Skip to content

Comment on Ask HN: do you trust your "secure email" now?

Comments

I consider everything I type into a computer with an active network port to be published.

Anything less would be folly, there are so many hops where people could be listening in on your data (starting with the cable that runs from your keyboard to your computer) that even an email sent to your 'drafts' box on your own IMAP server is probably not secure. Unless you own the co-location facility and all the infrastructure between where you sit and where you store the mail.

The whole security thing to me is a matter of economics. I assume that any data that is not worth reading is collected and that anything that is worth more than it would cost to collect and read is read.

Maybe that's a paranoid view of the state of affairs but at least I won't be surprised or disappointed. My main bulwark against wholesale exposure of the contents of my inbox is a 'Rob'. Rob is a veteran sysadmin who configured and set up my machine and I trust him (I have to, since he has access).

Rob is secure in the sense that he's an honorable person, and that I believe that there is no offer that could be made that would make him break our bond of trust. So short of blackmailing Rob (which is hard, and I would definitely forgive him if that were to happen) my stored email is reasonably secure, but any email in transit is fair game and will probably be caught somewhere along the line and I treat all email that I send and receive as public as a consequence of that.

I think you get to a point, where you can't trust electronics at all. (Active network or no.)

Van Eck phreaking. Optical Time-Domain Eavesdropping [1]. Zero-Day exploits on operating systems, browsers, etc. Built-in vulnerabilities to processors. Backdoors in encryption algorithms. Acoustic Keyboard analysis [2]. Laser Audio detection [3]. Hard drive recovery. DRAM recovery. [4]

[1] http://www.rootsecure.net/content/downloads/pdf/optical_temp...

[2] http://www.cs.berkeley.edu/~tygar/papers/Keyboard_Acoustic_E...

[3] http://spie.org/x40847.xml

[4] https://citp.princeton.edu/research/memory/

If I wanted to send (very) secure email, I think I would want a Kindle-like device, with an ePaper display, no physical keyboard just a touchscreen, no bluetooth or wifi or 3G or microphone - just a single USB port. I'd install the software I want on it, and then I'd physically destroy the USB port. I'd want 4 AA batteries, no recharge port. I guess it would need a camera, as well. And it would have its own Faraday cage. And a built-in, non-electronic method that slags the RAM and storage with acid; possibly by pulling a pin out. I'd wipe the screen clean, every time I used it.

How do I get data out of it? I drop data into a QR code sending system. It would generate one full-screen QR-code like image every second or so. On another computer, I'd have a camera that I'd show the device to, and it would read the QR codes, and reconstruct the data. I can reverse the process to send data to it. Show it my computer screen, and it decodes the QR codes to a data file.

And if I personally wanted to increase the security, I would buy three completely different hardware random generators, XOR their output together, and make a giant One Time Pad. I'd invent a way to keep track of where you and I were, in that pad. (You'd start at one end, and I at the other.) I'd physically copy that data onto my secure-Kindle, and your secure-Kindle, and then physically destroy the random number generating system in its entirety. (And then destroy the USB port on both Kindles.) If I ever got a suspicious message from you (re-using One Time Pad, etc.), I'd slag my secure-Kindle. And you and I would invent pass phrases that we would use to communicate messages in secret.

My secure-Kindle would also have a password to let me power it on. And it would have one or more dummy passwords. If I entered a dummy password, the system would act completely normally in every way, but it would secretly insert the phrase "[COMPROMISED, DO NOT TRUST!]" or something like it, in the middle of every message I send.

I might need to have the dummy password electronically wipe the system, to help protect you from a government forcing me to decrypt messages you sent me.

But I honestly don't think there's a good way to stop this. If they have physical possession of the device, and of me, they can force me to reveal my passwords, and there's nothing I can do to stop them.

My second line of defense: I'm not important enough to monitor :)

First they came for the... well, you know.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.