Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Shameless plug: I'm working on such a system right now. It gives you the security of PGP, but makes key management transparent to the user without compromising security. The gist is that we designed an automatic key distribution and revocation algorithm that requires an adversary to compromise a bunch of different user-chosen services to break it. The (alpha) white-paper is at [1], poster (USENIX ATC 2014) is at [2], and the source code is at [3]. Also, the design is transparently backwards-compatible with IMAP.

[1] https://www.cs.princeton.edu/~jcnelson/steak-whitepaper.pdf

[2] https://github.com/jcnelson/syndicatemail/blob/master/papers...

[3] https://github.com/jcnelson/syndicatemail



Sounds great, thanks for posting the details.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: