Live data from Hacker News

Dark Mail Technical Alliance

darkmail.info

11–20 of 54 posts

Re: Dark Mail Technical Alliance

#11

I watched Citizenfour yesterday and one of the really disturbing parts of movie was Lavabit founder talking at European Parliament about why he had to shut it down. I am glad that something good is coming up. But can we please change name from 'dark' to something like 'secure, encrypted etc'? Dark inherently sounds negative, at least in my part of the world.

He had to shut it down - but as far as I remember, they got the SSL key anyway. None can tell me that providing it in a font size of 4pt would have stopped them. I think that typing 2560 chars is not that hard.

Re: Dark Mail Technical Alliance

#12
post #10

3 of 5 comments so far mentioning that the name is a mistake. Allow me to make that 4 of 6. Come on guys, authoritarians are going to argue that this is just about defending criminals and terrorists, do you want to make that argument for them? Call it 'Liberty mail' or something.

Sadly, I completely agree with this. From a wider public relations perspective beyond the realm of hackerdom calling it "darkmail" hands an easy propaganda win to the authoritarians.

Instead of dark scariness emphasise safety, security, protection, freedom, etc.

Re: Dark Mail Technical Alliance

#13
I'd love that e-mail encryption became widespread, but I'm doubtful that it'll ever happen. I think keeping private keys private may prove to be an impossible task. Systems are too insecure. Even security experts may fall victim to sophisticated attacks. Let alone the other 99.9% who are not security experts.

Re: Dark Mail Technical Alliance

#15
I don't think email encryption will ever be more widespread than it is today. People simply don't care, and even those few that can be convinced to use it will invariably do something that invalidates the whole exercise like bring their key to a public library, use it on their phone, resend the entire conversation in plain text accidentally, lose the key and generate a new one with you having no way to verify that it's not actually mitm, etc. All of this has happened to me.

Re: Dark Mail Technical Alliance

#16
post #13

I'd love that e-mail encryption became widespread, but I'm doubtful that it'll ever happen. I think keeping private keys private may prove to be an impossible task. Systems are too insecure. Even security experts may fall victim to sophisticated attacks. Let alone the other 99.9% who are not security experts.

Any security measure you take can only make attacks harder. If you have a really determined adversary nothing will protect you forever. Compared to the current status quo e-mail encryption even if the private keys are only kept moderately private would be a huge improvement.

Re: Dark Mail Technical Alliance

#17
post #15

I don't think email encryption will ever be more widespread than it is today. People simply don't care, and even those few that can be convinced to use it will invariably do something that invalidates the whole exercise like bring their key to a public library, use it on their phone, resend the entire conversation in plain text accidentally, lose the key and generate a new one with you having no way to verify that it…

Thats why its the goal of darkmail to push it so its used by gmail and organsiations like that.

Re: Dark Mail Technical Alliance

#18
post #10

3 of 5 comments so far mentioning that the name is a mistake. Allow me to make that 4 of 6. Come on guys, authoritarians are going to argue that this is just about defending criminals and terrorists, do you want to make that argument for them? Call it 'Liberty mail' or something.

Let me enhance the argument Joe Shmoe: "I recently read that dark net users are 90% pedophiles. So is this an email service for pedophiles only?"

Re: Dark Mail Technical Alliance

#19
post #15

I don't think email encryption will ever be more widespread than it is today. People simply don't care, and even those few that can be convinced to use it will invariably do something that invalidates the whole exercise like bring their key to a public library, use it on their phone, resend the entire conversation in plain text accidentally, lose the key and generate a new one with you having no way to verify that it…

It will be widespread like https has made encrypted web browsing wide spread: when it requires zero effort and zero knowledge.
Post reply on HN