Live data from Hacker News

Dark Mail Technical Alliance

darkmail.info

41–50 of 54 posts

Re: Dark Mail Technical Alliance

#41

The proposal for forward secrecy in the spec ( https://darkmail.info/downloads/dark-internet-mail-environme... ) is not great and does not reflect the current state of the art: > PFS for message objects, as the description above suggests, is far more difficult, and contrary to the nature of email. It recommends just rotating public keys every few days with a paranoid mode. A much better solution is to implement the A…

I don't really understand why people are trying to reinvent something that has already been figured out. That kind of NIH behaviour is absolutely lethal in the world of cryptography.

Re: Dark Mail Technical Alliance

#42
So who will be able to use this wonderful protocol? Because I don't think it will be available on gmail(or any other big provider). How it isn't going to end like a pgp right now, when I can sent encrypted emails only to myself, because no one in my circle uses encryption?

Re: Dark Mail Technical Alliance

#43
post #8

I'd rename it 'Trustmail'

I wouldn't trust anything with the word 'trust' in it. My assumption is that if you have to put some quality in a name (like, say, QualityCircle), then the name is about all of that quality there is in the product.

Re: Dark Mail Technical Alliance

#44
post #5

The spec is pretty intense, I think the first thing to work on is better high level documentation and overview. There is a lot going on with how this proposed system formats, encrypts, signs, routes, and validates. I've only glanced over less than half of the spec so far, but I'm not convinced of the design just yet. For starters, I'm not sure I fully understand the trust model, or even the baseline limitations on th…

Why is it so complicated? Seems unnecessarily byzantine.

Re: Dark Mail Technical Alliance

#45
post #10

3 of 5 comments so far mentioning that the name is a mistake. Allow me to make that 4 of 6. Come on guys, authoritarians are going to argue that this is just about defending criminals and terrorists, do you want to make that argument for them? Call it 'Liberty mail' or something.

Isn't that bike shedding?

Re: Dark Mail Technical Alliance

#46
post #10

3 of 5 comments so far mentioning that the name is a mistake. Allow me to make that 4 of 6. Come on guys, authoritarians are going to argue that this is just about defending criminals and terrorists, do you want to make that argument for them? Call it 'Liberty mail' or something.

Isn't that bike shedding?

Not necessarily. Bike shedding refers to arguing about trivial issues. Naming can have a huge impact on how something is perceived so I wouldn't call it trivial.

Re: Dark Mail Technical Alliance

#47
post #32
post #15

I don't think email encryption will ever be more widespread than it is today. People simply don't care, and even those few that can be convinced to use it will invariably do something that invalidates the whole exercise like bring their key to a public library, use it on their phone, resend the entire conversation in plain text accidentally, lose the key and generate a new one with you having no way to verify that it…

> People simply don't care that's because they think email is already private. They don't understand that it's the electronic equivalent of printing their conversations on billboards and hope nobody will actually look at them. As soon as you demonstrate with a simple sniffer, they are outraged. We just need "Firesheep for email" and then demand for privacy will explode.

Even after the Sony hack, people don't realize things like their work email isn't really theirs, or email isn't private. If that wasn't a good enough catalyst, I can't imagine what it will take to cross this threshold.

Re: Dark Mail Technical Alliance

#48
post #42

So who will be able to use this wonderful protocol? Because I don't think it will be available on gmail(or any other big provider). How it isn't going to end like a pgp right now, when I can sent encrypted emails only to myself, because no one in my circle uses encryption?

I think you are pretty close to getting it right. This spec is Dead on Arrival. This spec will never get traction in a large corporate environment. Primarily because the business has a need to monitor and archive employee emails. As a result no large corporation will ever adopt end to end encrypted email as a standard.

While in the consumer arena Gmail and other ad / user profile supported business' will never adopt this as it limits their access to valuable user data.

Re: Dark Mail Technical Alliance

#49
post #15

I don't think email encryption will ever be more widespread than it is today. People simply don't care, and even those few that can be convinced to use it will invariably do something that invalidates the whole exercise like bring their key to a public library, use it on their phone, resend the entire conversation in plain text accidentally, lose the key and generate a new one with you having no way to verify that it…

We don't need the general population to understand email security - they use what's available/provided and it'll have to be easy enough that it works in practice. Once there's a viable alternative and financial liability is tied to the pretense of email being secure, suddenly we'll change to the new system.

What's interesting is that it's only liberty minded tech people working on the problem. The next email system will be tailored to protect the user because that's what the designers care about, rather than the interests of other organizations, for example serving legal papers electronically.

Post reply on HN