digital knowledge. digital culture. digital memory.

Showing posts with label digital existance. Show all posts
Showing posts with label digital existance. Show all posts

12.10.07

Trust and DE


New to this blog? Why not subscribe to its feed or sign up for free email updates?

[Note to readers: Robert Martin and I have been having a blog2blog discussion about what he terms digital existence. You can see the start of the conversation here.]

You raised one point in your last post that fascinates me - audited Internet services. Before I get to that let me dispense with a couple other discussion points in no particular order.

Regarding Hushmail you wrote,

Since I am paranoid about my personal information, a better solution for my web mail might be something like Hushmail, which both Chris and I have used in the past. I stopped using Hushmail because you did, Chris, so maybe you can explain why you stopped using it.
[Crypto and DE, The Life and Times of Robert W. Martin. October 2, 2007]
This question really takes me down memory lane. Not only does it remind me of many years as a Hushmail user, but it also reminds me of what remains to this day my two most popular blog posts ever. This pair of posts on security and AJAX in March of 2005 still garner a few hits daily according to my vanity web monitoring. These posts have even been sighted, somewhat unflatteringly, in an IEEE conference address by Michael Sonntag, and in the O'Reilly book Ajax Design Patterns in connection with the Host-Proof-Hosting pattern. It is kind of cool as it is the only time in my life that my name is going to appear inside of an O'Reilly book other than when I scribble my name inside my own copies. In these posts, I discuss a general solution to using AJAX to provide cryptographic services, including digital signatures and cryptographic timestamps, to web applications. I also dissect the Java applet-based architecture of Hushmail as an illustration.

Anyway, why did I stop using Hushmail? Two reasons. First, the Java applet-based version of Hushmail that was available in those days (now they have a version that does not require Java) did not work through most corporate firewalls, which was a serious inconvenience to me. Second, from a pure usability stand point, other less secure email services such as gmail, yahoo mail and hotmail all left Hushmail behind in the dust. Still, it is fascinating that with the Java applet version of Hushmail, even the lead Hushmail sys admin could not decrypt my email. I have to claim ignorance on how the non-Java version of Hushmail operates.

You also wrote,
Your differential risk analysis did a good job pointing out that the two areas of concern are the mail client and the mail server. I agree that a well-chosen mail client and a well-chosen browser are arguably equivalent from a security point of view. The issue that comes to mind though is that your DE access point of choice might not offer a well-chosen browser.
[Crypto and DE, The Life and Times of Robert W. Martin. October 2, 2007]
Upon reflection, I missed a jarringly crucial point because my analysis factored out threats that are common to both scenarios under discussion: forget the mail server, can you trust your access point? From keystroke loggers to corrupt Java virtual machines, the permutations of potential threats to your privacy and security at the access point are countless. Cryptography has great potential to protect your messages across untrusted networks, and even on untrusted mail/data servers, but the access point is your encryptor/decryptor! How can you rely on cryptography when your encryptor/decrypto cannot be trusted?

Perhaps you have already suggested the answer in your previous post, "Someone like Gmail could help assuage my fears and increase my level of trust with them if they offered an audit service." If we take this notion one step further, you could also have audited Internet cafes or even audited shared workstations at the office. This workstation audit could provide some assurance that the workstation is free of malware, has no hardware keystroke loggers installed, and that the browser(s) and OS seem to be standard and unmodified at a certain patch level.

Similarly, your idea of audited webmail servers, and by extension other servers as well, is brilliant. One can imagine webmail and remote storage firms providing audited personal information access logs, and submitting periodic security audits and operational audits which would be published by trustworthy auditors in the public domain for all to scrutinize. (Note: I have always felt that credit bureaus ought to operate this way as well, but that is another topic.)

How would this be done? Who would the auditors be? Is there enough market pressure to compel webmail firms to submit to these invasive audits?

Photo by: michele pedrolli

25.9.07

webmail and low bandwidth DE


New to this blog? Why not subscribe to its feed or sign up for free email updates?


In my last blog2blog post to Robert W Martin, I asked him to explain why he wants to live his life online without needing his own equipment - something he calls digital existence.

You gave a pretty decent answer, Rob. For me, one of the most powerful motives for seeking digital existence is that it is now technically conceivable to overcome the security concerns inherent in hardware independence. This point was hammered home by your comment on your experience with electronic health records. If Alberta Health and Wellness can provide secure remote access to legally protected patient records, certainly it is possible to provide secure (or at least secure enough) remote access to my CV drafts, letters to the power company, and weiqi game records?

Digital existence has a different attraction in the South Pacific. If I had to characterize computer use in this part of the world it would be as follows:

  • There is a large cohort of older, wealthy, professionals who are heavy Internet users at home and at work; they can afford the high price of connectivity
  • There is a larger cohort of young users who have very little disposable income
  • This younger cohort are primarily unsophisticated but passionate users of low bandwidth social computing - hi5, bebo, facebook, free sms gateways to local mobile phone companies, and photo sharing sites
  • This younger cohort would love to share files and video as well, but the slow and/or expensive connections in the region make this impractical - you can almost hear a chant of I want my youtube
  • This younger cohort does not own their own computers nor do they typically have Internet connections at home - they rely on Internet cafés, computer labs at educational institutions, and their workplace to get online
In short, 20-somethings in the South Pacific are living low-bandwidth digital existence right now. However, they are doing so with very little understanding if the privacy and security ramifications of their activities.

So, with that, time for some the paranoia. When we started this, you asked, "can you really trust webmail?" A great question. Let's examine this with a little differential risk analysis. If you were going to send me an email, the list of locations where your message falls under threat would be as follows:
    The traditional POP3/IMAP (i.e. Outlook Express) scenario:
    Rob's POP3/IMAP client, Rob's PC, Rob's LAN, Internet, Rob's mail server, followed by the Internet again and then into an area influenced by my email choices.
And the webmail scenario looks like this:
    The webmail (i.e. gmail, yahoo, or hotmail) scenario:
    Rob's browser, Rob's PC. Rob's LAN, Internet, Rob's webmail host, followed by the Internet again and then into an area influenced by my email choices.
Let's agree that the risks inherent in your message traversing your PC, your (possibly wireless) LAN, the Internet, and my email-sphere-of-influence are common to both scenarios and mention them no further. Let's focus on the two legs of the journey that differ:
  • POP3/IMAP client vs. browser
  • the POP3/IMAP/SMTP mail server vs. the webmail server (which includes SMTP of course)
Looking at the clients, I think a well chosen mail client is no more or less secure than a well chosen browser. Both can operate with or without SSL/TLS (if supported by the server), both can render HTML and can execute Javascript, and both are extendible with various privacy and security enhancing plug-ins. They differ in that the mail client saves all of your mail on a local drive, which is great if you are the only user or a machine but terrible if the machine is used by multiple users. I suppose you could rig your mail client to store your mail on a removable device.

The browser, on the other hand, will often write some or all of your webmail fetched mail to cache - especially on a shared computer where you do not control the settings . Even once the cache is cleared, your mail may linger until some cryptographic disk wiping takes place, unless you cache to a removable device. Also, your browser would be vulnerable to session hijacking attacks that would not impact a mail client. For machine independent secure emailing, a thumb drive mounted mail client and a thumb drive mounted browser (see xb browser) are probably equally good, but having a thumb drive feels like cheating when the point was to have no hardware of your own. If you disallow thumb drives, the browser seems to come out ahead in the digital existence balance.

Looking at the servers, both traditional POP3/IMAP/SMTP servers and webmail server's can archive some or all of your email after it has been sent or received, including messages that you have deleted. Perhaps the difference is that webmail servers are guaranteed to have a copy of all of your mail, and it will be all indexed and ready for searching by:
  • you
  • any data mining software
  • any advertising (think gmail) software
  • any unscrupulous sysadmin
  • any criminal who gains access to this juicy repository of information
  • any government agent with a warrant (Patriot Act or otherwise)
Still the use from anywhere nature of webmail is invaluable to the goal of digital existence. So the conversation naturally moves towards cryptography...

Photo by: nico.cavallotto

20.9.07

Debating digital existence


New to this blog? Why not subscribe to its feed or sign up for free email updates?


My buddy Robert W Martin (not the guy in the picture) wants to live his life online. But he wants to do it without owning any of his own hardware. To readers in Fiji, this may sound like a yaqona induced fantasy, but Rob lives in a large city in Canada. For about CDN$40 (FJ$60) per month, he gets a connection at home at a speed of about 512kb/s, up and down, with no practical usage limit. At work, his connection may be as fast as 1Mb/s and similarly fast connections are available at numerous Internet cafes for anywhere from free to CDN$5 (FJ$7.50) per hour, not to mention various mobile networking options with various speeds and prices.

With affordable and fast connectivity like this, all he needs to do is get a free webmail account, an online office application service like Google Docs, a file vault, maybe a photo hosting site, and then a bunch of IM and P2P accounts and he's set, right? But here's the problem, like most security professionals, he's paranoid.

He calls his quest the search for digital existence:

This means not having a computer of my own. No desktop, no laptop, not even a wifi-connected smartphone. I want to exist online and experience the richness of the web without having to own any hardware. My access will be through public access terminals and Internet cafes, and by borrowing bandwidth from work, friends and family.[Digital existence revisited, The life and times of Robert W Martin]
Rob has invited me to hammer through some of the difficult questions with him in a blog2blog conversation.

Rob, you suggested that we address these questions:
  • Can you really trust webmail?
  • Do you really want your files hosted online?
  • How much encryption do you need?
  • Do you need your own access device (keyboard, computer, PDA, etc.) or can you trust public computers?
Good ideas, but first I want to know why. Why do you want to live on the net without your own hardware? Why do you want digital existence?

Photo by: Cayusa