Live data from Hacker News

Show HN: Easily send encrypted email from your existing email

virtru.com

11–20 of 28 posts

Re: Show HN: Easily send encrypted email from your existing email

#11
post #4

So, can I keep the keys myself instead of storing them in the cloud? Or do I have to trust Virtru instead of google or some other company that they don't buckle when someone comes knocking for the keys? Based on the feature list, I can't have the keyserver on my own server. I have to trust Virtru. This is no different than sending the text in plain IMO.

So as of this moment, you can't keep the keys yourself. Our technology absolutely allows for self-hosted keys. We do have private key managers being developed, which we intend to open source, and be for private use. It will be an option for the those that want the responsibility of keeping the keys safe, and also address your concern.

Re: Show HN: Easily send encrypted email from your existing email

#12
post #7

How can Virtru help email users who are concerned with government surveillance activities that have been revealed in the last year?

Hey, that's a great question. We've put a lot of time and effort into thinking about this and have been working with some key people in the industry who have a lot of experience in this area. We've comprehensively addressed this issue on our blog. Here's the direct link: https://blog.virtru.com/faq-on-government-surveillance/ Let us know what you think.

     > Q. What would Virtru do if it received a request 
     >    from the United States government for encryption keys?

     > A. We will require the government to go to court, 
     >    and if we can, we will notify you.
To me that seems naive. You won't be able to notify anyone if you get a National Security Letter (NSL). Lavabit had turned over encryption keys for individual users, because they had to [1]. They only shut down when the government wanted their SSL key, to give access to everyone.

How are you any different?

[1] http://en.wikipedia.org/wiki/Lavabit

Re: Show HN: Easily send encrypted email from your existing email

#13
post #11
post #4

So, can I keep the keys myself instead of storing them in the cloud? Or do I have to trust Virtru instead of google or some other company that they don't buckle when someone comes knocking for the keys? Based on the feature list, I can't have the keyserver on my own server. I have to trust Virtru. This is no different than sending the text in plain IMO.

So as of this moment, you can't keep the keys yourself. Our technology absolutely allows for self-hosted keys. We do have private key managers being developed, which we intend to open source, and be for private use. It will be an option for the those that want the responsibility of keeping the keys safe, and also address your concern.

great. Thanks. Will signup when it becomes available :)

Re: Show HN: Easily send encrypted email from your existing email

#14
post #7

Earlier quoted context omitted.

Hey, that's a great question. We've put a lot of time and effort into thinking about this and have been working with some key people in the industry who have a lot of experience in this area. We've comprehensively addressed this issue on our blog. Here's the direct link: https://blog.virtru.com/faq-on-government-surveillance/ Let us know what you think.

> Q. What would Virtru do if it received a request > from the United States government for encryption keys? > A. We will require the government to go to court, > and if we can, we will notify you. To me that seems naive. You won't be able to notify anyone if you get a National Security Letter (NSL). Lavabit had turned over encryption keys for individual users, because they had to [1]. They only shut down when the gov…

Unlike lavabit we're not a content provider and therefore not bound by the same laws. We're just a third-party provider that holds the keys. #7 on the blog post here goes into more details: https://blog.virtru.com/faq-on-government-surveillance/

Re: Show HN: Easily send encrypted email from your existing email

#15
post #11
post #4

So, can I keep the keys myself instead of storing them in the cloud? Or do I have to trust Virtru instead of google or some other company that they don't buckle when someone comes knocking for the keys? Based on the feature list, I can't have the keyserver on my own server. I have to trust Virtru. This is no different than sending the text in plain IMO.

So as of this moment, you can't keep the keys yourself. Our technology absolutely allows for self-hosted keys. We do have private key managers being developed, which we intend to open source, and be for private use. It will be an option for the those that want the responsibility of keeping the keys safe, and also address your concern.

Also, our privacy policy contains details on how we handle user data: https://www.virtru.com/privacy-policy

And we have a blog post discussing some frequently asked questions on government surveillance: https://blog.virtru.com/faq-on-government-surveillance/

Re: Show HN: Easily send encrypted email from your existing email

#16
post #11

Earlier quoted context omitted.

So as of this moment, you can't keep the keys yourself. Our technology absolutely allows for self-hosted keys. We do have private key managers being developed, which we intend to open source, and be for private use. It will be an option for the those that want the responsibility of keeping the keys safe, and also address your concern.

Also, our privacy policy contains details on how we handle user data: https://www.virtru.com/privacy-policy And we have a blog post discussing some frequently asked questions on government surveillance: https://blog.virtru.com/faq-on-government-surveillance/

about blog: yeah, I agree you need to obey the laws and everything, but does the law state that you need to store the keys?

Until the law does, keeping all the keys in one place is an invitation for the bear to get the honey. If all the honey was in separate honeycombs, the bear might still get them all, but would probably have a tad bit more work to do.

Atleast hypothetically :).

Re: Show HN: Easily send encrypted email from your existing email

#17
post #4

So, can I keep the keys myself instead of storing them in the cloud? Or do I have to trust Virtru instead of google or some other company that they don't buckle when someone comes knocking for the keys? Based on the feature list, I can't have the keyserver on my own server. I have to trust Virtru. This is no different than sending the text in plain IMO.

Nope. > However, you’re entrusting us to help you maintain your privacy; you should know how we will respond if the government asks us for access to your encryption keys. The government would need those keys if it wanted to read any encrypted files it does obtain. Without them, the files are useless. > We won’t provide your keys to anyone without your consent — unless we are ordered to divulge them by a judge with ju…

so from a security standpoint, this is equivalent to the status quo, except transferring responsibility from Google to a small startup for maintaining keys? I'd be shocked if google doesn't encrypt emails at rest. Is there still plenty of inflight unencrypted SMTP traffic to worry about that this could address? I guess you have to worry about the recipient if you are sending email to a non gmail/hotmail/ymail address?

Re: Show HN: Easily send encrypted email from your existing email

#18
post #13
post #11

Earlier quoted context omitted.

So as of this moment, you can't keep the keys yourself. Our technology absolutely allows for self-hosted keys. We do have private key managers being developed, which we intend to open source, and be for private use. It will be an option for the those that want the responsibility of keeping the keys safe, and also address your concern.

great. Thanks. Will signup when it becomes available :)

Out of curiosity, on which platform would you want to run the self-hosted server?

Re: Show HN: Easily send encrypted email from your existing email

#19
post #17

Earlier quoted context omitted.

Nope. > However, you’re entrusting us to help you maintain your privacy; you should know how we will respond if the government asks us for access to your encryption keys. The government would need those keys if it wanted to read any encrypted files it does obtain. Without them, the files are useless. > We won’t provide your keys to anyone without your consent — unless we are ordered to divulge them by a judge with ju…

so from a security standpoint, this is equivalent to the status quo, except transferring responsibility from Google to a small startup for maintaining keys? I'd be shocked if google doesn't encrypt emails at rest. Is there still plenty of inflight unencrypted SMTP traffic to worry about that this could address? I guess you have to worry about the recipient if you are sending email to a non gmail/hotmail/ymail address…

>> I'd be shocked if google doesn't encrypt emails at rest

Virtru encrypts email content on the client side, so your email is protected before it ever leaves your computer. That gives you protection in transit and at rest

Re: Show HN: Easily send encrypted email from your existing email

#20
post #4

So, can I keep the keys myself instead of storing them in the cloud? Or do I have to trust Virtru instead of google or some other company that they don't buckle when someone comes knocking for the keys? Based on the feature list, I can't have the keyserver on my own server. I have to trust Virtru. This is no different than sending the text in plain IMO.

Nope. > However, you’re entrusting us to help you maintain your privacy; you should know how we will respond if the government asks us for access to your encryption keys. The government would need those keys if it wanted to read any encrypted files it does obtain. Without them, the files are useless. > We won’t provide your keys to anyone without your consent — unless we are ordered to divulge them by a judge with ju…

One of our core goals is to bring privacy to the masses without poeple needing to completely ditch their current accounts and infrastructure. We want to seamlessly integrate with the apps people already use so that even non-technical people can use it.

DarkMail would require people to completely ditch everything and jump to a new system.

But for the super-security minded folks we're researching ways we can seamlessly integrate PGP like capabilities into the product so that Virtru would never even be in a position to see the keys at all.

Post reply on HN