Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In many cases, hard core security around email isn't necessary. For light privacy, where you simply don't want the other party to immediately be able to google your address (i.e. craigslist or online dating) I want to recommend Gliph Cloaked Email. https://gli.ph

I run Gliph and am happy to answer questions about the level of anonymity you can achieve if anyone has any.



> We encrypt data with 256-bit SSL in transit and AES-256 encryption before it hits disk.

Your website copy does not inspire confidence in your ability to properly implement cryptography software.


For us crypto-ignoramuses, what's wrong with what you quoted?


>> We encrypt data with 256-bit SSL in transit and AES-256 encryption before it hits disk.

> For us crypto-ignoramuses, what's wrong with what you quoted?

First off, it is very easy to get cryptography wrong. I wouldn't trust most people with being able to implement cryptography software correctly.

Buzzwords like AES and SSL are used to convey a sense of security. Their 256-bit SSL uses AES-256 to encrypt data in transit. While using AES-256 to encrypt a file doesn't mean it is secure. The mode of operation is very important. The following wikipedia page has a picture that was probably encrypted with something like AES-256. I will let you guess what the original picture was.

http://en.wikipedia.org/wiki/Block_cipher#Modes_of_operation

Another issue not discussed is key management. To encrypt the files with AES-256 they need to have the key. If someone breaks into their server, the server will have the key and the files. It becomes easy to break the security.


How do you encrypt data stored on your severs?

Also, the gli.ph https certificate will expire in less than two weeks. You may want to renew.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: