I'm in shock.
I'm in shock.
All tech geeks set up mail servers with encryption and volunteer to migrate their non-tech friends and family to new email homes. We also show how to configure encryption in their mail clients and start getting them to use native email clients rather than webmail.
This will have two effects. It will send a message to Google/Microsoft/Yahoo!/insert big mail provider here/... that they have been lax in protecting the privacy and interests of their users. Of course, given the free-as-in-beer model of webmail it was long apparent to some that the user was actually the product and the advertiser was the actual customer. If a user is seen as a mere data-point then there is little incentive to assure these mere data-points privacy. maybe this will be the kick in the pants the big providers need. Maybe that model is irredeemably broken and always has been but we just didn't know it yet.
Email should be like snail mail. Everybody acts as their own mail server and mail client in snail mail land. Your inbox is the physical letterbox and you would never let some corporation provide that value in return for some dubious positive (convenience? a nice interface to your mail store? the ability to search your mail store? ...)
The second effect is that it sends a message to the spooks and claws back a vital channel of our privacy. We can work on safe and easy anonymous browsing and safe and anonymous and federated social networking and whatever else further down the road -- mail needs to come first.
Think about it. There are enough tech geeks. Every geek should need to know how to do this anyhow. This will scale. We need to build a movement around this. When something in the political arena forces the immeasurably invaluable Groklaw offline something tangible needs to be done. We have had a series of ever more alarming wake-up calls (though I hate how clichéd that sounds) since the first Snowden revelations. We need to start acting on these calls. Sure our response needs a political dimension (a global moratorium on digital mass surveillance) as well but I think that this technical part-solution has got legs.
What do you think?
I certainly wouldn't be comfortable with my peers having the opportunity to control my email and the myriad of accounts associated with it. I can't imagine they would be happy with me doing the same with their data.
> We also show how to configure encryption in their mail clients
Encryption is fairly useless without authentication, and we can safely assume that the NSA has control of Certificate Authorities.
> Think about it. There are enough tech geeks. Every geek should need to know how to do this anyhow. This will scale.
I've been battling with the concept of hosting my email for quite some time, and it always boils down to being a horrific thing to set up. There's a pile of easy ways you can screw up and make something insecure or spam-ridden. I spent a good day trying to put together a solution I was happy with, but couldn't.
You don't need CA's for e-mail encryption. You need keyrings and networks of trust (I exchange keys with my closest associates via offline means; I sign a certificate stating that I vouch for the authenticity of their certificates; my associates can then choose whether or not to trust the signatures I've signed, and whether to trust the signatures they've signed again).
Yes, there's room for infiltration, but it is vastly better than relying on central CA's for this type of usage, because it allows people you trust to contradict infiltrators.
Of course there's no need to rely on a central CA - it's not hard to run your own, and you can make it reasonably secure - say, a small ARM Linux board with passphrase-protected private keys on a removable SD card. Generating the keys in a secure way is perhaps a bigger problem - untrusted hardware RNGs, poor quality entropy after boot etc.
One can also keep a virtual machine CA on a hardware-encrypted USB device (IronKey, say, depending on your level of trust with Imation) - it's easy enough to bootstrap a tiny Linux distribuution from source with just OpenSSL and some utility scripts to issue & revoke certs.
You don't necessarily need a $5000 HSM solution to issue your own SSL certificates at this level.
Well sure, I can issue them myself in a few minutes, the issue is that arbitrary mail servers won't be able to authenticate me. Which means we're means we're back to MITM attacks—better than plain text if the observer can't manipulate the data stream—but I wouldn't bet on it. Work with the assumption that the NSA is Mallory, not Eve.
If you have to stay on the Internet, my research indicates that the short term safety from surveillance, to the degree that is even possible, is to use a service like Kolab for email, which is located in Switzerland, and hence is under different laws than the US, laws which attempt to afford more privacy to citizens. I have now gotten for myself an email there, p.jones at mykolab.com in case anyone wishes to contact me over something really important and feels squeamish about writing to an email address on a server in the US.