Vaporizing communications: Splitting the message

Opinion
Apr 13, 20116 mins

Jack Hembrough, CEO of VaporStream, continues his discussion of controlling e-mail distribution which he started in the last column. Everything that follows is Mr. Hembrough’s own work with minor edits.

* * *

Have you ever responded to an e-mail, “Give me a call and let’s discuss” because you were uncomfortable putting private information in the reply? Lawyers are no longer the primary professionals who are circumspect about what they put in electronic messages. There is a growing sense that pressing “send” for an electronic message is tantamount to publishing the content. The potential for disclosure and the lack of privacy in electronic communication is becoming sand in the gears of progress. The lack of privacy, or the fear of public disclosure, is driving business people away from traditional written electronic messaging, despite the proliferation of mobile devices, and “Give me a call and let’s discuss that” is a phrase returning to our daily dialog.

For instance, how can the CEO of a public company inform the Board of Directors that earnings are going to exceed quarterly estimates without fear that the information will be shared?  Traditional electronic messaging is a very risky way to deliver this good news. An e-mail could be printed out and left in the seat back pocket of an airplane, resulting in an embarrassing data breach. However, if an unintended passenger found the e-mail and passed it on to the Galleon Group, it could result in a criminal offense.  

The wonderful productivity tools that comprise traditional electronic communications – e-mail, text, IM, even Twitter — are being put aside as folks return to face-to-face meetings and phone conversations to restore a semblance of privacy. Sun’s Scott McNealy reminded us over a decade ago, “You have zero privacy. Get over it.” Do we really have to get over it?  

To stay private, a written electronic message:

1. Would not exist where it could be read by anyone except the author and the intended recipient.

2. Would have all copies controlled for their entire life cycle.

3. Would be immune to digital photographic capture.

It would be recordless.

Encryption from the source to the destination addresses the first requirement for truly private electronic communications. Fortunately, that’s pretty straightforward. Peer-to-peer encryption guarantees the message does not exist in cleartext anywhere except the end points, but it does require endpoint key management and, likely, an endpoint agent.

SSL/TLS encryption is most often used leveraging the public key infrastructure (PKI) that is built into nearly all devices.By applying cryptography at the endpoints, SSL is adequate as long as you trust your network provider.  

The second requirement is more difficult since as soon as the message is written to permanent memory, copies can be made. The more copies, the more difficult it is to control the message. One solution is to ensure there is only one copy of the message, and that the one copy disappears after it is viewed.

To ensure a single copy, the message must be contained in a custom viewer (or Web page) that does not allow writing outside of volatile display memory, preventing duplication. When the viewing screen is overwritten after the message is read, the message disappears.

With everyone carrying at least one mobile device equipped with a camera, the screen shot immunity requirement is the most difficult. Short of embedding Doctor Evil’s sharks with laser beams on their heads in every display device, pictures are going to happen. The solution is to make the picture of the message meaningless.

To make a screen shot meaningless, one must separate the complete message into the address element (to/from) and the content element (subject/body), and never allow the two elements to be displayed at the same place at the same time. Be careful not to include identifying data (your signature, for example) in the content. A picture of the address element shows only that a message went from A to B. A screen shot of the content may be interesting, but is unattributable without the address element – it’s hearsay.

A misappropriated picture of a message that reads, “Earnings are going to exceed Street estimates by $0.12” is not terribly actionable by an arbitrageur. However, if I’m a board member who read on the previous screen that the message was from the CEO of a major financial institution the message is wonderful news.

It is possible for a violator to take a picture of both parts of the VaporStream and reconstruct it to show a somewhat reassembled VaporStream.  I’ve also had folks point out a determined thief could film the screen sequence of downloading the header (to/from), clicking on it, and revealing the body (subject and content).  The problem with these scenarios is the believability of the violator constructed artifact.

Wouldn’t it just be easier for the thief to Photoshop whatever message he wanted?

For some reason we’ve come to believe a forwarded e-mail (or a piece of paper with an e-mail printed on it) is truth, even though we all know modifying an e-mail is a trivial task.  I’d suggest a composite reconstructing a VaporStream message would not carry that same credibility.

There is, for example, a body of legal precedent making e-mail, called Electronically Stored Information, admissible evidence. It’s hard to imagine reconstructed VaporStreams getting the same legal deference.

If you combine these three techniques, you’ll have recordless messaging and will have restored privacy to written electronic communications. Only once privacy has been restored can we continue to leverage the network and the asynchronous nature of electronic communications that we’ve come to rely on. Only a single copy of the message will ever exist. It will move in two parts, encrypted over the public network, from the author to the recipient. As each screen on the author’s display is overwritten, the message element will disappear. The address element will get pushed to the recipient’s viewer. When the recipient pulls the content element to the viewer, the address will be overwritten and the content will be displayed. When the content window is overwritten by the recipient’s next action, the content will be gone – forever.

Traditional modes of communication – e-mail, text, IM, even Twitter – fall short in the privacy arena. You have a right to private electronic conversations. Take back your right to privacy with recordless communications.

* * *

Jack Hembrough, CEO of VaporStream, is a highly regarded technology veteran with nearly 20 years experience in security-related technology. He has held leadership positions with Application Security, Authentica, IRE SafeNet, and Raptor Systems. In 2010, VaporStream was named to Gartner’s prestigious “Cool Vendors in Healthcare Providers” list. It is an inherently secure recordless messaging service that eliminates damaging information compromises and regulatory compliance infractions because its messages are never recorded.