Live data from Hacker News

Gmail Will Warn If Message Is Not Authenticated/Encrypted

gmailblog.blogspot.com

171–180 of 216 posts

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#171
post #67

Earlier quoted context omitted.

+1 for fastmail, here, too. Amazing service, really good communication during rare downtime, contributes heavily to open-source/community, decent prices, can heavily customize filters/etc, and as far as I'm aware, probably the most mainstream email provider that won't give into the NSA.

I like Fastmail (paying customer here) but let's not kid ourselves that they are anymore safe from the NSA or the Five Eyes. That's wishful thinking and is the same argument as if you host your email in Switzerland, it's magically untouchable from mass surveillance.

Checkout Riseup from my above comment. They release warrant canaries regularly.

PS: I'm not related to Riseup.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#172

Earlier quoted context omitted.

Yes. I periodically test with various recipients and mail goes through without a hitch. The only difference I might have versus people starting out fresh is that the domains I host are relatively aged. The newest is two years old and the oldest is nineteen. I also made sure that DNS is set up properly, both forward and reverse, and especially for IPv6.

maybe my sin is hosting at linode - for a new recipient at either of the behemoths, I seem to have 50% chance of going to spam. Thanks for your comment.

I host with linode, and have had generally good results sending mail to gmail. They're definitely not the worst. Granted, I have had SPF enabled for about 10 years.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#173
post #129

Earlier quoted context omitted.

Long before Let's Encrypt, SMTP transactions with STARTTLS have permitted self-signed and non-root-CA chained certificates. The pervasiveness of self-signed certificates for SMTP servers means that rejecting them would drop large amounts of email. STARTTLS is basically useful for thwarting passive collection of network traffic.

Gmail's new rules on unencrypted e-mail don't support self-signed certificates though - you have to use an offcial CA-issued certificate from one of Google's approved CAs.

I'm not so sure about that; I use a self-signed cert for port 25 TLS, and I just sent from google to my domain, and didn't see a warning.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#174

This sounds great but Google has been making it harder and harder to run your own mail server even for personal use. I think they would be happy of email servers were only run by a few large companies. They make it sound like they are doing the right thing but really they are bully the industry to do it their way. So many people have Gmail accounts that you can't run an email server that cannot send email to Google.…

I disagree - I run a personal mail server and dkim+spf just took a little bit of research to set up, so I'm very glad this brought them to my attention because I want to do what I can to make my emails trustworthy.

If there are any potential downsides to these things I'm interested to hear them, but it seems like they're generally agreed good practices, and hosting your own mail means you're signing up for some ongoing learning and maintenance anyway.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#175
I'll tell you what I want: I want Google to help identify non-DKIM-compliant forwarders. As the operator of (yes, I know) a vanity e-mail domain with DKIM, SPF, and DMARC records, I have no problem sending mail to gmail directly; in fact, my outgoing mail uses postmark, so I'm not even directly responsible for my sending reputation.

BUT! It drives me crazy that many of my recipients get e-mail at hosts (schools, mostly) that forward the e-mail with differences (encoding changes, subject changes, etc.) that invalidate the DKIM signature. Since they're forwards, the SPF check is going to fail, too, so the end result is that google shoves it into a spam folder.

I claim that google definitely has the data to be able to identify these bad forwarders--heck, even mail sent from gmail to these hosts will presumably fail DKIM checks on the way back into google--and I'd love to see them contact these domains, or even publish a list of known bad forwarders, so that I can push them to make changes.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#176
post #81

Earlier quoted context omitted.

Now I can just get a free cert and turn on TLS. What's the problem, exactly? Most people are not capable of running their own mail server. The convenience of services like Google, plus the risk of turning your mail box into a spam machine, vastly outweighs the downsides for most people.

> What's the problem, exactly? > Most people are not capable of running their own mail server. I think that is a big part of the problem. It should be relatively straightforward for someone who isn't a full-time email server administrator to setup a mail server correctly, but it's not. At least, it wasn't easy last time I tried it with Postfix and (iirc) Courier on Ubuntu. All the cryptography options are disabled by…

If you make hard things easy to do, then people that don't know what they are doing will do it (poorly). They'll set up a server once, and never maintain or update it and it'll eventually be hacked and taken over by spammers. I set up and maintain our mail servers and work, and for my personal email, I chose to point my domain to Gmail to let Google take care of it, I don't want to expend the effort it takes to run my own mail server.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#177
How disappointing, when I read the headline I thought Google was supporting PGP signing and encryption of emails. They could easily do so in their web and mobile clients, keeping emails safe from prying eyes.

Though that would also prevent analysis of emails for ad targeting, so they'd have to do it as some sort of paid project.

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#178

This sounds great but Google has been making it harder and harder to run your own mail server even for personal use. I think they would be happy of email servers were only run by a few large companies. They make it sound like they are doing the right thing but really they are bully the industry to do it their way. So many people have Gmail accounts that you can't run an email server that cannot send email to Google.…

Maybe I'm in an odd position, but is email really such a big communication tool? I mean sure in business world, but for that companies have their own email servers anyway. I only receive email from 2FA-things and order confirmations/paypal recipes. I hardly ever actually send anything from Gmail or receive anything from actual people. All my communication with actual people is either through apps like Signal or WhatsApp or through IM like IRC

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#179
post #151
post #83

Earlier quoted context omitted.

My first concern is, if nowadays is so easy to get your certs signed by a CA how can "Authenticated/Encrypted" emails successfully prevent phishing attacks? In my modest opinion there are many week points in X.509 and how CAs are verifying identities, and even if this things were fixed you still have the problem of state-sponsored attacks that have no solution within the current www pki. I personally have no problem…

The use of TLS (which is what uses a CA-issued certificate) isn't to prevent phishing attacks, it's to prevent emails being read or modified in transit. DKIM (which does not use a CA-issued certificate, it uses a public key published in DNS) is the technology that's intended to authenticate the email sender. It still wouldn't stop phishing attacks where the purported email sender is something like "admin@facebook-acc…

> to prevent emails being read or modified in transit

Except everything you send and receive with your Gmail account is read by them and whatever government agencies anyway... So what's the point?

Re: Gmail Will Warn If Message Is Not Authenticated/Encrypted

#180

Earlier quoted context omitted.

To play devil's advocate, why is email shit? It is pretty much a way to send someone a document in the original way Berners Lee defined html which was essentially sgml. I get not letting people mail active scripts, but every large mail provider also makes a browser. So email is shitty because providers fuck with it at the mailserver level (i think this is the case, and have heard that about providers) as it doesn't s…

Email is also far less instantaneous and is locked into a single kind of infrastructure. It's useful for only one thing. I don't think it needs to be changed, really. It will stay this useful forever, probably.

"locked into a single kind of infrastructure"

What does that mean? A mail server can be a small perl script running on an embedded computer, or it can be a hundred front-end SMTP servers using a database as a back end datastore, there's no real infrastructure limit other than being able to make and receive connections on TCP port 25.

Post reply on HN