From: Guyzmo <guyzmo+notmuch@m0g.net>
To: Jameson Graef Rollins <jrollins@finestructure.net>
Cc: notmuch@notmuchmail.org, Daniel Kahn Gillmor <dkg@debian.org>
Subject: Re: Feature suggestion. Indexing encrypted mail?
Date: Sun, 6 Apr 2014 11:15:16 +0200 [thread overview]
Message-ID: <20140406091516.GG26903@vilya.m0g.net> (raw)
In-Reply-To: <87txa7pp8z.fsf@servo.finestructure.net>
Hi!
On Sat, Apr 05, 2014 at 12:09:32PM -0700, Jameson Graef Rollins wrote:
> On Sat, Apr 05 2014, David Bremner <david@tethera.net> wrote:
> > john.wyzer@gmx.de writes:
> >> Would it be possible to add the configurable option to also decrypt
> >> encrypted messages on the fly while indexing to make them searchable,
> >> too?
> > As far I understand an attacker could reconstruct the message from the
> > index, so one question is whether the extra complexity in notmuch is
> > worth the minimal extra security over decrypting on delivery and storing
> > plaintext on the (presumably encrypted) disk. Of course decrypting on
> > delivery may be inconvenient (or impossible). I have CCed the two people
> > who have implemented most of the crypto related stuff in notmuch so they
> > can comment.
> Indexing encrypted email is a bit of a foot-gun, since, as David
> mentions, it is apparently possible to reconstruct encrypted messages
> From the index. It therefore needs to be approached with care.
>
> I think decrypting on "delivery" (or mail fetch or whatever) sounds
> difficult and unwieldy. In either event, it seems out of the scope of
> notmuch. If a user figured out how to have that done, no changes to
> notmuch would be needed afaict.
[…]
I indeed agree with this view, and I think the best process would be
to have the MUA decrypt and index an encrypted mail when the user wants
it to be indexed. So the user do not get really highly secret messages
disclosable by the index, and for the others take that kind of risk.
That way you wouldn't need to keep the secret in the gpg-agent for
too long, and/or need a password for an automated process.
my two cents,
--
Guyzmo
next prev parent reply other threads:[~2014-04-06 9:17 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-04-05 16:38 Feature suggestion. Indexing encrypted mail? john.wyzer
2014-04-05 17:10 ` David Bremner
2014-04-05 18:35 ` Jeremy Nickurak
2014-04-05 19:03 ` john.wyzer
2014-04-05 19:09 ` Jameson Graef Rollins
2014-04-06 9:15 ` Guyzmo [this message]
2014-04-06 22:16 ` Daniel Kahn Gillmor
2014-04-07 8:08 ` john.wyzer
2014-04-07 15:57 ` Jameson Graef Rollins
2014-04-07 20:15 ` Jeremy Nickurak
2014-04-07 20:31 ` Jameson Graef Rollins
2014-04-07 21:06 ` Mark Walters
2014-04-08 5:25 ` Daniel Kahn Gillmor
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
List information: https://notmuchmail.org/
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140406091516.GG26903@vilya.m0g.net \
--to=guyzmo+notmuch@m0g.net \
--cc=dkg@debian.org \
--cc=jrollins@finestructure.net \
--cc=notmuch@notmuchmail.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
Code repositories for project(s) associated with this public inbox
https://yhetil.org/notmuch.git/
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).