Automatically encrypt your Gmail account
github.com
github.com
Once your emails get into google servers, the NSA has made a copy of them. NSA copies your emails before you even read them.
You are protecting yourself from someone who has access to your gmail account, not from someone who has a BACKUP of your gmail account.
I recognise this isn't perfect, but the very fact that in various stories a fuss has been raised about data retention times indicates it might not be completely useless to close the window of vulnerability, another comment in this thread mentions monitoring the incoming messages via IMAP IDLE also which is another idea, but once again there is a non zero window of plaintext messages on the server.
And if nothing else, the thousands of spam messages this will armor with strong encryption will give the fascists something to waste their time on.
I haven't followed the NSA Prism story as closely as maybe I should have, but I'm curious: is this TRUE? Like, is it indisputable fact that the NSA has all your email, or, is it more like, we can't be sure what they do and don't have access to, therefore, it's better to assume the worst?
Also, please explain how you would implement a webmail service without storing emails.
"is it indisputable fact that the NSA has all your email, or, is it more like, we can't be sure what they do and don't have access to"
They don't need to have second hand copies of the mail when they can just tell Google to give them access.
"implement a webmail service without storing emails." is not relevant to anything I said.
FAIRVIEW, BLARNEY, and two whose names were redacted exist in addition to PRISM. They are tapping the pipes and grabbing stuff off of the server.
They can pretty much have whatever they want.
it is the "least untruthful statement".
> or, is it more like, we can't be sure what they do and don't have access to, therefore, it's better to assume the worst?
it is just hard to imagine how they don't have access to something. They obviously capable of accessing everything they want. Thus if they don't access something, it would mean they don't want to. Ed absurdum.
Interesting piece of history btw:
http://en.wikipedia.org/wiki/Martin_Hellman#Computer_privacy...
"Hellman has been a long-time contributor to the computer privacy debate. He and Diffie were the most prominent critics of the short key size of the Data Encryption Standard in 1975. An audio recording survives of their review of DES at Stanford in 1976 with Dennis Branstad of NBS and representatives of the National Security Agency.[12] Their concern was well-founded: subsequent history has shown not only that NSA actively intervened with IBM and NBS to shorten the key size ..."
And really, it doesn't matter whether the NSA has explicit connections into Gmail, your email is backed up periodically by Google already, so plaintext is available to interested parties for quite a while even if you were to empty your trash.
But even before that, many SMTP servers transmit emails in the clear, so it wouldn't matter if the NSA had their hooks into Google if they've got their hooks into the backbones that Google peers with.
Oh, and you lose all read state, all information about when an email was sent, any labels, stars, any reference headers for threading, ...
Seemingly the only threat that this addresses is "someone may hack into my email account and I don't want them to be able to read my email". There are several other methods for solving that particular issue without destroying email metadata and the usefulness of email itself.
The first company that offers serious client-side encryption (with steganography + noise thrown in for good measure) is going to make a bundle.
Hint, hint.
The general facility of client side private key encryption before form submission of both text fields, areas, and files seems like it would be very useful. Not sure why that's not planned for, say, html5. Odds are I'm sprinkling my own ignorance all over this :)
If this sort of functionality was standardised, simplified and baked in to the major browsers, we'd be able to build all sorts of wonderful software on top of it.
However, I take your point. Lots of work, not quite the same. It still seems like the facility should be baked in though so that application's could make the proper tradeoffs.
If you split the text into words, discard case and encrypt each word, the NSA can just e-mail you a dictionary file, match the line numbers in the dictionary file ciphertext to line numbers in the dictionary file plaintext, and they've got your secret decoder ring (at least for every word in the dictionary file).
That said, I think this is worth doing, so it's currently in progress. I just don't have a ton of time at the moment, pull requests eagerly accepted though. :)
EDIT: 'Sup with the downvote? Explain what's wrong with my post.
https://grepular.com/Automatically_Encrypting_all_Incoming_E...
result, data = mail.search(None,'(NOT BODY "BEGIN PGP MESSAGE")') ids = data[0] id_list = ids.split()
There's a chance "result" will indicate a failure and/or "data" will be None, causing the access to data[0] to throw an exception.
I haven't looked into what the API returns for "result" so I can't speculate on a fix, but I'm sure it should be easily handled.
Unfortunately sometimes the IDLE errors and I haven't been able to figure out why. And I've yet to get Gmail to actually delete the email (vs just moving it to the trash)
I'm still looking into it.
It works, but it's cobbled together and still has some issues I haven't been able to resolve.
It of course still doesn't keep out the scary folks, as they'll just tap the network beforehand, but it does raise the bar quite a bit from other 3rd parties snooping. Combine with a crypto-stick, https://www.crypto-stick.com/, and good practices on the mail server and you're in the best shape anyone can be until everyone encrypts their outgoing email.
I think I will do this. I was thinking of downloading all my gmail to my local anyways and then deleting them since emails over 180 days old don't require a warrant to read right?
Thank you for creating this.
http://www.syncdocs.com/syncdocs-screenshots/how-to-encrypt-...