Show HN: GPG emails for everyone, from everywhere – open sourced
kinko.me
kinko.me
https://news.ycombinator.com/threads?id=dreamdweller
https://news.ycombinator.com/threads?id=banpei
https://news.ycombinator.com/threads?id=dramatise
https://news.ycombinator.com/threads?id=kc99
https://news.ycombinator.com/threads?id=conn23
https://news.ycombinator.com/threads?id=Darkpandemic
https://news.ycombinator.com/threads?id=SanktKlaus
https://news.ycombinator.com/threads?id=freemefromthis
https://news.ycombinator.com/threads?id=SimonJester89
It's possible that this one article caused all the above users to sign up at the same time just to add their one and only HN comment. Occam's razor suggests a different conclusion, however.
And Occam actually would support this, considering it's a much simpler solution than people going about creating accounts, logging in and out of them, to fake positive feedback on a website that matters for technical discussion but not much for marketing value (outside the US).
I have one reservation. From https://kinko.me/faq/ :
The box receives the email and checks that it knows all GnuPG encryption keys needed to forward an encrypted version of the mail. If it does not it rejects the email. Otherwise it encrypts your email and sends it to the receivers’ email accounts.
This makes it sound like a user can only send email to recipients whose GPG keys they have. If this is the case, this is a huge red flag; the past two decades of encrypted email usage has proved conclusively that the huge majority of users do not care about privacy. If as a kinko user I have to get GPG keys for all my friends, this will never take off.
I'd strongly recommend encrypting where possible, but allowing unencrypted copies to be sent where no gpg key is found. Perhaps there could be a warning and resend, eg 'Some of the recipients for this mail have no gpg keys. Please reply to this message to confirm you understand that this message will be sent unencrypted to those recipients'?
Also, if you can solve the user experience problem with generating and using GPG keys, you will be doing the world a great service.
Good luck! Will be following the project with interest.
(Otherwise you would have to use a specific email not only for contacts that don't use GnuPG, but also for registration with 99% of all the websites out there.)
FWIW, GNU Anubis (an MTA) can do gpg signing. Of course, there's a big gap between 'can do' and actually does, which is where this (Kinko) comes in. http://www.gnu.org/software/anubis/manual/anubis.html#SEC64
I've seen a better (opensource) approach to use gpg to securely store email: upon receiving a message, if not already encrypted, use the public key of the account recipient to encrypt it. This way, all email is encrypted with your pgp key. The downside , which this box is trying to solve, is that the (imap) client will need to do the decryption, so it's not transparent to the user. There's also filters for well known MTA (exim,postfix,etc) that will encrypt/decrypt using pgp or s/mime (user/host) keys upon connection.
I see another problem with the 'box' approach, it will need the plain-text passphrase, so if someone steals or has access to your (mail)box, all your email is plain-text and you will have to revoke the pgp key.
Not only that, if you are not aware of the intrusion, someone can impersonate you, since they can sign any message/document with those credentials.
How about redundancy/backups? If the net connection goes down or box/house stops working, what happens to the emails?
Note: This is not spy stuff. This is a reasonably secure environment for your email (and as secure as the average's persons desktop is)
On a desktop, the pgp credentials either exists momentarily (user input) or through an agent, so at first sight it would seem that would be safer, although then we could also argue that a desktop is probably not as safe as this box due to all the other software that is run by the user.
So I guess what I'm saying is you could probably use something hipper and less trademark-infingey. How about "an expression of support or encouragement" from Jamaica?
http://www.urbandictionary.com/define.php?term=big%20ups
Instead of "kinko me" and kinkoing one another the kids could give one another "BIG UPS." I see nothing that could go wrong with this plan.
Isolating this on a separate piece of hardware might be a good idea. But getting your code on the hardware seems like an obvious and fairly fatal flaw. The possibility of the NSA forcing the single maker to insert some hidden code or even some hidden extra hardware makes this a "single point of failure". They sell servers the size of "wall-warts" - you could run Linux or BSD on that and run your secure email on top of that.
Keeping a general purpose computer secure is always going to be a problem but recent experience seems to pretty say "if you can't trust yourself, you can't trust anyone".
1. Subtle bugs that look OK during code review but actually introduce security problems (like == vs = but with a multi-billion-dollar spy agency behind it).
2. Binaries that don't match the source code (compile with the backdoor present, release code with it removed).
2b. An auto-update mechanism that lets the vendor deploy an update only you receive, which compromises your keys, then releasing another update minutes later which removes the compromise and covers their tracks.
3. The device shipping with an update mechanism that adds a backdoor during update installation, so there's no backdoor when you inspect the update on your computer but there is when running on the device.
Moreover compared to the current state when almost nobody uses gpg because it doesn't work with their favourite cloud provider, this approach would provide a nice alternative.
If you trust "magic configuration" to secure your email, you can already have (a lot of) that with just smtp+tls.
As far as I can tell there's no way to know if the email you send will be encrypted or not. So there's no way to know if it can be considered secure or not? Secondly, it appears as if though if the receiver has a public key listed, the email will be encrypted, regardless of whether of the recipient uses gpg normally.
Finally all off-line storage an backup is still plain-text, so if someone, say, gets access to your laptop that you use for reading mail, it's all stored in plaintext on that machine, because it's been retrieved in plaintext from the kinko box.
Fundamentally though, this doesn't help with managing trust, and making trust visible. I agree that is hard, and inconvenient -- but without it I'm not really sure I see the point? Worse than that, I can't see how this won't give a false sense of security.
For this we are going to crowd fund in a couple of weeks.