Show HN: Easily send encrypted email from your existing email
virtru.com
virtru.com
Based on the feature list, I can't have the keyserver on my own server. I have to trust Virtru. This is no different than sending the text in plain IMO.
> However, you’re entrusting us to help you maintain your privacy; you should know how we will respond if the government asks us for access to your encryption keys. The government would need those keys if it wanted to read any encrypted files it does obtain. Without them, the files are useless.
> We won’t provide your keys to anyone without your consent — unless we are ordered to divulge them by a judge with jurisdiction over us. If we are ordered to divulge them, we will fight for you to have notice and an opportunity to object.
So I guess I'll keep waiting for a DarkMail client.
Virtru encrypts email content on the client side, so your email is protected before it ever leaves your computer. That gives you protection in transit and at rest
Virtru allows you to send securely to any recipient, regardless of the email provider they use. The easiest way to read the secure message is to use the Virtru software to integrate with your existing email client.
Our iPhone client uses IMAP, so it works with any email provider that supports IMAP.
Our browser extension currently integrates with Gmail, Yahoo, and Outlook.com. If the Virtru browser extension does not integrate with your email provider, then we provide a mechanism to read the secure email in your browser without installing anything. However, you cannot reply securely without the Virtru software.
DarkMail would require people to completely ditch everything and jump to a new system.
But for the super-security minded folks we're researching ways we can seamlessly integrate PGP like capabilities into the product so that Virtru would never even be in a position to see the keys at all.
And we have a blog post discussing some frequently asked questions on government surveillance: https://blog.virtru.com/faq-on-government-surveillance/
Until the law does, keeping all the keys in one place is an invitation for the bear to get the honey. If all the honey was in separate honeycombs, the bear might still get them all, but would probably have a tad bit more work to do.
Atleast hypothetically :).
Virtru allows users to easily send encrypted email from their existing email address. It is super easy to use and currently works in your browser and on your phone.
We are launching our public beta program today and would love feedback from the community. Several of the Virtru team members will be monitoring this thread to respond to feedback and questions.
EDIT: Virtru team members: DHowitzer (CTO), ravenac95, znelson, jgilpin
1) It's hard for the normal person. (The user experience for PGP is just horrendous)
2) Before you send an email to someone you have to know their public key.
With that said, we have done some research on integrating PGP like public key encryption along with our current key serving mechanism. With public key, using Virtru will be essentially equivalent to holding the keys yourself. Look for more of this in the future :-)
We've comprehensively addressed this issue on our blog. Here's the direct link: https://blog.virtru.com/faq-on-government-surveillance/
Let us know what you think.
> Q. What would Virtru do if it received a request
> from the United States government for encryption keys?
> A. We will require the government to go to court,
> and if we can, we will notify you.
To me that seems naive. You won't be able to notify anyone if you get a National Security Letter (NSL). Lavabit had turned over encryption keys for individual users, because they had to [1]. They only shut down when the government wanted their SSL key, to give access to everyone.How are you any different?
http://www.rsync.net/resources/notices/canary.txt
I've actually found it kind of surprising that they haven't had any warrants yet.
But you're going to be served with an NSL if you get big enough to be interesting. It seems to happen to everyone. An then you won't be able to update the canary any more. That's a good idea, but I don't think it is enough.
I don't mean to be negative, I just guess I don't see why you'll succeed against the government when the others have not.
There may be no single silver bullet here. In addition to pursuing open source key servers, we're also working on UI/UX for easy addition of public key wrapping using the same crypto as PGP. Our hope is that we can deploy public key in a way that most people start using it to minimize the proportion of unwrapped keys on Virtru's server.