot image... As for time needed, assume this: The attacker sets up a physical server that can accept the same physical disks as your server (with hotswap), with an additional disk (or ssd) for booting into a hypervisor, sets parameters…

Not sure if anyone will see this, this late, but someone else recently posted this presentation on Rakasha, a malware based on top of coreboot open bios and friends -- so if you know the type of server, you might just pop up the cover and switch out the BIOS...:

https://www.youtube.com/watch?v=yRpilXPv8pU

Post reply on HN