Live data from Hacker News

Google has most of my email because it has all of yours (2014)

mako.cc

1–10 of 56 posts

Re: Google has most of my email because it has all of yours (2014)

#3
post #2

It is unfortunate that encryption systems for email never really found widespread use.

Most systems never found a good way to encrypt data at rest.

You either have to let the user manage the keys / passphrase, giving up things like search and password recovery, or you have to manage the keys in a service, which doesn't provide privacy from the service that manages the keys.

Re: Google has most of my email because it has all of yours (2014)

#4
post #3
post #2

It is unfortunate that encryption systems for email never really found widespread use.

Most systems never found a good way to encrypt data at rest. You either have to let the user manage the keys / passphrase, giving up things like search and password recovery, or you have to manage the keys in a service, which doesn't provide privacy from the service that manages the keys.

Spam is also a problem. How do you do spam detection if you cannot read the message?

Re: Google has most of my email because it has all of yours (2014)

#5
post #2

It is unfortunate that encryption systems for email never really found widespread use.

As mentioned by other posters, it opposes convenience too much. I say it's unfortunate that SMTP/IMAP was not made easy/free enough to self-host. I understand cost, uptime, and admin challenges, I am just saying these communication mechanisms will continue to be centralized while there is financial incentive to make them better and appeal to the masses.

Re: Google has most of my email because it has all of yours (2014)

#6
post #4
post #3

Earlier quoted context omitted.

Most systems never found a good way to encrypt data at rest. You either have to let the user manage the keys / passphrase, giving up things like search and password recovery, or you have to manage the keys in a service, which doesn't provide privacy from the service that manages the keys.

Spam is also a problem. How do you do spam detection if you cannot read the message?

A few years (almost two decades!!!) when the filters weren't as good I read a proposal to make an email system that charges $0.01 to the sender. Spammers would be bankrupt.

It was difficult to implement and up against an already entrenched tech.

With Bitcoin I've been thinking of that idea again. Could a payment system on top of existing email be created? The receiver of the email could get the senders penny and Bitcoin might get a killer app that doesn't involve drugs...

Re: Google has most of my email because it has all of yours (2014)

#7
post #2

It is unfortunate that encryption systems for email never really found widespread use.

It's all about ease of use. https is probably the only user-friendly / good UX crypto solution in common/widespread use (unless you count transparent drive encryption), and it achieves this in part by being centrally controlled via registrars to eliminate the need for the user to understand PKI. This in turn makes it kind of a joke from a crypto-snob POV, though it's good enough for most routine stuff.

Even MacGPG plugins for Mac Mail.app are really hard to install, manage, and use, and require a level of expertise and knowledge of how PGP/GPG works that makes them off limits for non-technical users.

Re: Google has most of my email because it has all of yours (2014)

#8
post #4
post #3

Earlier quoted context omitted.

Most systems never found a good way to encrypt data at rest. You either have to let the user manage the keys / passphrase, giving up things like search and password recovery, or you have to manage the keys in a service, which doesn't provide privacy from the service that manages the keys.

Spam is also a problem. How do you do spam detection if you cannot read the message?

If you have the public keys of all senders, one can easily white/black list the known known/non-spammers. All the undecided goes into just one folder.

Probably not be that hard to sort out.

Re: Google has most of my email because it has all of yours (2014)

#9
post #7
post #2

It is unfortunate that encryption systems for email never really found widespread use.

It's all about ease of use. https is probably the only user-friendly / good UX crypto solution in common/widespread use (unless you count transparent drive encryption), and it achieves this in part by being centrally controlled via registrars to eliminate the need for the user to understand PKI. This in turn makes it kind of a joke from a crypto-snob POV, though it's good enough for most routine stuff. Even MacGPG pl…

OTR is great if all endpoints have the same software clients (e.g. client-side IM). Doesn't necessarily work so great if your clients are all "in the cloud" though.

Re: Google has most of my email because it has all of yours (2014)

#10
post #6
post #4

Earlier quoted context omitted.

Spam is also a problem. How do you do spam detection if you cannot read the message?

A few years (almost two decades!!!) when the filters weren't as good I read a proposal to make an email system that charges $0.01 to the sender. Spammers would be bankrupt. It was difficult to implement and up against an already entrenched tech. With Bitcoin I've been thinking of that idea again. Could a payment system on top of existing email be created? The receiver of the email could get the senders penny and Bitc…

It could be even more convenient, if it only charged for unauthorized contacts. Emails back and forth between friends/coworkers? No charge. Email newsletter you signed up for? One-time cost to them to send you the opt-in message. Random spammers? Never get authorized; have to pay every time.

It would also put a slight amount of friction in place for contacting people out-of-the-blue (when e.g. sending fan-mail to famous people)—but the fact that some stranger paid $0.05 to say something to you could also make you just fractionally more interested in what they have to say.

On the other hand, for accepting bug reports, help tickets, etc., there'd have to be some kind of email equivalent to an "800 number", that is free to initiate contact with. Either that, or a lot of behind-the-scenes pairing magic to get your email address into the directory service of all the products and services you use.

Post reply on HN