Skip to content

Comment on Say Goodbye to BlackBerry? If Obama Has To, Yes He Can. Maybe.

Comments

Presidential email is a tough technical problem. The audit trail piece is easy enough, but there's also the problem of keeping the email account clean and secure. Somehow, it needs to provide relatively unfettered access to the president from his close friends and advisors, but not allow the general public or untrusted parties to send messages to it. It should guarantee that emails sent to that account are from verifiable sources. It absolutely must guarantee that emails sent from that account were sent by the president.

Security by obscurity is bound to fail, as an obscure address will leak out quickly. A private-key system (PGP/GPG) is a step in the right direction. All unsigned or unencrypted mail sent to or from that account would be rejected outright (but looked at by staff and saved, of course). In this restricted case, where the number of trusted recipients is manageable, even the public key distribution problem is simple: a Secret Service agent could hand-deliver a CD containing the president's public key to every trusted recipient, and pick up the recipient's public key in return.

Keeping recipients' private keys secure is more difficult. Whereas I'm sure that the NSA or even the White House IT staff can keep the president's private key reasonably safe, a security breach on a correspondent's laptop, with a private key on it, would potentially mean that someone can masquerade as a trusted recipient. That would, at best, lead to the feared PR nightmare and scandal.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.