Skip to content

Comment on NSA-Proof Your Email Without Encryption

Comments

This doesn't prevent your server/CA being compromised like an encryption scheme like PGP would.

rxlOP

Yes, if the server is compromised before a recipient reads a particular email, that can allow the attacker to read that email. However, all emails that are read are deleted from the server and unread emails are automatically deleted after a certain number of days. So, if someone was to compromise the GhostMail server, he/she would only be able to read a paltry amount of messages.

If GhostMail was compromised, the attacker would be able to read messages as they are being sent. Sending messages as images does not stop them from being copied or held for an indefinite amount of time.

rxlOP

In the unlikely scenario that the app was compromised and stayed compromised, you would be correct. However, if it was compromised and the situation was quickly rectified, only sent but unread messages would be able to be read. If a service like WhatsApp was compromised, however, a much larger amount of messages would be able to be read.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.