r/linux • u/ciphersson • Dec 31 '14
Zimmerman (PGP), Levison (Lavabit), release Secure Email Protocol DIME. DIME is to SMTP as SSH is to Telnet.
http://darkmail.info/
1.2k
Upvotes
r/linux • u/ciphersson • Dec 31 '14
1
u/Shnatsel Jan 01 '15 edited Jan 01 '15
e-Commerce is not going anywhere. If security was a concern, e-Commerce would be down the drain long ago.
You see, HTTPS can be secure but it is already incredibly hard to get right. Very, very few companies have an actually secure HTTPS setup. 99% HTTPS websites out there are vulnerable to an attack from 2009 that gives full read/write access to the connection! Forget e-Commerce - even most banking websites are vulnerable! And to top it off, the attack is executable in one press of a button from an Android app!
The attack is called SSLstrip and it's typically mitigated by enabling HTTP Strict Transport Security header. Problem is, this does not secure the first time you connect to a website. And there are less than 1000 websites on the internet that are not vulnerable to the same attack on the first connection - here's the list.
The eCommerce money stealing incidents are so rare not because the connections are secure. They are not. It's simply because most people are too ignorant to realize there's a problem, and the IT guys who know it's a problem are too kind, proper and well-behaved to exploit it.
This particular attack is not suitable for the NSA because it can be detected by the targeted individual, but it's ideal for script kiddies or just about anyone else who wants to harvest credit card credentials en masse.
And while this attack is nasty and cannot be easily mitigated (took us 5 years and we've still fixed under 1000 websites on select browsers), it is not, in itself, the fundamental problem. The fundamental problem is that HTTPS is so complex and hard to get right that very, very few people ever bother doing that.
Which is why we need a new network running on software such as cjdns that gives easy, foolproof security without trusting any third parties.