Live data from Hacker News

Gmail Will Warn If Message Is Not Authenticated/Encrypted

gmailblog.blogspot.com

91–100 of 216 posts

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#91
post #70

Earlier quoted context omitted.

More worrisome, "Your message has been added to your permanent record at wholesale data storage and may be used against you, in perpetuity, by current and/or future regimes, partner corporations and other select criminal organizations (tax-funded or independent) for reasons including but not limited to financial or political gain, manipulation, incrimination, assassination and personal entertainment."

Which is different from any other email provider in any substantial way (including your local ISP or personal server) because... they have a reasonable hope for reliable storage? Seriously: this is calling out Google in a way that's comical since it's equally applicable to your own computer.

Well, no, it really isn't. None of that really occurs on a personal server, and local ISPs probably don't do wholesale data storage because that's not their business, but it is Google's.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#92
I wonder how long it will be before Google fully cuts Gmail off from the outside world, much like how they turned gchat from a member of the federated xmpp/jabber ecosystem into hangouts and cut it off from the everyone else.

I guess if nothing else, it would probably reduce spam!

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#94
post #67

Earlier quoted context omitted.

+1 for fastmail. I've been using them for the past few years to host my 'other' main e-mail (the one I've had since 1994) and it's been a delight.

+1 for fastmail, here, too. Amazing service, really good communication during rare downtime, contributes heavily to open-source/community, decent prices, can heavily customize filters/etc, and as far as I'm aware, probably the most mainstream email provider that won't give into the NSA.

I'm sure that Australian Federal Police and Victoria law enforcement would be able to exercise search warrants on Fastmail's servers if they needed to.

Since you're in Tennessee (and thus a U.S. Person), you're actually ineligible for collection under FAA 702. Gmail/Hotmail/Yahoo, etc. would actually be the safest place for your information.

Of course that assumes that you believe the NSA follows U.S. law. If you don't have that assumption, that also implies that the NSA wouldn't respect Australian sovereignty enough to keep it from infiltrating Fastmail's servers.

I'm saying this to illustrate that there's no silver bullet for secure transmission and storage of information.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#95
post #85

Earlier quoted context omitted.

> The use of unencrypted or encrypted link to the receiving email provider's MX server doesn't change all that much in terms of who can read the email: it's still sitting in plaintext on the recipient's server (as well as the sender's server), and the group of actors who can sniff traffic on the backbone like that is probably just as easily able to get it from the servers. That's not at all obvious to me. And this so…

A state actor who can sniff traffic can just as easily serve a secret order to the email server operator to compel them to hand over the data. In fact this is already SOP for governments when dealing with communications which are encrypted in-flight but not end-to-end.

depends where those servers are based and who owns them

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#96
post #81

Earlier quoted context omitted.

Now I can just get a free cert and turn on TLS. What's the problem, exactly? Most people are not capable of running their own mail server. The convenience of services like Google, plus the risk of turning your mail box into a spam machine, vastly outweighs the downsides for most people.

> What's the problem, exactly? > Most people are not capable of running their own mail server. I think that is a big part of the problem. It should be relatively straightforward for someone who isn't a full-time email server administrator to setup a mail server correctly, but it's not. At least, it wasn't easy last time I tried it with Postfix and (iirc) Courier on Ubuntu. All the cryptography options are disabled by…

If it helps, I recently rebuilt my mail server and changed from FreeBSD+qmail+Courier to Ubuntu+Postfix+Dovecot. In doing so, I used this series from Ars Technica:

http://arstechnica.com/information-technology/2014/02/how-to...

It shows how to set up SPF, DKIM, TLS, anti-spam filtering, Sieve, certificate-based authentication (I still haven't figured out how to do this with an iPhone), and so on. The only bolt-on it references but doesn't explore and I actually used is the Z-Push package to implement ActiveSync.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#98

Earlier quoted context omitted.

Which is different from any other email provider in any substantial way (including your local ISP or personal server) because... they have a reasonable hope for reliable storage? Seriously: this is calling out Google in a way that's comical since it's equally applicable to your own computer.

Well, no, it really isn't. None of that really occurs on a personal server, and local ISPs probably don't do wholesale data storage because that's not their business, but it is Google's.

Well, you have no reliable way to assert your personal mail server is not bugged and observed right now.

You're one judge's pen-stroke away from having personal property seized and then it's just a matter of how real your machine's physical security measures are.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#99
post #80

Earlier quoted context omitted.

These aren't requirements. Gmail is a mail client. What it is doing is adding warnings. Without SPF/DKIM you can't be authenticated. Google is showing the user that they cannot verify the sender. Without TLS email is sent in the clear. Google is showing the user that sensitive information will be visible when sent over the network. You can run your server fine without this, but users will be warned that you're not fo…

> These aren't requirements Well, except they are. Before, yes, they were just best practices. It was great if you had them but by no means required and didn't really impact your experience much if at all. With this switch, though, they became requirements to getting a "normal" experience in Gmail. Even having a warning is a degraded experience at this point.

I'd actually consider that an improved experience. Sure, the sender using the improperly created personal mailbox will be inconvenienced if people ask about it. However, the actual user of gmail benefits from this.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#100

Earlier quoted context omitted.

Well, no, it really isn't. None of that really occurs on a personal server, and local ISPs probably don't do wholesale data storage because that's not their business, but it is Google's.

Well, you have no reliable way to assert your personal mail server is not bugged and observed right now. You're one judge's pen-stroke away from having personal property seized and then it's just a matter of how real your machine's physical security measures are.

You have no reason to suspect it either. Yes, in this hypothetical scenario your mail server or your ISP's server might be compromised, and yes, in this scenario, there wouldn't be a big difference. But we don't live in hypothetical scenarios. Paranoia is great and all, but let's be real. An average Joe's personal mail server is more than likely not bugged nor observed, and if communication happens in TLS, then there'd be no reason to suspect the delivery either.

We all know Google is doing it, though.

Post reply on HN