I'll gladly disclose the systems - I want to be be as transparent as
possible, as I feel that was one of the major faults of tormail was
the lack of transparency which led to it's downfall, as we saw when we
realized that it was brought down as it was all completely hosted on
one sole source, Freedom Hosting.

That will be the fail safe - this project isn't solely hosted.  The
plan is once the proof of concept, by that once I make sure that my
code works and the team works and and users are pleased with the
service and people are happy with the transparency, and we're
providing a valuable service to ensure the ability for others to have
freedom of expression, freely, especially from areas where it's
restricted, without fear of reprisal or fear of someone providing
their information to a governmental source, which hopefully there will
be enough volunteers to ensure that these services are adequately

At this point though the backup location isn't ready for for complete
configuration - I only have the certificates for the VPN between the
two sites configured and I'm still working on the the failsafe code
basically, honestly, it's not security through obscurity, it's just
the need to complete the actual code to ensure that physical site A is
taken offline, then physical site B will come online with the same
hash hostname.

So basically, the final design will be as follows, mtas will deliver
be configured to deliver to both all of the data servers (we will
start off with at least two sites), but only one data server will be
the primary data server at a time.  That primary data server will
mount the other ones remotely via a vpn connection and have the db
constantly written to the secondaries.  If the primary goes doe down,
one of the secondaries will take over.  If for some reason, the
hostname is considered "compromised" (such as a primary server being
seized by a governmental organization and replaced), the hostname of
the next secondary will start being used.  Such a change will be
propagated via Social Media and other means.  But any way, the nice
ascii graph.

Internet---------MTAs---------Primary Data Server---------tor users
                  |                  |
                  |                  |
                  |                  |
                  |                  |
                  |                  |
                tor users

There's some already coded solutions that I'm looking into that I just
want to make sure work with tor hidden services.  There's also some
solutions that people smarter than me on this list probably know about
that hopefully may share with me.

The way the service is set up will be documented.  The other team
member and I will be actively documenting everything and ensuring that
we have everything documented and again, as transparent as possible.
For this little project I hope plenty of people volunteer, plenty of
people participate in a open provide feedback and ideas because you
know what, I might have ideas, I might have solutions, but I'm sure
someone might have something better.

Thanks for your feedback!

- --Rock

