Welcome to Scribd, the world's digital library. Read, publish, and share books and documents. See more
Download
Standard view
Full view
of .
Save to My Library
Look up keyword
Like this
2Activity
0 of .
Results for:
No results containing your search query
P. 1
PRISM Proof Cloud Email Services

PRISM Proof Cloud Email Services

Ratings: (0)|Views: 417 |Likes:
Published by hughpearse
This article is a survey of free cloud email services. It lists services by their affiliation with the NSA, their support for HTTPS, their support for SSL ephemeral mode, and the physical location of their servers.
This article is a survey of free cloud email services. It lists services by their affiliation with the NSA, their support for HTTPS, their support for SSL ephemeral mode, and the physical location of their servers.

More info:

Published by: hughpearse on Jul 04, 2013
Copyright:Attribution Non-commercial

Availability:

Read on Scribd mobile: iPhone, iPad and Android.
download as PDF, TXT or read online from Scribd
See more
See less

12/12/2013

pdf

text

original

 
PRISM Proof Cloud Email Services
Introduction
Cloud email services use SSL certificates to encrypt the conversation between your browser  and the HTTP server, this encrypted traffic is called HTTPS. Most HTTPS certificates allow for a master key to decrypt the encrypted traffic, however this is not true for certificates which use a temporary session key which is individual for each user. This is known as SSL ephemeral mode.This article is a survey of free cloud email services. It lists services by their affiliation with the NSA, their support for HTTPS, their support for SSL ephemeral mode, and the physical location of their servers. By carefully choosing a cloud email service, users can be confident that their  traffic is not entering the network of the United States. Additionally if their traffic did enter the United States, the SSL certificate of the cloud service they select supports ephemeral mode which prevents the NSA from gaining a master key to decrypt network traffic.
Lists of free cloud email services
http://ubuntuforums.org/showthread.php?t=2125732http://email.about.com/od/freeemailreviews/tp/free_email.htmhttp://capturedbloggingtips.com/2013/03/6-best-alternatives-to-gmail/
 
https://en.wikipedia.org/wiki/Comparison_of_webmail_providershttp://prism-break.org/#email-services
Individual cloud email services that support HTTPS
https://www.gmx.comhttps://www.hushmail.com/https://mail.google.com/https://www.zoho.com/mail/https://mail.aol.comhttps://www.icloud.com/https://www.outlook.com/owa
https://mail.live.comhttps://mail.yahoo.com/https://www.mail.com/int/https://shortmail.com/https://www.inbox.com/https://lavabit.com/https://www.fastmail.fm/https://mail.yandex.com/https://www.mail.lycos.com/https://www.nokiamail.com/https://www.rediff.com/https://mail.riseup.net/https://www.contactoffice.com/https://webmail.xmission.comhttps://ojooo.com/https://mail.opera.com/
Private key disclosed to law enforcement (PRISM/FBI etc)
https://mail.google.com/https://mail.aol.comhttps://www.icloud.com/https://www.outlook.com/owa
https://mail.live.comhttps://mail.yahoo.com/https://www.hushmail.com/
Private key not disclosed to USA law enforcement (this list is used for the remainingtests)
https://www.gmx.comhttps://www.zoho.com/mail/https://www.mail.com/int/https://shortmail.com/
 
https://lavabit.com/https://www.inbox.com/https://www.fastmail.fm/https://mail.yandex.com/https://www.mail.lycos.com/https://www.nokiamail.com/https://www.rediff.com/https://mail.riseup.net/https://www.contactoffice.com/https://webmail.xmission.comhttps://ojooo.com/https://mail.opera.com/
Domains that use Ephemeral Diffie-Hellman key exchange on HTTPS
www.gmx.com- DHE_RSAwww.mail.com- DHE_RSAshortmail.com- DHE_RSAlavabit.com- DHE_RSAwww.mail.lycos.com- DHE_RSAmail.riseup.net- DHE_RSAwww.contactoffice.com- DHE_RSAwebmail.xmission.com- DHE_RSAojooo.com- DHE_RSA
Domains that use Ephemeral Diffie-Hellman key exchange on POP3:995
pop3.inbox.com - DHE-RSA-AES256-SHApop3.ojooo.com - DHE-RSA-AES256-SHApop.contactoffice.com - EDH-RSA-DES-CBC3-SHA
Domains that use Ephemeral Diffie-Hellman key exchange on IMAP:993
imap.inbox.com - DHE-RSA-AES256-SHAimap.ojooo.com - DHE-RSA-AES256-SHAimap.opera.com - DHE-RSA-AES256-SHAimap.contactoffice.com - EDH-RSA-DES-CBC3-SHA
Domains that use Ephemeral Diffie-Hellman key exchange on SMTP:465
smtp.inbox.com - DHE-RSA-AES256-SHAsmtp.riseup.net - DHE-RSA-AES256-SHAsmtp.xmission.com - DHE-RSA-AES256-SHAsmtp.ojooo.com - DHE-RSA-AES256-SHAsmtp.opera.com - DHE-RSA-AES256-SHA

Activity (2)

You've already reviewed this. Edit your review.
1 thousand reads
1 hundred reads

You're Reading a Free Preview

Download
/*********** DO NOT ALTER ANYTHING BELOW THIS LINE ! ************/ var s_code=s.t();if(s_code)document.write(s_code)//-->