Live data from Hacker News

Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

silentcircle.wordpress.com

151–160 of 217 posts

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#151
"dark mail alliance" group, here is what you need to do...

1. get a new website, terrible design even from a 1995 point of view it is bad. Drop shadows on tag-lines are tacky. Not that tech people care, but if you want to take over the world. Try starting by having a decent designer on your team.

2. the only way to "truely" fix this for good is to not use email. instead, use a different form of communication (im thinking of...)

3. work with a few "enterprise companies" 4. get some capital 5. lastly, email is really still on 1.0, there was really no 2.0... unless you consider the time before the internet as 1.0 when the government used internal mail. But as we know mail today technically its still 1.0

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#152
post #89

Earlier quoted context omitted.

Freedom \ Liberty \ Patriot \ Constitution Mail would be very effective in blocking political speeches and biased headlines from cheap attacks. My personal favorite is Lincoln Mail... Seems highly appropriate on many levels and should be FOX News proof.

Lincoln Mail would be shot while in the Security Theater.

too soon

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#153

Earlier quoted context omitted.

The problem with e-mail is that gathering the meta-data is almost as valuable as looking inside at the message contents. Secure messaging layers aren't going to help you there - unless everyone starts using something like Tor.

Why Tor? We have had mix-nets for many years, and they do an excellent job of protecting metadata. Even old-fashioned cypherpunks remailers do a fine job at that.

Appologies for the spelling errors in this note below - it's an OCR of an old printout (I've been unable to find a current archive of cypherpunks going back this far):

Cypherpunks archive-96.02.29-96.03.06: List of reliable remailers

List of reliable remailers Anonymous Remail Service (nobody@vegas.gateway.com) Sun, 3 Mar 199609:18:03-0500

( Messages sorted by: [date][ threa4][ subject][ author] ( Next message: Adam Shostack: "Re: NYT on Crypto Bills" ( Previous message: Raph Levien: "List of reliable remailers" ( Next in thread: Black Unicorn: "Re: your mail"

Thought that this was worth reposting:

>1 attended last weeks "Information, National Policies; and International >Infrastructure" Symposium at Harvard Law School, organized by the Global >Information Infrastructure Commission, the Kennedy School and the >Institute for Information Technology Law & Policy of Harvard Law School.

>During the presentation by Paul Strassmann, National Defense University >and William Marlow, Science Applications International Corporation, >entitled 'Anonymous Remailers as Risk-Free International Infoterrorists" >the questions was raised from audience (Professor Chaarles Nesson, >Harvard LAw School) - in a rather extended debate - whether the CIA and >similar government agencies are involved in running anonymous remailers >as this would be a perfect target to scan possibly illegal messages.

>Both presenters explicitly acknowledged that a number of anonymous >remailers in the US are run by government agencies scanning traffic. >Marlow said that the government runs at least a dozen remailers and that >the most popular remailers in France and Germany are run by the >respective government agencies in these countries In addition they >mentioned that the NSA has successfully developed Systems to break >encrypted messages below 1000 bit of key length and strongly suggested >to use at least 1024 bit keys. They said that they themselves use 1024 >bit keys.

>J ask Marlos afterwards if these comments were off or on record, he >paused then said that he can be quoted.

>So I thought I pass that on. ft seems interesting enough, don 't you > think?

>Best

> Viktor Mayer-Schoenberger >Information Law Project >Austrian Institute for Legal Policy

Groundfog@alpha.c2.org

( Next message: Adam Shostack: "Re: NYT on Crypto Bills" ( Previous message: Raph Levien: "List of reliable remailers" ( Next in thread: Black Unicorn: "Re: your mail"

I of 1 05.09.96 01:58

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#154

Earlier quoted context omitted.

I totally agree, I really think you should change the name. Some suggestions: - Locke Mail [from John Locke] - Mill Mail [from John Stuart Mill] - Hobbes Mail - Liberty Mail

I suggest names that don't have limited country/cultural references if the intent is to make this a global success. Some other suggestions: -SecMail (Secure Email) -PrivMail (private/privacy email) -FMail (freedom email) -NetMail (New Internet standard email) And thank you for taking this on, it is seriously needed. And please, no reliance on CA certs, chances are the NSA has compromised at least some of those.

I like Fmail because it is the alphabetical successor to Email.

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#155
post #138

Earlier quoted context omitted.

I suggest names that don't have limited country/cultural references if the intent is to make this a global success. Some other suggestions: -SecMail (Secure Email) -PrivMail (private/privacy email) -FMail (freedom email) -NetMail (New Internet standard email) And thank you for taking this on, it is seriously needed. And please, no reliance on CA certs, chances are the NSA has compromised at least some of those.

how did you manage not to say FreeMail

LibreMail (drawing from LibreOffice)

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#156

Earlier quoted context omitted.

And over an unencrypted channel no less, www.darkmail.info doesn't have ssl, so the NSA will know if you are interested.

It is not a crime to be interested in something like this.

Not yet it isn't.

Remember what happened with "Anarchist's cookbook" and recipes for thermite and such that used to be readily available on the net, and relatively uncontroversial. It was just "information" after all. These days it seems knowing how to do some basic chemistry is considered intent to do harm or something.

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#157
post #89

Earlier quoted context omitted.

Freedom \ Liberty \ Patriot \ Constitution Mail would be very effective in blocking political speeches and biased headlines from cheap attacks. My personal favorite is Lincoln Mail... Seems highly appropriate on many levels and should be FOX News proof.

As a non-American, all of these terms remind me of irritating American flag-waving rhetoric (the kind used to justify the types of things that the NSA is doing right now, for that matter), and I would wager most of the world would feel the same.

As an American, I agree. I'm more in favor advertising the confidentiality angle.

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#158
post #150

Earlier quoted context omitted.

> GMail won't update to 3.0 in any meaningful way, no matter what Perhaps this problem can be addressed by having a plugin/add-on/extension that decrypts the mail within the browser. GMail, Yahoo, or other mail providers that don't adopt this new and secure email protocol won't get the plaintext of your message, and preferably not the metadata either. This requires that the new protocol use a converter or proxy or so…

Maybe people could run a local app/filter that extracts keywords from our own mail and shares them with google. Leave the power completely in our hands to give to google what we feel like giving them.

This patchwork approach to attempting to solve a large broken system has visibly failed analogously to politics, in terms of preventing the threat of mass-surveillance.

I don't see how this is any different. We need new technology to solve new problems. Decentralization. Changing behavior is not easy, but sometimes necessary. Everything else being proposed seems half-assed (for lack of a better word) and easily circumventable by a resourceful adversary.

As long as Google (or whomever) holds all the cards and has a lot to lose by not complying to threat of force (for ex. shareholders and stock prices), then we won't get anywhere.

Re: Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

#159

Since it hasn't been mentioned yet, OS X and iOS already support S/MIME encrypted email, and having the private keys live on users' devices and doing encryption of outgoing messages on users' devices is probably the safest setup.

Hmmm, I don't know if I'm being outrageously paranoid, but I'm resisting the temptation to put my PGP private key on my iPhone - because it'd be _way_ too easy for Apple to extract the key/passphrase if they were coerced by someone powerful enough, and those "powerful enough" have shown that they consider a court order granting them the private key used to secure 400,000 people's email is an appropriate tool when tar…

It's good to be paranoid - but if you don't trust Apple -- you'll have to be quite paranoid with your (and every other) iPhone you encounter. After all they might be recording all sound within range of the mic, for example. Or all text typed. Or both.

AFAIK Apple is close to best in class when it comes to handling secure information (keys, pins etc) -- even if they're not perfect.

Post reply on HN