Live data from Hacker News

A realization of why email is critical infrastructure for the Internet

utcc.utoronto.ca

211–220 of 255 posts

Re: A realization of why email is critical infrastructure for the Internet

#211
post #40

Well, in Estonia, they have a different approach. 1. If you are a citizen or a resident, you get an ID card to use for every public service. It's just a smart card with a government PKI. 2. The public services provide an email account that can only be used within the e-government services. The card is used for accessing those services. 3. The email service accepts either identity number or registry number of the reci…

> If you are a citizen or a resident, you get an ID card to use for every public service. It's just a smart card with a government PKI. This is the biggest flaw in the design. Tying the ID card to a single identity. If you're using it with a bank, it needs to be tied to your bank account. If you're using it for physical access control at your company's building, it needs to be tied to your employee account. These are…

> This is the biggest flaw in the design

No, it's solid design. It's a very simple safe primitive. You can build endless infrastructure on top of it. Similar to subkeys.

For example a lot of businesses use Smart-ID on top of that. You need to tie the smartid stuff to your PKI identity. But after that you can just use that as identity.

https://www.smart-id.com/

Re: A realization of why email is critical infrastructure for the Internet

#212
post #40

Well, in Estonia, they have a different approach. 1. If you are a citizen or a resident, you get an ID card to use for every public service. It's just a smart card with a government PKI. 2. The public services provide an email account that can only be used within the e-government services. The card is used for accessing those services. 3. The email service accepts either identity number or registry number of the reci…

> If you are a citizen or a resident, you get an ID card to use for every public service. It's just a smart card with a government PKI. This is the biggest flaw in the design. Tying the ID card to a single identity. If you're using it with a bank, it needs to be tied to your bank account. If you're using it for physical access control at your company's building, it needs to be tied to your employee account. These are…

By public services, I meant the public services provided by the state. For instance, health insurance, family doctor application, taxes, etc.

Banks require your ID whether it's smart or not. But it's not for payment purposes but for authentication. And they are not state bodies, but private commercial entities. They are not part of the PKI ecosystem of the state.

Re: A realization of why email is critical infrastructure for the Internet

#213
post #74
post #36

I really hope that we end up moving back towards supporting open protocols. I was heartened (and a little surprised) that Jack Dorsey recently mentioned that the draconian control of the Twitter API was the worst thing Twitter had done [1]. The corporatisation of the Internet, has undone a lot of the great work that had traditionally underpinned the network. It feels like the slow, laborious and fundamentally equitab…

It really is about incentives. When the government and universities were the primary agents influencing the internet, open protocols were favored I presume because they incentivized the decentralization that the internet was created for. Now private corporations are the primary agents of change, and they are driven by very different incentives. When was the last time you heard of a company based around open protocols…

And yet none of those corporations has displaced email, despite the fact that it has become a universal cyberattack channel, with a stagnant UX that doesn't address most real-world use cases for email!

I saw a need for a safer, better, decentralized protocol for email, so I drafted one (TMTP) and implemented client & server. More at:

https://mnmnotmail.org/ & https://twitter.com/mnmnotmail

Related protocol projects in development include:

https://mathmesh.com/

https://en.wikipedia.org/wiki/Dark_Mail_Alliance

Re: A realization of why email is critical infrastructure for the Internet

#214

Earlier quoted context omitted.

> If you are a citizen or a resident, you get an ID card to use for every public service. It's just a smart card with a government PKI. This is the biggest flaw in the design. Tying the ID card to a single identity. If you're using it with a bank, it needs to be tied to your bank account. If you're using it for physical access control at your company's building, it needs to be tied to your employee account. These are…

> This is the biggest flaw in the design No, it's solid design. It's a very simple safe primitive. You can build endless infrastructure on top of it. Similar to subkeys. For example a lot of businesses use Smart-ID on top of that. You need to tie the smartid stuff to your PKI identity. But after that you can just use that as identity. https://www.smart-id.com/

> It's a very simple safe primitive. You can build endless infrastructure on top of it.

It has nothing to do with the primitive. Someone will find a flaw in the implementation, or human flaws in the bureaucracy that administers it.

And building infrastructure on top of it is the flaw. These things should all be independent of one another.

Re: A realization of why email is critical infrastructure for the Internet

#215

Earlier quoted context omitted.

Same thing in the US. I always laugh whenever I see a list of corrupt countries and the US isn't near the top. Codifying bribery into law as lobbying and superpacs doesn't make it not bribery.

That's because the US has a low amount of corruption on the positions that face the public. It's also because most of those lists are ordered by a "perception index", that is the kind of bullshit that increases if your government does an awareness program and if corruption fighting gets on the news.

So, ironically, corruption reduction efforts can raise a country's rank on such lists.

Re: A realization of why email is critical infrastructure for the Internet

#216
post #40

Well, in Estonia, they have a different approach. 1. If you are a citizen or a resident, you get an ID card to use for every public service. It's just a smart card with a government PKI. 2. The public services provide an email account that can only be used within the e-government services. The card is used for accessing those services. 3. The email service accepts either identity number or registry number of the reci…

But is it really email as we know it? It looks more like a private message system like you find in forums and social networks.

In France, we are not as advanced as Estonia when it comes to e-government services, but we have an official identification system called "France connect", and government services have private messaging systems to communicate with them. And I think many countries have similar systems. The only difference seems to be that it is better integrated in Estonia.

Re: A realization of why email is critical infrastructure for the Internet

#217
post #74

Earlier quoted context omitted.

It really is about incentives. When the government and universities were the primary agents influencing the internet, open protocols were favored I presume because they incentivized the decentralization that the internet was created for. Now private corporations are the primary agents of change, and they are driven by very different incentives. When was the last time you heard of a company based around open protocols…

And yet none of those corporations has displaced email, despite the fact that it has become a universal cyberattack channel, with a stagnant UX that doesn't address most real-world use cases for email! I saw a need for a safer, better, decentralized protocol for email, so I drafted one (TMTP) and implemented client & server. More at: https://mnmnotmail.org/ & https://twitter.com/mnmnotmail Related protocol projects i…

Looks interesting.

If your draft didn't take off, what do you think the main reason would be?

Re: A realization of why email is critical infrastructure for the Internet

#218
post #40

Well, in Estonia, they have a different approach. 1. If you are a citizen or a resident, you get an ID card to use for every public service. It's just a smart card with a government PKI. 2. The public services provide an email account that can only be used within the e-government services. The card is used for accessing those services. 3. The email service accepts either identity number or registry number of the reci…

I still have a vague hope that the United States Postal Service could be "pivoted" into being a PKI provider and distribute physical tokens to citizens. They already have substantial procedures and infrastructure for verifying identity. There would be problems, to be sure, but I'd much rather get my ubiquitous PKI for citizens from the USPS than the banks or "tech giants".

This would be great for things like voting, but I think it could also be easily abused.

Many services would want to use your PKI token as identification, we would likely give up a lot of privacy because of its existence/ease-of-use.

Re: A realization of why email is critical infrastructure for the Internet

#219

Earlier quoted context omitted.

> If you are a citizen or a resident, you get an ID card to use for every public service. It's just a smart card with a government PKI. This is the biggest flaw in the design. Tying the ID card to a single identity. If you're using it with a bank, it needs to be tied to your bank account. If you're using it for physical access control at your company's building, it needs to be tied to your employee account. These are…

By public services, I meant the public services provided by the state. For instance, health insurance, family doctor application, taxes, etc. Banks require your ID whether it's smart or not. But it's not for payment purposes but for authentication. And they are not state bodies, but private commercial entities. They are not part of the PKI ecosystem of the state.

> By public services, I meant the public services provided by the state. For instance, health insurance, family doctor application, taxes, etc.

It's not clear why any of these things should be tied together even when they're all provided by the government.

You may have to identify yourself to your employer for taxes, but why should they get the identity used for your healthcare when it isn't any of their business? All it does is create the potential for that to leak. Or vice versa. Your tax returns are none of the business of the doctor you asked out, so these things should not be tied together in any way.

And the only reason the bank wants your government identification is that they're required to by law. Otherwise banks would widely offer numbered accounts. Even then this should only require the identity used for taxes and not the one used for healthcare or military service or professional licensing, none of which is any business of the bank.

Re: A realization of why email is critical infrastructure for the Internet

#220
post #217

Earlier quoted context omitted.

And yet none of those corporations has displaced email, despite the fact that it has become a universal cyberattack channel, with a stagnant UX that doesn't address most real-world use cases for email! I saw a need for a safer, better, decentralized protocol for email, so I drafted one (TMTP) and implemented client & server. More at: https://mnmnotmail.org/ & https://twitter.com/mnmnotmail Related protocol projects i…

Looks interesting. If your draft didn't take off, what do you think the main reason would be?

At this early stage, I'd say the biggest obstacle is reaching a wide enough audience; I have no prior fame, and no PR budget yet.
Post reply on HN