Live data from Hacker News

Gmail Will Warn If Message Is Not Authenticated/Encrypted

gmailblog.blogspot.com

61–70 of 216 posts

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#61
post #43

Its great that Google wants all the lines carrying data from their servers to be secure and tamper proof. It would be interesting to see if they ever support end to end encryption which would lock them out of scanning the data as well.

Then how would searching your mail work? That breaks the product on a fundamental level and makes it worse than all competing products for all but a few users with specific needs. The existing end-to-end browser extension is a reasonable compromise.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#62
This is interesting but as pointed out by other comments there is great danger of Gmail abusing their position to make life harder for small email providers.

I would be more positive towards this if they gave precise, technical details of their notion of "supporting TLS" and "being authenticated", ideally with a service allowing me to test easily whether my mail server is fine according to them (rather than having to sign up for Gmail to test it).

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#63
post #54

Earlier quoted context omitted.

>Now I can just get a free cert and turn on TLS. What's the problem, exactly? Certs weren't free for business use until let's encrypt.

That's kind of the point. They weren't but now are, and now there's even less of an excuse not to have a cert.

Is it possible to get a Let's Encrypt certificate without a public facing website (which is unrelated to wanted to run a mail server)?

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#64
Unfortunately, this is the sort of a change that's a red herring for any actual improvements to email security.

The use of unencrypted or encrypted link to the receiving email provider's MX server doesn't change all that much in terms of who can read the email: it's still sitting in plaintext on the recipient's server (as well as the sender's server), and the group of actors who can sniff traffic on the backbone like that is probably just as easily able to get it from the servers.

The authentication feature is even worse. The problem of spam and phishing isn't that email claims to be from important-service@bigbank.com, it's that email claims to be from "Big Bank" . It's been noted before that spammers tend to be the most aggressive at uptaking new "anti-spam" technologies like SPF and DKIM, and this sort of validation feature seems like a prime vehicle for exploitation by spammers.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#65
post #63

Earlier quoted context omitted.

That's kind of the point. They weren't but now are, and now there's even less of an excuse not to have a cert.

Is it possible to get a Let's Encrypt certificate without a public facing website (which is unrelated to wanted to run a mail server)?

Yes, they recently enabled the DNS validation. Otherwise, it wants to use a webserver to validate ownership. It can spin up an embedded webserver if you don't have one already.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#67

There are really good, albeit few, alternatives: Fastmail ( https://www.fastmail.com/ ) Tutanota ( https://tutanota.com/ ) Riseup ( https://help.riseup.net/ )

+1 for fastmail. I've been using them for the past few years to host my 'other' main e-mail (the one I've had since 1994) and it's been a delight.

+1 for fastmail, here, too. Amazing service, really good communication during rare downtime, contributes heavily to open-source/community, decent prices, can heavily customize filters/etc, and as far as I'm aware, probably the most mainstream email provider that won't give into the NSA.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#68

Earlier quoted context omitted.

Yep surprised they haven't rolled one out yet. Ideally placed.

> Yep surprised they haven't rolled one out yet. Ideally placed. In fact, they will fight tooth and nail against it since their business model relies on having access to the plain text of the message. It's the very reason they are releasing this technology: a user sees a padlock icon that's confusing similar to other "encrypted" mail offerings, for example OpenPGP. For Google, it's essential that end-to-end encryptio…

How would I search my encrypted inbox? Either Google knows my private key, in which case this doesn't seem to buy us anything, or I can't search.

I search a lot.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#69
post #54

Earlier quoted context omitted.

Now I can just get a free cert and turn on TLS. What's the problem, exactly? Most people are not capable of running their own mail server. The convenience of services like Google, plus the risk of turning your mail box into a spam machine, vastly outweighs the downsides for most people.

>Now I can just get a free cert and turn on TLS. What's the problem, exactly? Certs weren't free for business use until let's encrypt.

WoSign never seemed to care.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#70
post #8

Other mailers should warn about Gmail, with "Your message was scanned for advertising purposes".

More worrisome, "Your message has been added to your permanent record at wholesale data storage and may be used against you, in perpetuity, by current and/or future regimes, partner corporations and other select criminal organizations (tax-funded or independent) for reasons including but not limited to financial or political gain, manipulation, incrimination, assassination and personal entertainment."
Post reply on HN