Live data from Hacker News

Show HN: Easily send encrypted email from your existing email

virtru.com

21–28 of 28 posts

Re: Show HN: Easily send encrypted email from your existing email

#21
post #8
post #6

Earlier quoted context omitted.

Encryption has been used in the past to keep emails secure from surveillance(PGP), but it has always been cumbersome to setup and use on both ends. Virtru's focus has been to make powerful encryption available to everyone by making it easy to use and with the services you and those you communicated with already use. Right now we have Chrome/Firefox support as well as an iPhone app...but many other clients soon.

PGP - one can store the keys on one's own server. In Virturo, it appears it has to be on Virutro servers. So hypothetically, we could have a Lavabit moment.

See my other comment about Virtru and allowing for self-hosted keys. We also don't host the content, so different laws apply..I think znelson commented on that somewhere in the thread already.

Re: Show HN: Easily send encrypted email from your existing email

#22
post #8
post #6

Earlier quoted context omitted.

Encryption has been used in the past to keep emails secure from surveillance(PGP), but it has always been cumbersome to setup and use on both ends. Virtru's focus has been to make powerful encryption available to everyone by making it easy to use and with the services you and those you communicated with already use. Right now we have Chrome/Firefox support as well as an iPhone app...but many other clients soon.

PGP - one can store the keys on one's own server. In Virturo, it appears it has to be on Virutro servers. So hypothetically, we could have a Lavabit moment.

I think it's been iterated before, but in the future we intend to open source our key serving software. There's still much work to be done on that front. We love PGP's crypto, but we found a few problems with it in general:

1) It's hard for the normal person. (The user experience for PGP is just horrendous)

2) Before you send an email to someone you have to know their public key.

With that said, we have done some research on integrating PGP like public key encryption along with our current key serving mechanism. With public key, using Virtru will be essentially equivalent to holding the keys yourself. Look for more of this in the future :-)

Re: Show HN: Easily send encrypted email from your existing email

#23
post #7

Earlier quoted context omitted.

Hey, that's a great question. We've put a lot of time and effort into thinking about this and have been working with some key people in the industry who have a lot of experience in this area. We've comprehensively addressed this issue on our blog. Here's the direct link: https://blog.virtru.com/faq-on-government-surveillance/ Let us know what you think.

> Q. What would Virtru do if it received a request > from the United States government for encryption keys? > A. We will require the government to go to court, > and if we can, we will notify you. To me that seems naive. You won't be able to notify anyone if you get a National Security Letter (NSL). Lavabit had turned over encryption keys for individual users, because they had to [1]. They only shut down when the gov…

Hi, it's Will Ackerly here. We've thought a lot about the National Security Letter scenario, and so, we're going to be pushing to our website a Canary (in the coal mine) icon, linking to a statement declaring that we have never received an NSL. Our special counsel on privacy (Tim Edgar, who used to work at ACLU) came up with the idea for us, which I believe Apple is using through regular reports (not a literal canary icon on their website).

Re: Show HN: Easily send encrypted email from your existing email

#25
post #16

Earlier quoted context omitted.

Also, our privacy policy contains details on how we handle user data: https://www.virtru.com/privacy-policy And we have a blog post discussing some frequently asked questions on government surveillance: https://blog.virtru.com/faq-on-government-surveillance/

about blog: yeah, I agree you need to obey the laws and everything, but does the law state that you need to store the keys? Until the law does, keeping all the keys in one place is an invitation for the bear to get the honey. If all the honey was in separate honeycombs, the bear might still get them all, but would probably have a tad bit more work to do. Atleast hypothetically :).

That is one reason why the underlying tech we're using, particularly the TDF, is designed to allow you to use any key server you want. Our hope is that we're the first of many TDF key servers out there, and are working to open source a key server under Apache license so anyone can use and contribute. If you're interested in helping make that possible or know people who might be, let us know.

Re: Show HN: Easily send encrypted email from your existing email

#26
post #17

Earlier quoted context omitted.

Nope. > However, you’re entrusting us to help you maintain your privacy; you should know how we will respond if the government asks us for access to your encryption keys. The government would need those keys if it wanted to read any encrypted files it does obtain. Without them, the files are useless. > We won’t provide your keys to anyone without your consent — unless we are ordered to divulge them by a judge with ju…

so from a security standpoint, this is equivalent to the status quo, except transferring responsibility from Google to a small startup for maintaining keys? I'd be shocked if google doesn't encrypt emails at rest. Is there still plenty of inflight unencrypted SMTP traffic to worry about that this could address? I guess you have to worry about the recipient if you are sending email to a non gmail/hotmail/ymail address…

>> I guess you have to worry about the recipient if you are sending email to a non gmail/hotmail/ymail address?

Virtru allows you to send securely to any recipient, regardless of the email provider they use. The easiest way to read the secure message is to use the Virtru software to integrate with your existing email client.

Our iPhone client uses IMAP, so it works with any email provider that supports IMAP.

Our browser extension currently integrates with Gmail, Yahoo, and Outlook.com. If the Virtru browser extension does not integrate with your email provider, then we provide a mechanism to read the secure email in your browser without installing anything. However, you cannot reply securely without the Virtru software.

Re: Show HN: Easily send encrypted email from your existing email

#27

Earlier quoted context omitted.

> Q. What would Virtru do if it received a request > from the United States government for encryption keys? > A. We will require the government to go to court, > and if we can, we will notify you. To me that seems naive. You won't be able to notify anyone if you get a National Security Letter (NSL). Lavabit had turned over encryption keys for individual users, because they had to [1]. They only shut down when the gov…

Hi, it's Will Ackerly here. We've thought a lot about the National Security Letter scenario, and so, we're going to be pushing to our website a Canary (in the coal mine) icon, linking to a statement declaring that we have never received an NSL. Our special counsel on privacy (Tim Edgar, who used to work at ACLU) came up with the idea for us, which I believe Apple is using through regular reports (not a literal canary…

Rsync.net uses a warrant canary as well:

http://www.rsync.net/resources/notices/canary.txt

I've actually found it kind of surprising that they haven't had any warrants yet.

But you're going to be served with an NSL if you get big enough to be interesting. It seems to happen to everyone. An then you won't be able to update the canary any more. That's a good idea, but I don't think it is enough.

I don't mean to be negative, I just guess I don't see why you'll succeed against the government when the others have not.

Re: Show HN: Easily send encrypted email from your existing email

#28

Earlier quoted context omitted.

Hi, it's Will Ackerly here. We've thought a lot about the National Security Letter scenario, and so, we're going to be pushing to our website a Canary (in the coal mine) icon, linking to a statement declaring that we have never received an NSL. Our special counsel on privacy (Tim Edgar, who used to work at ACLU) came up with the idea for us, which I believe Apple is using through regular reports (not a literal canary…

Rsync.net uses a warrant canary as well: http://www.rsync.net/resources/notices/canary.txt I've actually found it kind of surprising that they haven't had any warrants yet. But you're going to be served with an NSL if you get big enough to be interesting. It seems to happen to everyone. An then you won't be able to update the canary any more. That's a good idea, but I don't think it is enough. I don't mean to be nega…

Great points, definitely not negative, just realistic.

There may be no single silver bullet here. In addition to pursuing open source key servers, we're also working on UI/UX for easy addition of public key wrapping using the same crypto as PGP. Our hope is that we can deploy public key in a way that most people start using it to minimize the proportion of unwrapped keys on Virtru's server.

Post reply on HN