Live data from Hacker News

Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

silentcircle.wordpress.com

111–120 of 217 posts

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#111

Earlier quoted context omitted.

I think the biggest barrier to entry of any new and secure email protocol will be GMail. GMail (and similar services) are what most people seem to use at this point. And GMail won't update to 3.0 in any meaningful way, no matter what, since they want to be able to mine the data in your email, so they will still be storing it on their servers "in the clear." Which means the next time NSA hacks their servers, they'll s…

I agree with the barrier. I wonder if the NSA has made surmounting that barrier possible. If the friction to getting a 'secure' email experience is low enough, people will put up with having two for a while. As for connecting them. I could handle just being able to communicate with my security conscious friends on this platform. That might make it a niche play early on but so was email.

Call me cynical, but for all the public outrage worldwide I'm pretty sure that even that outcry comes from a minority.

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#112

Earlier quoted context omitted.

I submit, "Envelope." It's a good analogy, since now we're essentially sending all of our email on postcards.

I'd posit that the French already have our backs. A few years ago, the official body that governs standardized French attempted to wean French-speaking people from the borrowed English terminology. Et voila! "Courriel," a portmanteau of courrier and electronique was pilfered from the Quebecois for the benefit of francophones everywhere. Sadly however, if Google Translate is any indicator, then "courriel" never made t…

If you're curious: courriel has become the standard term in Quebec, where adopting English terminology is a little bit more culturally / politically sensitive.

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#115
post #26

Earlier quoted context omitted.

Only solves a subset of the email problem, IIUC.

What's missing? I was very skeptical about Bitmessage, but it totally surpassed my expectations when I tried it.

The biggest issue is missing messages. You essentially have to have it running all the time to get your "mail", otherwise you miss out on all of the resend windows.

I love the idea of bitmessage, but this issue is a major problem.

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#116

Terrible name.

I agree. This is a case where some marketing thinking would probably help. Lots of large businesses would probably like something like this (the ones that buy rsa keyfobs and use VPNs). My old company would strongly discourage email from the company system to non company email address for security reasons.

Having said that, many businesses have requirements for employee email that are startlingly close to what the NSA wants. We need info@, accounts@, support@ email addresses that can be read by many people. There also needs to be a way for someone other than Firstname Lastname to read the firstname.lastname@company.tld mail - either for oversight, vacation/illness covering, or hit-by-a-bus scenarios. There are probably certain businesses that have legal requirements about access to employee email. A shortsighted "secure/dark" email approach could easily be dead in the water in terms of corporate adoption if those requirements are not catered for.

(I dont use my personal GPG key for any work related or firstname.lastname@company.tld mail, but have a separate GPG key – who's passphrase is in a sealed envelope in the company safe so it can be made available to the company if required without needing to reveal my personal private key. If I'm hit by a bus, or if lawyers/law-enforcemet come knocking on company business - they can have the keys to the encrypted mail in my company account. Mail encrypted to _me_ at nickname@company.tld or me@mydomain.tld is useless if I'm hit by a bus, and would require lawyers/leo/courts to convince me to reveal a passphrase stored only in my head if they wanted it. (Or, you know, for the NSA to rootkit any of my devices I type my personal passphrase into…))

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#117
Email is so broken from a security standpoint I doubt that email 3.0 would even make it off the ground. You would be better off taking something like IM which silent circl allready has a secure solution for and adding the store and forward capabilities that make email email. Then u could have email clients use that protocol. But asking the entire world to change / upgrade it's email servers and clients with a fundamentally different protocol. I don't see that being successful.

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#118

I appreciate the cheekiness of calling it the "Dark Mail Alliance", but from a purely PR perspective, it would make sense to reconsider your name if you are taking the position that encrypted end-to-end email is not solely an interest of those pursuing shady or deviant activities.

I totally agree, I really think you should change the name. Some suggestions: - Locke Mail [from John Locke] - Mill Mail [from John Stuart Mill] - Hobbes Mail - Liberty Mail

BitMail?

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#119

I hope they are successful. For a long time I have wished that someone with the expertise and time would be motivated to create a new email system from the ground up, and make that system widely available and 'open' (in the sense of open protocols). There are many challenges, but if they can pull it off there are many benefits as well. And perhaps the nicest part is that it is hard to actively oppose such efforts wit…

I think the biggest barrier to entry of any new and secure email protocol will be GMail. GMail (and similar services) are what most people seem to use at this point. And GMail won't update to 3.0 in any meaningful way, no matter what, since they want to be able to mine the data in your email, so they will still be storing it on their servers "in the clear." Which means the next time NSA hacks their servers, they'll s…

I wonder if it would be possible for Gmail 3.0 if they agreed to 'read' your email ONLY while you are reading it so they could display advertising. For example, the email is encrypted on the server, but a client has to eventually decrypt it (so you can read it) - if we could trust google bots to grab relevant keywords on the fly for the content but keep no history then it may be good enough privacy.

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#120
post #47

Earlier quoted context omitted.

What's the relevance? This isn't a spam fighting endeavor.

When you go through the trouble of reinventing email to provide proper security, you should also solve the spam problem as part of the protocol. It would be great if the recipient could specify the amount of proof of work required for example. Or ask for a certain amount of bitcoin in exchange for accepting promotional material. Or a mail attribute that indicates it's a newsletter. Lots of interesting possibilities.

Maybe a new system could instigate whitelisting from the ground up, with a built in "contact request" protocol (which may be required anyway to exchange keys).

We've got very used to email's totally open mailboxes, and it seems to me that the cost may well outweigh the benefit.

Edit: Added comment about key exchange.

Post reply on HN