Live data from Hacker News

Gmail Will Warn If Message Is Not Authenticated/Encrypted

gmailblog.blogspot.com

51–60 of 216 posts

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#51
post #2

I have mixed feelings about this. > Not all affected email will necessarily be dangerous. To me, it sounds like they're saying that most of the "affected email" WILL be dangerous -- just not ALL of it -- and that's highly misleading, of course. Overall, though, I think this will be a good thing if it pushes more organizations ("mail senders") to implement opportunistic encryption for incoming mail and SPF/DKIM signin…

This will be popcorn time for those using Gmail for business.

I have a plugin in Thunderbird that shows the DKIM status of incoming email as gray/red/green, meaning no DKIM/DKIM invalid/DKIM valid. Most of the email I get from business accounts (usually on Exchange), including those from the company I work at, have no DKIM. (Yes, I've complained to the ITsec dept. They don't even have SPF set up...) Of the rest, surprisingly many have invalid DKIM sigs.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#52

Earlier quoted context omitted.

>I doubt that there is a way to build a webmailer without processing the emails content at some point. It is disingenuous and/or ignorant to suggest that temporarily loading an email into memory for the purpose of displaying it on the users screen is the same as parsing and catagorising the text and storing the results of the analysis in a database for the purpose of manipulating the user.

How do you run an efficient server-side search without maintaining a parsed index? I have 40,000 emails in my inbox. You want this to be linearly scanned everytime?

Yeah, I really do, it'd be funny as hell. Jesus fuck man, clean your inbox.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#54

This sounds great but Google has been making it harder and harder to run your own mail server even for personal use. I think they would be happy of email servers were only run by a few large companies. They make it sound like they are doing the right thing but really they are bully the industry to do it their way. So many people have Gmail accounts that you can't run an email server that cannot send email to Google.…

Now I can just get a free cert and turn on TLS. What's the problem, exactly? Most people are not capable of running their own mail server. The convenience of services like Google, plus the risk of turning your mail box into a spam machine, vastly outweighs the downsides for most people.

>Now I can just get a free cert and turn on TLS. What's the problem, exactly?

Certs weren't free for business use until let's encrypt.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#55
post #26
post #8

Other mailers should warn about Gmail, with "Your message was scanned for advertising purposes".

What about "Your message was categorized fir Bayesian spam filtering and may have contributed to eventual upstream rules" for all those installations that historically ran SpamAssassin? If you're using Gmail or sending to a gmail address[1], you know what you are in for, and if you don't you should at least know that anything you send to someone else is no longer in your control and you have very little control over…

What alternatives do you suggest, besides running your own mail server? I'm in the invite list for Protonmail and have also used the infamous cock.li for informal stuff, but I was looking for something a bit more established, that I can count on long term stability. It's bad enough to switch email addresses once, to be switching every time a service goes kaput is unacceptable.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#56
post #54

Earlier quoted context omitted.

Now I can just get a free cert and turn on TLS. What's the problem, exactly? Most people are not capable of running their own mail server. The convenience of services like Google, plus the risk of turning your mail box into a spam machine, vastly outweighs the downsides for most people.

>Now I can just get a free cert and turn on TLS. What's the problem, exactly? Certs weren't free for business use until let's encrypt.

That's kind of the point. They weren't but now are, and now there's even less of an excuse not to have a cert.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#57

Earlier quoted context omitted.

>I doubt that there is a way to build a webmailer without processing the emails content at some point. It is disingenuous and/or ignorant to suggest that temporarily loading an email into memory for the purpose of displaying it on the users screen is the same as parsing and catagorising the text and storing the results of the analysis in a database for the purpose of manipulating the user.

How do you run an efficient server-side search without maintaining a parsed index? I have 40,000 emails in my inbox. You want this to be linearly scanned everytime?

Indexing for search != parsing for advertisement.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#58

There are really good, albeit few, alternatives: Fastmail ( https://www.fastmail.com/ ) Tutanota ( https://tutanota.com/ ) Riseup ( https://help.riseup.net/ )

+1 for fastmail. I've been using them for the past few years to host my 'other' main e-mail (the one I've had since 1994) and it's been a delight.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#59
post #7

Earlier quoted context omitted.

And by ideally placed, you mean for the NSA, right? I'd never put any GPG keys of mine in an American cloud provider. That sort of voids the entire point of it.

More importantly, end-to-end encryption means that your desktop/laptop/tablet/phone/TI-83 is doing the crypto, especially signatures. On a somewhat related note, I remember reading some documentation on a one-time password scheme, which I can't find anymore. It briefly mentioned something about using DES calculators to handle crypto signatures (for what reason i cannot remember). For our purposes, a PGP/GPG hand-held…

> phone/TI-83 is doing the crypto

Phone? Can we remotely trust nowadays smartphones not to have a number of backdoors?

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#60
post #19

In my opinion, you should just behave like your emails are public record. This is the best way of approaching that technology.

That's what I do as email is more akin to a postcard than a letter. If that makes someone uncomfortable, then they should choose another medium.

> they should choose another medium

Which kind of medium do you have in mind? If you want a federated communication medium in wide use that doesn't require you to use proprietary software or a centralized server, there isn't much choice. This is why I'd say it's a worthwhile endeavor to make it possible to communicate securely and privately with email.

Post reply on HN