I2P-Bote – Email plugin for the I2P network that uses a distributed hash table
i2pbote.xyz
i2pbote.xyz
Is your threat model different from, say, a state-level MitM, who today can record IP traffic that happens to include TLS and simply wait the equivalently long time until the underlying ciphers are broken and obsolete? Is the information being exchanged of such sensitivity to require outlasting a typical human lifespan, making the possibility of offline cryptanalysis, enabled by the dissemination of still-encrypted content, an unacceptable risk?
If the cryptosystems themselves have comparable properties, do ancillary factors make, say, the I2P DHT usecase worse than the TLS-over-the-public-web usecase, given that a darknet overlay network typically has a self-selecting clientele vs. the vast numbers of people defaultly using TLS, making publicly accessible but encrypted blobs traversing the former more tempting targets in a smaller haystack?
Attacks are found, cryptosystems are broken, key strengths weakened, side channel attacks created, computers get faster, dedicated hardware is created, etc...
Pretending that we got it 100% right this time seems naive at best, and adding a small amount of "defense in depth" by not giving everyone all of the encrypted data seems like a good place to start.
not applicable to offline decryption and of fairly limited use in asynchronous communication
> computers get faster, dedicated hardware is created
not relevant with 256bit keys. Even grover's algorithm would only cut it down to 128bits which is still "boiling the oceans" territory. So at least in that area we have a lot more safety margin than in the past.
Of course none of that is a guarantee that the data will stay secure, but you can't just generalize all attacks used in the past and then count them against a system where we learned from some mistakes and others simply aren't applicable.
Even if I believed in cryptography that outlasted human lifespans (and in general I do not for the same reason as the other person who replied to your comment) I have a difficult time accepting a world where it is simply considered reasonable to have every single letter sent by every single person before 1930 (including your great grandparents when they were teenagers) accessible to anyone today (not just state level actors, but literally any person who cared, such as me) who has access to an archive (and like, why not keep one? it almost seems silly not to: I can even see some people making it their life's mission to archive the data for the next generation to decrypt) and wants to bother reading (or indexing and searching and analyzing) that content.
Despite what many people will tell me, handing everything to everyone hidden behind a single crypto lock feels much more dangerous than transmitting it over a wire to only the destination then storing it somewhere that some physical security can apply.
It just seems like good security-in-depth. If a flaw were found in the crypto primitives used in my network drive, an attacker would either have had to record all the data as it was being sent, or will need direct access to the drive in question.
It's just one extra step that could possibly save you.
No cryptosystem is perfect, and relying 100% on just the crypto means that if an attack were found, it would be instantly exploitable to all of your past content without any real ability for you to update or delete it.
That's not true.
For example, Bitmessage has chans which are essentially mailing lists. In this case the key is supposed to be known/distributed. Recipients use it to read and publish to the mailing list while hiding their list subscriptions and access patterns. That would continue to work even if a flaw in the crypto is found (at least as long as the proof-of-work hashing algo can continue to perform its function without flaw).
Meanwhile, smtp is stored and transmitted in plaintext something like 95% of the time. Hacking mail servers, end user PC's, etc to get at someone's mail is a common practice. Pick your poison I guess.
We already have a basic level transport system called IP, and it's quite efficient.
With the I2P-Bote, everything is done for you via the hashtable. No domain to buy, no mail server to baby, no working to get off everyone's spam list because you're a new mail server, and no giving up your privacy to google.
Even if your smtp message is encrypted you're at least giving up plain-text info like your email address, the recipients email address, your IP, and whatever user-agent or fingerprinting data can be extracted from your browser or mail client.
That being said, if you use S/MIME or GPG on top of I2P-Bote that doesn't remove the original stated concern of having all messages stored and accessible to everyone in encrypted form.