OK, here's my monthly props for
CryptoGram...
Bruce Schneier links to a story where some
Russians use a '
dead drop' technique via anonymous email systems like Hotmail.
The idea is that 2 or more people share an email account and instead of
sending email messages to each other they just save their message as a
draft email for the next guy to read.
I like this as a specific case to illustrate the more general point
about security based on "building higher walls" being bad becuase it
assumes that all entry points are known!
After blog mint [?]:
I've been thinking more about this... the key isn't that the message
never went across the wire because it did (from the PC to the Hotmail
server) but it's that it didn't leave Hotmail via SMTP, so the goal in
sight is to avoid SMTP message detection and signal analysis based on
SMTP traffic. Taking that as the general case leaves open a bunch
of other scenarios, like storing secret data on mobile SIM cards for
example. Just a thought...