Live data from Hacker News

Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

silentcircle.wordpress.com

141–150 of 217 posts

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#141

Since it hasn't been mentioned yet, OS X and iOS already support S/MIME encrypted email, and having the private keys live on users' devices and doing encryption of outgoing messages on users' devices is probably the safest setup.

Hmmm, I don't know if I'm being outrageously paranoid, but I'm resisting the temptation to put my PGP private key on my iPhone - because it'd be _way_ too easy for Apple to extract the key/passphrase if they were coerced by someone powerful enough, and those "powerful enough" have shown that they consider a court order granting them the private key used to secure 400,000 people's email is an appropriate tool when targeting a single individual.

Once that's known, is it really such a stretch to assume that an already complicit PRISM partner might be convinced/coerced to monitor downloads of crypto-capablea app from their respective app-stores, and provide or allow backdoors to their OS that leak private keys?

Maybe that's being overly paranoid, but in the "post Snowden" era, it might just be a sensible and pragmatic view…

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#142
post #89

Earlier quoted context omitted.

Freedom \ Liberty \ Patriot \ Constitution Mail would be very effective in blocking political speeches and biased headlines from cheap attacks. My personal favorite is Lincoln Mail... Seems highly appropriate on many levels and should be FOX News proof.

Lincoln Mail would be shot while in the Security Theater.

aoh SNAAAPP

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#143
post #89

Earlier quoted context omitted.

Freedom \ Liberty \ Patriot \ Constitution Mail would be very effective in blocking political speeches and biased headlines from cheap attacks. My personal favorite is Lincoln Mail... Seems highly appropriate on many levels and should be FOX News proof.

As a non-American, all of these terms remind me of irritating American flag-waving rhetoric (the kind used to justify the types of things that the NSA is doing right now, for that matter), and I would wager most of the world would feel the same.

So why not use multiple brands? I don't think the name is to be taken lightly at all, and naming it in such a way that doesn't make it such an easy target could do some real good. They just need to bring the tech, and then we can have a whole laundry list of names suitable for different languages/cultures.

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#144
post #84
post #73

Earlier quoted context omitted.

"Well, Bob, as your viewers may know, 'Smith Mail' came out of a group that calls themselves 'The Dark Mail Alliance'. This is a group of anti-government hackers that..."

"... keep their software in a so called 'subversion' repository, clearly for nefarious ends."

If they do not comply we will be forced to rebase all your mails, they belong to us.

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#146

The site http://www.darkmail.info/ is served over http and not https. If someone has access to the pipe, it would be easy get the email addresses of people who submit their email addresses at that site.

The marketing system they're using is Mailchimp which I'm sure is also easy to access for anyone who might've been able to snoop emails off the HTTPS version of DarkMail.info

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#147
post #90

Earlier quoted context omitted.

> you should also solve the spam problem as part of the protocol. I disagree. Different problems sometimes require mutually exclusive solutions. In fact, receiving lots of unsolicited mail provides some plausible deniability. So a spam free-for-all might actually be a useful part of the new network.

Or you know, renders the system completely worthless because no one can sort through that much spam. Which also makes it completely trivial to DDoS into oblivion. And the problem gets worse then that: the more anonymous it is, the less it's possible to stop someone from spamming. Though I suppose you could attack this problem from the email address side: make it computationally expensive to general an email address,…

[deleted]

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#148

Earlier quoted context omitted.

I agree with the barrier. I wonder if the NSA has made surmounting that barrier possible. If the friction to getting a 'secure' email experience is low enough, people will put up with having two for a while. As for connecting them. I could handle just being able to communicate with my security conscious friends on this platform. That might make it a niche play early on but so was email.

Call me cynical, but for all the public outrage worldwide I'm pretty sure that even that outcry comes from a minority.

I think it is quite rational to be cynical about it, but before you completely write it off, consider what the cynics said about email when it was small. Basically email was characterized as a way for nerds to exchange jokes that either everyone had already heard, or nobody understood.

I recall that in 1979 exactly nobody in my family (except me) had a network email account (on USC-ECLC no less) and they didn't care. What my family had worked for them and it was just sillyness on my part to think that email added anything to the mix.

What mattered though was that enough people had email accounts that they could get more done, more efficiently, than people without email. Every year that converted more and more people to the idea that email was something they should have, by 1999 everyone thought they should have one even if they weren't sure why.

I see similar thinks with a reconstructed email system that is free from surveillance. People being able to joke about things or discuss things and not find themselves unable to board a flight because they joked about something the TSA considered suspicious. You and I may not have had that experience yet but folks have, and it is getting more common not less common. We just had a law enforcement officer drive up and shoot a kid dead because he was carrying a toy gun. He thought the gun might be real. I say that "Clubs in NYC are the bomb!" I don't want someone detaining me for four hours asking me what exactly I meant by that.

As few as 3 years ago I would not have considered a system like this something that "regular" people would want to use, and that would inhibit adoption and use. But now I am not so sure about that.

I agree that the 'outrage' is a minority, but it is coming from more people than it ever has before. At some point the minority is large enough to be a 'useful subset' and once it becomes self supporting I've seen otherwise "useless" products become part of everyday life. It is that change, that I wonder about here.

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#149

I appreciate the cheekiness of calling it the "Dark Mail Alliance", but from a purely PR perspective, it would make sense to reconsider your name if you are taking the position that encrypted end-to-end email is not solely an interest of those pursuing shady or deviant activities.

I totally agree, I really think you should change the name. Some suggestions: - Locke Mail [from John Locke] - Mill Mail [from John Stuart Mill] - Hobbes Mail - Liberty Mail

Liberty Mail seems cheesy and try-hard.

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#150

Earlier quoted context omitted.

I think the biggest barrier to entry of any new and secure email protocol will be GMail. GMail (and similar services) are what most people seem to use at this point. And GMail won't update to 3.0 in any meaningful way, no matter what, since they want to be able to mine the data in your email, so they will still be storing it on their servers "in the clear." Which means the next time NSA hacks their servers, they'll s…

> GMail won't update to 3.0 in any meaningful way, no matter what Perhaps this problem can be addressed by having a plugin/add-on/extension that decrypts the mail within the browser. GMail, Yahoo, or other mail providers that don't adopt this new and secure email protocol won't get the plaintext of your message, and preferably not the metadata either. This requires that the new protocol use a converter or proxy or so…

Maybe people could run a local app/filter that extracts keywords from our own mail and shares them with google. Leave the power completely in our hands to give to google what we feel like giving them.
Post reply on HN