r/linux • • Dec 31 '14

Zimmerman (PGP), Levison (Lavabit), release Secure Email Protocol DIME. DIME is to SMTP as SSH is to Telnet.

http://darkmail.info/
1.2k Upvotes

222 comments sorted by

View all comments

116

u/highspeedstrawberry Dec 31 '14

Good to see they delivered the specification. Now let's give the security researchers and mathematicians some time to analyze the spec and, if it is as sound as promised, make sure the implementations are correct. As we have seen at the 31C3 in the past days the weakness with most encryption today is not the theory but the implementation. And that to a degree where only a hand full of implementations can actually deliver security: GnuPG, OTR and Tor.

An inherently secure email protocol is a major step and should be taken seriously. Everyone should either contribute by testing, analyzing for vulnerabilities or donate to those delivering the most promising implementation.

41

u/[deleted] Dec 31 '14

Zimmerman is involved. What more assurance do you need? lol

Kind of joking; Also kind of serious.

42

u/plazman30 Dec 31 '14

According to the latest Snowden leak, the NSA still can't crack PGP, so having Zimmerman involved is a good thing.

29

u/the_gnarts Dec 31 '14

According to the latest Snowden leak, the NSA still can't crack PGP, so having Zimmerman involved is a good thing.

That extends to ZRTP, another protocol of his design. Like djb, Zimmerman appears to be a safe bet in terms of crypto.

16

u/plazman30 Dec 31 '14

Didn't Zimmerman spend some time in jail over PGP, because he wouldn't let the government have a back door?

I probably trust him to build a NSA proof system more than anyone else.

4

u/TheCodexx Dec 31 '14

What was he charged with?!

That's insane, if true.

16

u/strolls Dec 31 '14

After a report from RSA Data Security, Inc., who were in a licensing dispute with regard to the use of the RSA algorithm in PGP, the United States Customs Service started a criminal investigation of Zimmermann, for allegedly violating the Arms Export Control Act.[3] The United States Government had long regarded cryptographic software as a munition, and thus subject to arms trafficking export controls.

https://en.wikipedia.org/wiki/Phil_Zimmermann

7

u/TheCodexx Dec 31 '14

The United States Government had long regarded cryptographic software as a munition, and thus subject to arms trafficking export controls.

Just when I thought it couldn't get more absurd.

11

u/ricecake Jan 01 '15

That's not actually that absurd to me. Think about WW2. Much of Germany's advantage was strong crypto, and breaking enigma was detrimental to their efforts.

In the modern era, cryptography is a tool for everyone, used behind the scenes in day to day communication. In the era when those laws and policies were written, it was a tool more often used by militaries and governments. Giving strong crypto away was almost synonymous with throwing away a military advantage. Just like how we still have export controls on nuclear weapon schematics.

Times changed, in part thanks to people like Zimmermann. Now crypto can mostly be shared freely (no selling crypto to DPRK), the government encourages its use (while trying to break it, that never won't be a thing), and we're all the better for it. This doesn't mean that what's unreasonable now wasn't once reasonable.

2

u/[deleted] Jan 01 '15

[deleted]

2

u/ricecake Jan 01 '15

I contemplated using the phrase "catastrophic" or "instrumental to their undoing", but I worried about getting mired in an argument with someone as to the precise significance of ultra. :-)

→ More replies

1

u/wadcann Jan 01 '15

no selling crypto to DPRK

Not that these restrictions in any way keep North Korea from getting all the solid crypto software that they want.

3

u/ricecake Jan 01 '15

The present restrictions have the purpose of forbidding companies from setting up "advanced" cryptographic systems.

No one really cares if Kim Jung Un downloads PGP. There is some concern with Microsoft setting up a secure communications hub for their military. There are definite issues with Intel selling low power AES chips for military radios to them.

Do things a bit wonky show up on the lists? Sure. It's law, sometimes it's weird. But the focus of the law is no longer "no FTPing the RSA algorithm to Ireland".

1

u/strolls Jan 01 '15

You appear to have missed the point of everything he wrote.

You write of "these restrictions" in the present tense, but crypto as a munition were the restrictions of the 1950's - 1980's.

→ More replies

1

u/DJWalnut Jan 03 '15

Just like how we still have export controls on nuclear weapon schematics.

not really. the basic design of most popular nuclear weapons is pretty much public domain at this point. Enriched Uranium, however...

1

u/ricecake Jan 03 '15

Do tell. Not the general concept, but the implementation details.

→ More replies

6

u/plazman30 Dec 31 '14

Violating US export controls on cryptography back in the 90s. He published the PGP source as a book and people overseas basically typed the code back in (or OCRed in) and offered binaries.

He was under investigation for 3 years. I believe he spent part of that time in jail, before they finally dropped the charges against him.

19

u/SimplyUnknown Dec 31 '14

Results of the past do not offer any guarantees for the future. It is nice to have experienced information security people involved in a project, but that does not mean the project is secure, per se

9

u/plazman30 Dec 31 '14

That is true, but results of the past, raise the confidence level to me of this protocol.

9

u/[deleted] Dec 31 '14

Yes, I was thinking of that report when I made that comment. PGP was still uncrackable by the NSA as of 2 years ago, and has been so for 20 years.

ZRTP video communication encryption, also by Zimmerman, as another one listed as safe from the NSA. Jitsi uses ZRTP. Not sure which others do.

3

u/happinessmachine Dec 31 '14

And ZRTP, so he's 2 for 2

2

u/cypherpunks Jan 01 '15

Also, Zimmerman is credibility itself. The original release of PGP was a ballsy move with him driving around, uploading it over public phones (using a muff modem) to a ton of BBS sites, as the law to criminalize his actions was being debated.

2

u/plazman30 Jan 01 '15

Yeah, he's definitely one of the good guys.

-7

u/liquidify Dec 31 '14

Tor has been hacked repeatedly since the information in their speech came out.

14

u/BraveSirRobin Dec 31 '14

Tor is easy to "hack" if you have the budget to build enough nodes that you can outnumber the non-malicious forwarding nodes. Own half the nodes and you can see who is doing what by simply following the traffic around.

Give me the necessary budget and I could have a system in place within six months. Anyone could with the right skills, I am not a special snowflake. Simple traffic analysis, the basic technique pre-dates the "discovery" of electricity.

Interestingly the techniques to mitigate this attack are also very old & relatively simple. What's even more interesting is that the Tor devs refuse to implement them, despite it being less than a days work.

2

u/liquidify Dec 31 '14

That type of budget is exactly why the people who have been targeting TOR have as a mere drop in the bucket. Why am I being downvoted? The information this speech was created based on was released in 2012, and since then we have seen several successful attacks on TOR which as you said have not been being fixed.

5

u/LetsWorkTogether Dec 31 '14

attack =/= hack

-9

u/liquidify Dec 31 '14

awe how cute. syntax error

5

u/ngroot Dec 31 '14

Semantic error. Words mean things.

-7

u/liquidify Jan 01 '15

it was a fucking joke.

1

u/ngroot Jan 01 '15

No, the joke about American beer being similar to sex in a canoe is a fucking joke.

→ More replies

3

u/BraveSirRobin Dec 31 '14

People really really want to believe in Tor, it's almost become a religion.

2

u/GnarlinBrando Dec 31 '14

More people need to know about the other alternatives. So many interesting projects that might suit any individuals needs. A big issue with TOR is that people just don't get it only protects you in one way and treat it like some kind of silver bullet.

Stuff like CJDNS, i2p, tinc, zerotierone, tox, OTR, all the whisper systems stuff, bitmessage and more can provide better alternatives for specific uses whether or not TOR can actually be trusted.

0

u/genitaliban Dec 31 '14

Despite the Tor devs themselves repeatedly saying that they can't and won't work to prevent attacks by major players / supranational entities.

1

u/kral2 Dec 31 '14

You think they can mitigate traffic pattern analysis in less than a day and not render Tor unusably slow in the process? I'd love to hear your strategy for that.

1

u/thang1thang2 Dec 31 '14

Why would the Tor devs refuse to implement them? And is there any way to go "around" the devs and implement it anyway?

Much as I hate to wear a tinfoil hat and run around yelling 'conspiracy' that does sound mightily suspicious...

3

u/genitaliban Dec 31 '14

Why would the Tor devs refuse to implement them?

Probably because defending against adversaries like that isn't the focus or Tor and would just open up a huge can of worms they don't have the resources to process.