Live data from Hacker News

Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

ezing.de

11–20 of 35 posts

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#12
post #2

I wish the site had a contact address for feedback or an announcement list. It looks like a good idea; I'm looking for more information. Digging for the Kickstarter to look for more information there...

my contact-address is info@ezing.de Thanks for all your feedback. You are absolutely right. The app should be open-source to give everyone the possibility to check every part of the security-relevant codes.

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#14
post #7
post #6

Earlier quoted context omitted.

That doesn't mean developing secure asynchronous messaging apps for smart device platforms is a bad idea (although adopting PGP over libaxolotl seems a tad foolish these days), it only means people should understand their threat model. If your threat model includes an adversary capable of taking over a cell tower or using IMSI catcher, then use a device with no baseband, like a simple tablet.

This is an important conversation people should have when discussing security. The dream is perfect security and trust - something that no singular person could ever have completely, because it basically requires a ton of things to happen: * You need to audit the blueprints for all hardware. * You need to verify, physically, the products of manufacturing - the physical hardware you will use - often requiring you to k…

Zanny, I disagree with your use of the "nothing is completely secure" truism as an argument against "storing private keys inside cellphones is not a good idea".

The local police department has ISMI catchers.

I estimate they won't have the ability to extract a file via the baseband until something like eZing becomes ubiquitous.

At that point, automated private key extraction will just become another feature of the ISMI catchers.

All of this is tangential to the real problem: basebands. Both in cell phones and cable modems. Time to take 'em back. You wouldn't allow OTA updates of your router or PC... Now would you?

I'll anticipate one response: "But, giving consumers control of their PHYs would be hell for the cellular/cable operators!" Well, after a few years, their/our networks (and devices) will be more secure.

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#15
post #7

Earlier quoted context omitted.

This is an important conversation people should have when discussing security. The dream is perfect security and trust - something that no singular person could ever have completely, because it basically requires a ton of things to happen: * You need to audit the blueprints for all hardware. * You need to verify, physically, the products of manufacturing - the physical hardware you will use - often requiring you to k…

Zanny, I disagree with your use of the "nothing is completely secure" truism as an argument against "storing private keys inside cellphones is not a good idea". The local police department has ISMI catchers. I estimate they won't have the ability to extract a file via the baseband until something like eZing becomes ubiquitous. At that point, automated private key extraction will just become another feature of the ISM…

> You wouldn't allow OTA updates of your router or PC... Now would you?

Have you booted an internet-connected Windows 7/8 machine recently? "Here, have Windows 10, with all the privacy features built in to it switched off! (In fact we're already downloading ot for ypu even before you agree to install it, so it'll be ready as soon as you agree, isn't that _convenient?_)"

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#17

"It will not be open-source" Pass.

"... but available in full for a review."

I don't know what this means? A snapshot (i.e. not an updated repository) available to anyone who asks for it?

I don't understand how it could meaningfully be "available in full" without it being equivalent and easier to just open source it.

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#18
post #12
post #2

I wish the site had a contact address for feedback or an announcement list. It looks like a good idea; I'm looking for more information. Digging for the Kickstarter to look for more information there...

my contact-address is info@ezing.de Thanks for all your feedback. You are absolutely right. The app should be open-source to give everyone the possibility to check every part of the security-relevant codes.

    > The app should be open-source
and yet your website says:

    > It will not be open-source
what's going on? :)

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#19
post #16

If anyone wants to help do this on desktop, some folks have been building PGP support into a Nylas N1 plugin! https://github.com/nylas/N1/issues/96 (I work at Nylas.)

Which doesn’t help anyone, considering how you continue to refuse to accept pull requests implementing auth solutions, and refuse to provide one in the open source version.

Any hosted service is inacceptable by default for security-conscious users (metadata...), and your product is barely acceptable for selfhosting. Which requires to fork.

Re: Show HN: EZing – Mobile email client that looks like Messenger and uses PGP

#20
post #15

Earlier quoted context omitted.

Zanny, I disagree with your use of the "nothing is completely secure" truism as an argument against "storing private keys inside cellphones is not a good idea". The local police department has ISMI catchers. I estimate they won't have the ability to extract a file via the baseband until something like eZing becomes ubiquitous. At that point, automated private key extraction will just become another feature of the ISM…

> You wouldn't allow OTA updates of your router or PC... Now would you? Have you booted an internet-connected Windows 7/8 machine recently? "Here, have Windows 10, with all the privacy features built in to it switched off! (In fact we're already downloading ot for ypu even before you agree to install it, so it'll be ready as soon as you agree, isn't that _convenient?_)"

No, I have not. :) Well, the Windows 7 machine under my desk at work is managed by the IT dept.
Post reply on HN