Live data from Hacker News

The Sinking Ship of E-Mail Security

adamcaudill.com

31–40 of 56 posts

Re: The Sinking Ship of E-Mail Security

#31

Ok, I'll bite. This is a good post - I am negative on your ability to pull this off, but it's a worthwhile discussion to have IMO * Totally anonymous (ie no metadata trail) communication seems impossible / impractical. If everywhere is the Tor then we massively increase traffic, (not to mention the trustworthiness of "everyone" is a lot lower per unit than everyone currently running a tor node) Anyway, even if a encr…

    Anyway, even if a encrypted anonymous message arrives for me, just working out who it's from without any metadata seems complex web of double decryption
It's simple. You can encrypt everything, including the metadata. Then, when it arrives in your box, you simply decrypt everything, and see who it's from. It doesn't have to be anonymous.

Re: The Sinking Ship of E-Mail Security

#32
post #30
post #29

Earlier quoted context omitted.

Considering how locked down they are (iPhone, at least), yes, they are likely substantially more secure than PCs for most people.

You have to be more specific: Secure from what kind of threat? There are many threats ranging from service providers deciding to uninstall "unpopular" applications that threaten antiquated revenue models to State threats used against activists and dissidents.

I assume he means "threats that would allow another app or actor to read your private key".

Re: The Sinking Ship of E-Mail Security

#33
post #32
post #30

Earlier quoted context omitted.

You have to be more specific: Secure from what kind of threat? There are many threats ranging from service providers deciding to uninstall "unpopular" applications that threaten antiquated revenue models to State threats used against activists and dissidents.

I assume he means "threats that would allow another app or actor to read your private key".

And ignores the threat of a stolen device.

Re: The Sinking Ship of E-Mail Security

#34
post #3

While the spirit is laudable—I'm not sure if there's an 'e-mail security' version of https://craphound.com/spamsolutions.txt , but, if there were, then I'm pretty sure that one of the reasons for failure would be "You are a private individual announcing that you will be rolling out a new standard for e-mail in a couple of weeks".

Change has to start somewhere. Starting with a draft and getting feedback from the community before pushing it ahead for more formal standardization seems like the right place to me. As I said in the article, my goal is to get people talking about potential solutions. I have little hope that the solution I propose will be accepted and used as is - but if it gets more people talking, and discussions going about someth…

> Change has to start somewhere. Starting with a draft and getting feedback from the community before pushing it ahead for more formal standardization seems like the right place to me.

I agree that change has to start somewhere, and, to be clear, I don't mean anything against you, but rather against the likelihood of any success: I think that we're stuck with a broken legacy system until something radical, by which I mean "all existing infrastructure is destroyed"-type radical, forces a ground-up re-start.

Nonetheless, there seem to be at least two competing objections to trying to start the change here:

- My point of view: It seems unlikely that the eventual solution (if there is one) will come from a large group carrying a large and representative collective weight, not an individual (or even a small, self-selecting community like HN, or—probably, and with no offence meant—the readership of your blog) with a necessarily specialised viewpoint; and that a large group is more likely to buy in to "let's create a new standard!" than "let's use my / my community's standard that I / we created without your viewpoints or input!"

- Alternatively, if one believes (as it seems you do) that the solution will start with an individual, then surely the thing to do is to deliver a product, not a promise. I don't know about anyone else, but my reaction when I see assurances of delivery RSN is automatic scepticism.

Re: The Sinking Ship of E-Mail Security

#35
post #28

Earlier quoted context omitted.

The same as any other device. I'm nitpicking.

It depends on the device, I guess, but no, I'm saying your phone is better off in that scenario than any of your other devices.

Why would a fully-encrypted smartphone be better off than a fully-encrypted laptop? I'm not following here.

Re: The Sinking Ship of E-Mail Security

#36

Earlier quoted context omitted.

K-9 Mail is good, but it doesn't support PGP/MIME. Only inline PGP. Doesn't look like they will either as it's been on their todo list for several years now with no progress.

Whilst this is true it is not really that big a problem. You can open the attachment, copy to the clipboard and then use APG to decrypt. It could be nicer and would be excellent if the client supported PGP/MIME, but I can live with it.

I would say it's a not-insurmountable problem, but definitely a big problem. If I have to copy-and-paste all my e-mails into APG just to read them, that's a significant inconvenience.

Re: The Sinking Ship of E-Mail Security

#37
I've thought a lot about this and so far the solutions I've seen put forth (e.g. Flowingmail, Bitmessage, for starters) don't seem likely to get any widespread adoption, and that can be the death knell of anything like this that relies on network effects. Hell, I can't even get people to send me a PGP key even when I refuse to send them important documents without one (they just say they're going to send me one later, then forget about ever getting the document they wanted). It's really not that hard to generate a PGP key, but even motivated people don't do it.

My immediate intuitions are that 1.) this is a very hard problem to solve and 2.) if it's going to be solved in any reasonable amount of time, it needs to be bootstrapped into existing, popular methods of communication (such as e-mail). Adding some sort of PKI into the existing e-mail spec would probably be a good start, since it's just not something that people are used to dealing with.

Re: The Sinking Ship of E-Mail Security

#38
post #35
post #28

Earlier quoted context omitted.

It depends on the device, I guess, but no, I'm saying your phone is better off in that scenario than any of your other devices.

Why would a fully-encrypted smartphone be better off than a fully-encrypted laptop? I'm not following here.

depends on the software installed on both and the adversary you have in mind

if we're talking defending from suits; your phone is probably turned on a lot larger percentage of the time than your laptop so it's more susceptible to a cold boot attack

if we're talking defending from some thug who jacked your phone; it probably doesnt matter

Re: The Sinking Ship of E-Mail Security

#39

Ok, I'll bite. This is a good post - I am negative on your ability to pull this off, but it's a worthwhile discussion to have IMO * Totally anonymous (ie no metadata trail) communication seems impossible / impractical. If everywhere is the Tor then we massively increase traffic, (not to mention the trustworthiness of "everyone" is a lot lower per unit than everyone currently running a tor node) Anyway, even if a encr…

Anyway, even if a encrypted anonymous message arrives for me, just working out who it's from without any metadata seems complex web of double decryption It's simple. You can encrypt everything, including the metadata. Then, when it arrives in your box, you simply decrypt everything, and see who it's from. It doesn't have to be anonymous.

How do I know which key to use to decrypt it? If there is any identifier then that is an identifier for the sender - an irrevocable one that will slowly build up a metadata trail.

Anonymity is hard if not impossible - it's why I don't think evoting can work and why this seems laudable but hard

Re: The Sinking Ship of E-Mail Security

#40
I am always scared that if I start signing my emails (the least I can do) they might start looking weird to my friends, family, and colleagues. They may even think that the block of gibberish may be spam. I do like my KDE KMail client which masks the signing information and presents signed and unsigned messages in a sane way.
Post reply on HN