TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Announcing The Dark Mail Alliance – Founded by Silent Circle and Lavabit

565 pointsby cyloover 11 years ago

40 comments

natural219over 11 years ago
I appreciate the cheekiness of calling it the "Dark Mail Alliance", but from a purely PR perspective, it would make sense to reconsider your name if you are taking the position that encrypted end-to-end email is not solely an interest of those pursuing shady or deviant activities.
评论 #6643371 未加载
评论 #6643375 未加载
评论 #6643416 未加载
评论 #6643858 未加载
评论 #6644263 未加载
评论 #6645806 未加载
评论 #6655625 未加载
评论 #6646334 未加载
评论 #6643688 未加载
评论 #6643393 未加载
评论 #6646903 未加载
评论 #6645947 未加载
评论 #6643222 未加载
评论 #6646528 未加载
ChuckMcMover 11 years ago
I hope they are successful. For a long time I have wished that someone with the expertise and time would be motivated to create a new email system from the ground up, and make that system widely available and &#x27;open&#x27; (in the sense of open protocols).<p>There are many challenges, but if they can pull it off there are many benefits as well. And perhaps the nicest part is that it is hard to actively oppose such efforts without revealing an intent.
评论 #6644116 未加载
erikbover 11 years ago
I am definitely no security expert, but from my feeling it seems as if unsecure protocol + secure messaging layer is much more successful in practical applications than purely secure protocols. Therefore my believe would be that improving existing secure messaging layers would help the world much more than creating another secure protocol which nobody will use because it would require to replace the whole infrastructure. Especially Email seems to be something that is unlikely to go away, because of its long history, huge infrastructure and simplicity.
评论 #6643467 未加载
natchover 11 years ago
My Fucking Mail would be a better name. As in, it&#x27;s mine, do fucking not read it. Sorry for the profanity but I think it fits how many people feel about this.
评论 #6646161 未加载
评论 #6644658 未加载
zokierover 11 years ago
To everyone complaining about the name: it is just the name of the advocacy&#x2F;development group. You don&#x27;t call SMTP mail &#x27;IETF mail&#x27;, nor should you call call whatever they come up &quot;dark mail alliance mail&quot;.
评论 #6643679 未加载
danielweberover 11 years ago
Anyone gone through the checklist yet? <a href="http://craphound.com/spamsolutions.txt" rel="nofollow">http:&#x2F;&#x2F;craphound.com&#x2F;spamsolutions.txt</a>
评论 #6642834 未加载
评论 #6642806 未加载
Cort3zover 11 years ago
This is very good news. An interesting not here: In Norway the official postal service, Posten, has introduced something called DigiPost. Post means mail, so DigiMail. This is essential a secure way of sending information and it is approved by the Norwegian government for sending and receiving sensitive information. So you can ask to get your sensitive government stuff through DigiPost.<p>My point being: There is already a big market for sending secure emails. If this Dark Mail, or whatever it is called, is secure enough for a government to use then the adoption will be huge.<p>This probably means that it should be called something else than dark. &quot;Normal people&quot; don&#x27;t know what encryption is, what NSA is or even why it is bad that companies like Google read and use their email. They won&#x27;t know why or even that their email is insecure. They might have ssl in their Web browser showing a small lock, so they think they are already secure and don&#x27;t need this &quot;SecureMail&quot;. It is absolutely critical that the name of this thing is something that a normal person will feel that he&#x2F;she needs. Something as simple as &quot;New Email&quot;. Yes, the nerds will rage, but the nerds already knows why this is a big deal. The name does not need to cater to them. What is important is to get adoption of this new email platform. And naming it secure mail will probably not help. And having a dark alliance behind it all is the worst idea so far. Both words have negative annotations and sounds like a untrustworthy hacker group or even a terrorist organization. Needless to say, they need some serious re-branding, and fast.
评论 #6646203 未加载
ajover 11 years ago
And this is how committees fail to achieve results ;) The top 20 (?) comments (or at least the most voted comment thread) is a discussion&#x2F;argument on just the name...
cottonseedover 11 years ago
Terrible name.
评论 #6642292 未加载
评论 #6642854 未加载
评论 #6642875 未加载
评论 #6642531 未加载
评论 #6642536 未加载
评论 #6642272 未加载
评论 #6643271 未加载
Tepixover 11 years ago
From the talk that just finished at Inboxlove, it appears they will use XMPP for transport, some JSON and encrypted cloud storage.<p>You receive a message via XMPP that an email is waiting for you on the cloud storage (similar to MMS). This is also a good solution for the spam problem, I think.<p>They have a working prototype, a whitepaper is forthcoming and the community is welcome to improve the new standard.
评论 #6643667 未加载
mikegirouardover 11 years ago
For those who didn&#x27;t know already (I didn&#x27;t, this is new territory for me), Silent Circle is co-founded by Phil Zimmermann (the PGP guy).
r0mualdover 11 years ago
&quot;Stay connected with the Dark Mail Alliance<p>[Enter your e-mail] &quot;
评论 #6643120 未加载
thebossover 11 years ago
I hope to see this magic new mystery protocol as something similar to TextSecure, where we have forward secrecy from the OTR protocol.<p>The current e-mail protocols are far too centralized, which doesn&#x27;t make sense. Mail is delivered, and after that, it is no longer in possession of USPS. This is unlike how E-mail works (even though it kind of seems like that&#x27;s what happens).<p>I hope to see some kind of client being required to run on my computer to decrypt e-mails at rest and receive e-mails that are delivered to me from the central server.
评论 #6645400 未加载
conroyover 11 years ago
I&#x27;m really interested in their solution for solving metadata leakage. I just looked over the SCIMP white paper, and it didn&#x27;t mention anything about metadata.
评论 #6642980 未加载
评论 #6642863 未加载
ad93611over 11 years ago
The site <a href="http://www.darkmail.info/" rel="nofollow">http:&#x2F;&#x2F;www.darkmail.info&#x2F;</a> is served over http and not https. If someone has access to the pipe, it would be easy get the email addresses of people who submit their email addresses at that site.
评论 #6645084 未加载
chiphover 11 years ago
Not sure I understand. Both SilentCircle and Lavabit have ceased offering their services. Are they now combined in an advocacy group to design a new email protocol and get it adopted by the IETF?
评论 #6642877 未加载
评论 #6644138 未加载
评论 #6643045 未加载
alexchamberlainover 11 years ago
As much as I hate promotion emails, I do hope they make sure that companies can still send mass &quot;dark mails&quot; securely, rather than sending the one by one...
评论 #6642633 未加载
devxover 11 years ago
They mentioned having a &quot;web of trust&quot; to help fight spam. But if you use that, doesn&#x27;t it mean someone like NSA, who can get everyone&#x27;s public keys (which I assume is what they&#x27;re going to use for this, just like for PGP), could then identify who are the people talking to each other, and essentially invalidate all their metadata gather protections? Or would that key be ephemeral, too?
prestyover 11 years ago
you can listen to more here <a href="https://www.youtube.com/watch?v=IgV_Z6V_llk" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=IgV_Z6V_llk</a><p>started at min 30 or so
digitalengineerover 11 years ago
Can we stop with &#x27;the name sucks&#x27; meta discussion and focus on the topic? I for one would <i>love</i> to see this work out. It&#x27;d be goddamntime someone clever did something about it and I could not imagine two better parties starting this.
pixelcortover 11 years ago
Since it hasn&#x27;t been mentioned yet, OS X and iOS already support S&#x2F;MIME encrypted email, and having the private keys live on users&#x27; devices and doing encryption of outgoing messages on users&#x27; devices is probably the safest setup.
评论 #6644927 未加载
frank_boydover 11 years ago
Sounds like another reinvention of the wheel, the &quot;email&quot; part of <a href="http://retroshare.sourceforge.net/" rel="nofollow">http:&#x2F;&#x2F;retroshare.sourceforge.net&#x2F;</a>
评论 #6644817 未加载
softworksover 11 years ago
Email is so broken from a security standpoint I doubt that email 3.0 would even make it off the ground. You would be better off taking something like IM which silent circl allready has a secure solution for and adding the store and forward capabilities that make email email. Then u could have email clients use that protocol. But asking the entire world to change &#x2F; upgrade it&#x27;s email servers and clients with a fundamentally different protocol. I don&#x27;t see that being successful.
tocommentover 11 years ago
What&#x27;s wrong with bitmessage?
评论 #6643037 未加载
评论 #6642784 未加载
dllthomasover 11 years ago
&quot;Dark Mail&quot; reminds me of Chrono Trigger...
评论 #6647461 未加载
nhermentover 11 years ago
I don&#x27;t understand how anyone of you can say &quot;it&#x27;s never going to take over email 1.0&quot;. Success is a lot about realisation. We have to start somewhere and this is a good start as any.<p>Having a standard is certainly a necessity. I definitely see secure email starting as a niche and if the user experience is at least as good as gmail I don&#x27;t see any reason why a new email system would not take over.<p>It&#x27;s not going to happen overnight but there definitely is a need for it. Lavabit and Silent Circle are proofs that this need is real.<p>There are major issues with replacing the current email:<p>1) there is no good open source email interface (if I&#x27;m wrong, please point me to this gem). Roundcube is good but not good enough when you come from gmail. I don&#x27;t know of anything better than roundcube.<p>2) the threshold for a company to implement secure email is too high. Having a secure standard with secure libraries certainly lower that threshold<p>3) the current open source mails are GPL like licenses. This sucks for companies and individuals. Give them the ability to do what they want, including money. Replacing email is not going to happen without investment. Technology investments are mainly done by companies, only exceptionally by individuals.<p>Anyway, if anyone wants to take a shot as implementing an easy to use &amp; opinionated (ie standardisation vs customization) webmail, chime in: <a href="https://github.com/nherment/dolphyn" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;nherment&#x2F;dolphyn</a><p>(edit: form &amp; typos)
pekkover 11 years ago
Why did Lavabit ever need to have my messages in the clear?<p>The problem is manufactured and the solution is missing the point.
betterunixover 11 years ago
What exactly remains to be developed? We have Mixmaster, Mixminion, Sphinx, etc....
speedyrevover 11 years ago
SPOILER: A year from now we find out this is an NSA black ops project.
评论 #6644406 未加载
computerheadover 11 years ago
&quot;dark mail alliance&quot; group, here is what you need to do...<p>1. get a new website, terrible design even from a 1995 point of view it is bad. Drop shadows on tag-lines are tacky. Not that tech people care, but if you want to take over the world. Try starting by having a decent designer on your team.<p>2. the only way to &quot;truely&quot; fix this for good is to not use email. instead, use a different form of communication (im thinking of...)<p>3. work with a few &quot;enterprise companies&quot; 4. get some capital 5. lastly, email is really still on 1.0, there was really no 2.0... unless you consider the time before the internet as 1.0 when the government used internal mail. But as we know mail today technically its still 1.0
hafichukover 11 years ago
Has anyone actually confirmed that Ladar Levison is behind this?
评论 #6643906 未加载
yaiuover 11 years ago
I wish they would give some sort of freebie to prorated Lavabit users that were were SOL due to the shutdown.
balabasterover 11 years ago
This is awesome, but will it be open sourced so that everyone can inspect the code and verify its sanctity?
xanthover 11 years ago
In all seriousness my opinion can be summed up as; Open Source Or GTFO
infocollectorover 11 years ago
Can we not just do this with an open alliance and pick up a name ?
tbfrenchover 11 years ago
LinkedIn to announce Dark Mail support.
shazowover 11 years ago
Maybe better yet, EncMail.
tylerkahnover 11 years ago
If you were interested in seeing any details whatsoever about the protocol there are none either in the article or on the official website.
评论 #6642703 未加载
ebbvover 11 years ago
The name &quot;Dark Mail&quot; is going to automatically be associated with the &quot;Dark Net&quot; which brings up thoughts of drug dealing and child pornography. This is their first problem.<p>The second is their approach. Overcoming the install base of current email, no matter how much better your new offering, is practically impossible. So instead secure layers on top of existing email is your only feasible option.
ps4fanboyover 11 years ago
Something like Secure Mail, Safe Mail, Trust Mail, Private Mail sounds better than Dark Mail