Open Sourcers Pitch Secure Email in Dark Age of PRISM
wired.com
wired.com
I am of the opinion that that will do more about email privacy than GPG (as long as you trust your hosting provider, at least).
+ Anonymous
+ Distributed
+ Encrypted
For anonymous, I was thinking that the service would be accessible only through Tor or i2p, so that neither the sender nor the receiver can be found out by tracing the message.For distributed, I was thinking that the mail system would essentially be a freesites-style distributed hash table where the mail address (or a hash thereof) would act as the key. The mail or parts of the mail would be stored multiple times across many clients to eliminate single points of failure. Perhaps a TTL system would prevent old mails from filling up everyone's space.
Finally, the encrypted would be achieved by having the mail address act as the public key (or at least, the mail address is a key to a distributed KV store that contains the public key). This way, before anonymously sending the message to the various distributed hash table buckets, it gets encrypted so only the desired recipient can read it.
It seems like it should be possible to build this from already existing technologies without thaaaat much trouble, though I haven't actually done anything about it.
Of course, getting people to use this would be another story ;-) and I guess people would want contacts lists, archives and so on.
How can you build a messaging system where the delivery service doesn't know where to deliver something?
- covered some of these issues, with pros and cons of various ideas.
The return address is contained inside the encrypted portion of the message so only the recipient can see which address sent the message. The message should also be cryptographically signed with the senders private key so that the sender can be verified.
Next, the DHT key would likely be a hash of the recipients address so it would be difficult or impossible to determine who the messages in a specific bucket belongs to. Also since the service would only be accessed through tor or i2p, the actual sender and receiver would be hidden. Obviously the recipient address (or rather DHT key) must be known so that the message can go to the right place.
Also obviously anyone can technically retrieve anyone else's messages but since they are encrypted this shouldn't matter.
This is currently Mailpile's vaguely planned "maximum privacy" mode, with the backwards compatible fallback being normal PGP/MIME over the normal Internet.
Anonymity from the POV of the sender/recipient is not characteristic of this sytem, and it doesn't give perfect forward secrecy/deniability like OTR. But most people consider anonymous e-mail to be spam. If you need PFS, just use OTR, it works.
(Note: we have yet to do formal threat modeling and this plan may change.)
If Mailpile or someone else is going to be self-installed, I'd love to see it built as PHP. (Looks like Python right now.) As much as I refuse to develop in PHP, that seems like the only way to make installation as easy and ubiquitous as Wordpress, which should be the goal.
(I realize that either Mailpile or my own suggestion---or anything hosted on someone else's hardware---is vulnerable to someone reading the data right out of RAM, but it seems like their goal is to evade snooping not by building a 100% secure system, but by making it easy and affordable for everyone to have their own email server, so that government surveillance has too many targets to be practical.)
I'd love to see you guys pull this off. Best of luck to you.
It goes deeper than just using some PGP client. You need to understand how it works, to be sure that the bits coming out of your network are encrypted, and only you and Alice know how to decrypt them.
"Cryptography for the 2⁶⁴"?