The proposal for forward secrecy in the spec ( https://darkmail.info/downloads/dark-internet-mail-environme... ) is not great and does not reflect the current state of the art: > PFS for message objects, as the description above suggests, is far more difficult, and contrary to the nature of email. It recommends just rotating public keys every few days with a paranoid mode. A much better solution is to implement the A…
Dark Mail Technical Alliance
41–50 of 54 posts
Re: Dark Mail Technical Alliance
#42Re: Dark Mail Technical Alliance
#43I'd rename it 'Trustmail'
Re: Dark Mail Technical Alliance
#44The spec is pretty intense, I think the first thing to work on is better high level documentation and overview. There is a lot going on with how this proposed system formats, encrypts, signs, routes, and validates. I've only glanced over less than half of the spec so far, but I'm not convinced of the design just yet. For starters, I'm not sure I fully understand the trust model, or even the baseline limitations on th…
Re: Dark Mail Technical Alliance
#453 of 5 comments so far mentioning that the name is a mistake. Allow me to make that 4 of 6. Come on guys, authoritarians are going to argue that this is just about defending criminals and terrorists, do you want to make that argument for them? Call it 'Liberty mail' or something.
Re: Dark Mail Technical Alliance
#463 of 5 comments so far mentioning that the name is a mistake. Allow me to make that 4 of 6. Come on guys, authoritarians are going to argue that this is just about defending criminals and terrorists, do you want to make that argument for them? Call it 'Liberty mail' or something.
Isn't that bike shedding?
Re: Dark Mail Technical Alliance
#47I don't think email encryption will ever be more widespread than it is today. People simply don't care, and even those few that can be convinced to use it will invariably do something that invalidates the whole exercise like bring their key to a public library, use it on their phone, resend the entire conversation in plain text accidentally, lose the key and generate a new one with you having no way to verify that it…
> People simply don't care that's because they think email is already private. They don't understand that it's the electronic equivalent of printing their conversations on billboards and hope nobody will actually look at them. As soon as you demonstrate with a simple sniffer, they are outraged. We just need "Firesheep for email" and then demand for privacy will explode.
Re: Dark Mail Technical Alliance
#48So who will be able to use this wonderful protocol? Because I don't think it will be available on gmail(or any other big provider). How it isn't going to end like a pgp right now, when I can sent encrypted emails only to myself, because no one in my circle uses encryption?
While in the consumer arena Gmail and other ad / user profile supported business' will never adopt this as it limits their access to valuable user data.
Re: Dark Mail Technical Alliance
#49I don't think email encryption will ever be more widespread than it is today. People simply don't care, and even those few that can be convinced to use it will invariably do something that invalidates the whole exercise like bring their key to a public library, use it on their phone, resend the entire conversation in plain text accidentally, lose the key and generate a new one with you having no way to verify that it…
What's interesting is that it's only liberty minded tech people working on the problem. The next email system will be tailored to protect the user because that's what the designers care about, rather than the interests of other organizations, for example serving legal papers electronically.