The Register® — Biting the hand that feeds IT

Feeds

NSA-proof email encryption? Cobblers, sniff German hackers

'Comical, shameless game' based on tech that won't stop determined g-men

Free ESG report : Seamless data management with Avere FXT

Analysis German hackers have poured scorn on Deutsche Telekom's plan to offer "secure email", describing it as little more than a marketing gimmick.

Deutsche Telekom and partner United Internet are rolling out SSL-encrypted connections between users’ computers and the companies' mail servers as part of the “Email made in Germany” offer.

Deutsche Telekom's email service T-Online or United Internet's GMX and Web.de services will also avoid routing customers’ email traffic through US-hosted infrastructure - and thus avoid surveillance by Uncle Sam's spooks.

René Obermann, chief exec of Deutsche Telekom, described the offer as a response to the NSA PRISM and XKEYSCORE global internet dragnet controversy: "Germans are deeply unsettled by the latest reports on the potential interception of communication data. Our initiative is designed to counteract this concern and make email communication throughout Germany more secure in general."

The two firms said in a statement that the scheme would offer secure communication for two-thirds of all email users in Germany.

Ralph Dommermuth, chief exec of United Internet AG, added: "Alongside email encryption and the designation of secure e-mail addresses, a third key element relates to data processing and archiving, which is carried out in Germany. This ensures that Germany's stringent data privacy laws are complied with."

Der Spiegel reported that Germany is a focus of the NSA's surveillance operation, which hoovers metadata on up to half a billion communications per month - including emails, text messages and phone calls.

Messages sent to mail servers outside Germany will not be encrypted in transit, at least initially, which means the data can be intercepted by network taps, installed in the internet's arteries worldwide, that are run by the NSA and the UK's eavesdropping centre, GCHQ.

Any service offered within Germany will be subject to EU data retention laws and rules allowing cops and g-men to lawfully intercept or seize data (see El Reg's recent analysis of the Lavabit and Silent Mail shutdowns for details). Metadata collection is unavoidable in the EU and US, so all the "Email Made in Germany" scheme offers is some protection against crooks snooping on email exchanges, rather than anything genuinely spy-proof.

"Email Made in Germany" only promises that email will be protected in transit with no guarantees that it will be stored in an encrypted format. Lavabit offered encrypted storage before it shut up shop last week, perhaps permanently, as a result of pressure from the US authorities to hand over those messages.

German hackers at the Chaos Computer Club dismissed Deutsche Telekom and United Internet's offer as a shrewdly timed marketing stunt. Like security experts, they repeat the advice that end-to-end encryption using packages such as PGP are the only way to ensure email privacy:

Advertising these changes under the label “E-Mail Made in Germany” seems like a desperate effort to bring the already failed project "De-Mail" back into the spotlight. Indeed, these providers are claiming that De-Mail would even improve upon the new practice “in features”.

The supposed improvement is in effect only a shameless game with the users’ increasing problem awareness precipitated by the NSA scandal. It is comical at best if providers are now selling a well-aged technology as a groundbreaking innovation.

What users of these mail services are not being told is that encrypting traffic between mail providers does not mean that the e-mails themselves will also be stored encrypted. Rather, the NSA scandal has shown that centralised services can not be regarded as trustworthy with regard to access from intelligence agencies.

Ultimately, the technologies employed are not capable of preventing the installation of wiretapping infrastructure within the system. The provider and intelligence agencies still have complete access to the contents of e-mails and, consequently, will be able to fully analyze them.

The CCC stands by its recommendation of end-to-end encryption using GnuPG/PGP or S/MIME as a sensible instrument to prevent unauthorised access to e-mail.

Chaos Computer Club's statement refers to De-Mail, a German encrypted email service that links users' addresses with verified identities, confirmed during the sign-up process using state-issued identification cards. De-Mail can be used to complete official documents, such as tax returns, online.

Andre Meister, writing in German on the Netzpolitik.org blog, adds: "The basic problem with email is that it’s a postcard readable by all — [and this] changes nothing. The contents of the mail aren't encrypted, even if the e-mails are stored on encrypted hard drives." ®

Free ESG report : Seamless data management with Avere FXT

Whitepapers

Microsoft’s Cloud OS
System Center Virtual Machine manager and how this product allows the level of virtualization abstraction to move from individual physical computers and clusters to unifying the whole Data Centre as an abstraction layer.
5 ways to prepare your advertising infrastructure for disaster
Being prepared allows your brand to greatly improve your advertising infrastructure performance and reliability that, in the end, will boost confidence in your brand.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Email delivery: Hate phishing emails? You'll love DMARC
DMARC has been created as a standard to help properly authenticate your sends and monitor and report phishers that are trying to send from your name..
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?

More from The Register

next story
Great Britain rebuilt - in Minecraft: Intern reveals 22-BEEELLION block map
Cunning Ordnance Survey bod spent the summer bricking it
EU move to standardise phone chargers is bad news for Apple
Faster than a speeding glacier but still more powerful than Lightning
Google's boffins branded 'unacceptably ineffective' at tackling web piracy
'Not beyond wit' to block rip-offs say MPs demanding copyright safeguards
Hundreds of hackers sought for new £500m UK cyber-bomber strike force
Britain must rm -rf its enemies or be rm -rf'ed, declares defence secretary
Michael Gove: C'mon kids, quit sexting – send love poems instead
S.W.A.L.K.: Education secretary plugs mate's app
NSA in new SHOCK 'can see public data' SCANDAL!
What you say on Twitter doesn't stay on Twitter
Report says PRISM snooped on India's space, nuclear programs
New Snowden doc details extensive NSA surveillance of 'ally' India
Highways Agency tracks Brits' every move by their mobes: THE TRUTH
We better go back to just scanning everyone's number-plates, then?
GCHQ's CESG CCP 4 UK GOV IT BFFs? LOL RTFA INFOSEC VIPs ASAP
Yet another security certificate fiddled with by Brit spooks
The target: 25% of UK gov IT from small biz... The reality: Not even close
Proud mandarins ignoring Cabinet Office's master plan, note MPs
prev story