MyEmail ads: Try harder Idris, I'm not convinced
I refer to Idris Jala's attempt to quash controversy surrounding the MyEmail project. He has attempted to explain justification based on the savings angle. One important aspect that most observers have not looked at is simply functionality. The basic requirements are:
The basic requirements are:
- The solution shall provide an alternative secure channel to communicate sensitve personal information to the ordinary public.
- The solution shall reduce the intermediaries government agencies use to make the communication channels in the hope of reducing costs.
- The solution should be easy to use.
Senator Jala has gone to great pains to explain unconvincingly how the solution satisfies requirement 2.
In total it costs RM0.50 for the administration and RM0.50 for the physical postal stamp currently. Taking away the physical postal stamp costs in an email solution, we are still left with RM0.50 for administration costs. But Tricubes wants to charge RM0.50 for the electronic 'stamp'. It boggles the mind.
And I beg to differ that the solution addresses requirements 1 and 3 properly.
To fulfill Req 1, the MyEmail is the worst possible solution. Most people nowadays use web-based enail systems like Gmail. They don't use the traditional client-server model emails where you download emails from a server to a client.
The client-server model is inherrently insecure. You either use IMAP or POP3 to retrieve the mails, both of which by default are unencrypted.
POP3 even sends passwords in clear text. Once the mails are downloaded on to a user's PC, it runs the risk of being snooped upon by unauthorised users, and being destroyed due to various technical failures and malware attacks.
The complication of setting up the client and maintaining it dissatisfies Req 3. The inherent insecurity of the Internet email dissatisfies Req 1.
So, to be practical and accessible to most people, MyEmail would most likely need to be a web-based email system, like Gmail. A web-based email will also satisfy Req 1, since the communications between the server and the web browser can be end-to-end encrypted (https).
But what the heck? If we have to get into a website to access the mail, then why not just have the agency provide the web service (for example pdrm.gov.my/saman. I just login to query my summons)?
The only logical justification for MyEmail is that the stuff in the inbox of MyEmail is considered certified legal. That is, I can produce a printout of the MyEmail email tax receipt to my bank, court and they must accept it as true.
But, how can one ensure that the printout is authentic? The other way is that I forward that tax receipt to my bank/lawyer and since it comes from xxx@myemail.my.
Oh, and what about phishing? I keep getting phished emails from what appears to be my friends inviting me to help some rich dead Nigerian retrieve "US$14,000,000 (FoURTEEN MILLIOn AMERICAN DOLLAR only)". So, most likely some nervous makcik, might also be getting a phished mail from my xxx@myemail.my notifying some lonely Russian ladies need a date ... desperately!
So, on a technical level, I am not convinced how MyEmail can satisfy the important Req 1 & 3. HSBC sends me electronic bank statements to my private email address, and it works (it is encrypted). They of all people, should be concerned with utmost data security so if they can send to my private email address, why can't the government do the same?
There are proven secure ways to digitally sign and encrypt messages via insecure channels like emails. It is called the public key encryption cryptography and infrastructure.
With a digitally signed email, one can read the mail, and verify it against a recognised public encryption key for authenticity. You can send it through any normal email system. Unfortunately, it is not the easiest concept to grasp for most people.
There was talk about a key certificate authority for Malaysia to keep these keys during the multimedia heydays, and how our IC's would have these digital keys that we can use to authenticate ourselves. What happened to that?
Tricubes should by now have a proper white paper to explain how technically their solution is secure and why the government cannot simply do business using normal email. And I can forsee that one day government agencies are not going to email us, unless it we have a xxx@myemail.my. It is just not practical.
From here on, there's only one line in Idris’s explanation dealing with Req 1 (and none on Req 3). Tricubes claims that the email is secure because a "MyKad-based authentication service layer ... ensures correct recipients".
It implies you need to have a MyKad reader to access the mail securely ... and it also means a stolen MyKad can be used to access the email. Isn't that more complicated? So, instead of these vague fluffy statements, Tricubes must come up with something more convincing. I'd really like to hear the FUD (Fear, Uncertainty and Doubt) stories they have used to sell this idea to the government .
Unless Tricubes can give a convincing technical explanation to fulfill Req 1 and 3, I have to assume that there is nothing to address Req 1, that isn't already available freely. If it means needing a dongle/hardware, it will fail as it breaks Req 3.
Where are the case studies for this? Come clean and be scrutinised by the technical community. There's no politics involved.
Since this email is as Jala says, voluntary, I will not volunteer to sign up for pure technical reasons.
But with adopting Tricubes solution, we will then have a problem in that we still need to maintain the old system (for those without internet access) AND pay for a new unconvincing system.
Everybody knows running two systems to do the same job is wasteful to say the least. I am for modernising interaction with the government, but this doesn't seem the right way to go, and it doesn't feel like a solution. If it was, Singapore, Korea or Israel would have implemented it!
Congratulations to Tricubes though for this RM50M windfall. Bill Gates never had it so good.

