Subscribe / Unsubscribe Enewsletters | Login | Register

Pencil Banner

Silent Circle, Lavabit unite for 'Dark Mail' encrypted email project

Jeremy Kirk | Nov. 1, 2013
Dark Mail will provide end-to-end encryption, including email metadata

In that case, the party interested in the communication would have to request the encryption key from a person or find another way to decrypt the message.

Snowden's documents showed the NSA was also collecting email metadata, which reveals a sender's and recipient's email addresses, subject line of the email, IP addresses and more. Dark Mail will encrypt the metadata, using the XMPP protocol to signal when a new message has arrived, Callas said.

The alliance is also considering longstanding problems around encryption keys, such as public and private key pairs that are in use for years. "The longer that a key stays around, the bigger of a vulnerability it is," Callas said.

One idea is to create a protocol that would only keep a static public key for just a few hours or a day and then refresh it. Older messages would need to be re-encrypted with a new key to maintain access, but it would provide much better long-term protection for sensitive messages, Callas said.

Also under consideration is "forward secrecy," an encryption feature that limits the amount of data that can be decrypted if a private key is compromised in the future.

Wide use of encrypted email has implications for companies such as Google, which displays advertisements based on email content. In industries such as financial services, companies are required to retain email for compliance regulations.

There's also a convenience factor, as email encryption isn't necessarily easy to implement, especially as people use multiple tablets and mobile phones and desktop computers. Callas said Dark Mail will be flexible, allowing users to send unencrypted email if they don't need an extra level of security.

 

Previous Page  1  2 

Sign up for CIO Asia eNewsletters.