Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

11–20 of 450 posts

Re: Encrypted email is still a pain

#11
I have "taught" encrypted email for many years to different types of people.

I'm surprised to see that most non-technical people that I assisted had a better understanding of these same tools than the author.

Generating the key using Enigmail has always worked for both Windows and Debian/Ubuntu (those are the top OSs people brought), finding a person's key was a pain a few years ago, I love the new UI.

My conclusion: The author probably had his mind set before even starting.

EDIT : Enigmail now allows you to enable encryption/signing by default, this prevents users from sending accidental clear-text emails.

Re: Encrypted email is still a pain

#12
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> * Hundreds of millions of users that primarily access messages through browser clients that can't meaningfully implement crypto.

Isn't protonmail pretty much a direct counter-example of this?

They even have an extension you can use if you don't want their server to be trusted at all: https://chrome.google.com/webstore/detail/protonmail-checker...

> * End user demands for things like search that can only be delivered efficiently at scale by databases of plaintext (most likely at centralized servers).

Thunderbird and Outlook at least seem to do search quite fast without any such thing. This could probably be done on something like protonmail by using an encrypted index too.

Re: Encrypted email is still a pain

#13
A secring is a "secret keyring" that contains a number of private keys. I agree that consistency of "secret" versus "private" would be helpful, but the concepts of a key and a keyring are distinct (and a reasonably effective metaphor IMO - you have a keyring which your keys are on). The extent to which the tools should push you towards having a single key versus rotating is arguable; people criticise GPG for being too hard to use but people (sometimes even the same people!) also attack it for not encouraging key rotation enough. A gitflow-esque helper for setting up a best-practice rotation would be a valuable thing for someone to make (and fundamentally there just isn't enough money in making these tools more usable, unfortunately, which is why I fear it will never happen).

GPG shouldn't need to tell you (prominently) where the files are because you should never need to know that - tools that integrate with GPG should be able to ask GPG where the keys are. The main thing that needs to happen here is for the Enigmail key generation bug to be fixed.

If you're looking for a good GUI mail experience with GPG integration I found KMail much nicer than Thunderbird/Enigmail, for what it's worth.

Re: Encrypted email is still a pain

#14
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> But: why bother? Email is just one of dozens of messaging systems available to Internet users.

No, it's not. It's the only widely available, decentralized system, with which you can send to anyone, if you know the address. None of the big ones is this open.

XMPP tried to address this and failed; now Matrix is trying again.

Re: Encrypted email is still a pain

#15
Your key is not importable :D

  $ gpg --import stanley.asc
  gpg: CRC error; C68D2A - 29357C
  gpg: read_block: read error: Invalid keyring
  gpg: import from `stanley.asc' failed: Invalid keyring
  gpg: Total number processed: 0
Edit: Your key is way too short.

Re: Encrypted email is still a pain

#16
Do any of these keyservers perform email verification? It would go a good way towards some kind of verification that a user's GPG key corresponds to their email. Otherwise, anyone can generate a key with any email address and push it up to the servers. The standard way of verifying it (key-signing parties) is somewhat difficult.

Re: Encrypted email is still a pain

#17
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> * Hundreds of millions of users that primarily access messages through browser clients that can't meaningfully implement crypto. Isn't protonmail pretty much a direct counter-example of this? They even have an extension you can use if you don't want their server to be trusted at all: https://chrome.google.com/webstore/detail/protonmail-checker... > * End user demands for things like search that can only be delivere…

No? Virtually nobody uses Protonmail. If the only thing between encrypted email and no encrypted email was a single provider that implemented PGP, we'd have had universal encrypted email in 1999.

(I'm stipulating that anything Protonmail does actually, you know, works. I have no idea if it does. Why bother? Encrypted email isn't going anywhere. The track record on things like this is quite bad.)

Re: Encrypted email is still a pain

#18
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

There is still very much a set of users in the incident response community that relies on PGP. These are professional teams that need to communicate with each other. They talk about upcoming disclosures, current abuse, upcoming operations or patches, et cetera.

This stuff is almost all short to mid-term secret. Most of this will become public in a month or so. Leaking meta-data is an assumed risk (or too much hassle to avoid, take your pick).

Re: Encrypted email is still a pain

#19
post #11

I have "taught" encrypted email for many years to different types of people. I'm surprised to see that most non-technical people that I assisted had a better understanding of these same tools than the author. Generating the key using Enigmail has always worked for both Windows and Debian/Ubuntu (those are the top OSs people brought), finding a person's key was a pain a few years ago, I love the new UI. My conclusion:…

The author probably exaggerates, but identifies a very valid point. You really don't want to have this kind of confusion about something that you are planning to trust your secrets to.

Re: Encrypted email is still a pain

#20
post #17

Earlier quoted context omitted.

> * Hundreds of millions of users that primarily access messages through browser clients that can't meaningfully implement crypto. Isn't protonmail pretty much a direct counter-example of this? They even have an extension you can use if you don't want their server to be trusted at all: https://chrome.google.com/webstore/detail/protonmail-checker... > * End user demands for things like search that can only be delivere…

No? Virtually nobody uses Protonmail. If the only thing between encrypted email and no encrypted email was a single provider that implemented PGP, we'd have had universal encrypted email in 1999. (I'm stipulating that anything Protonmail does actually, you know, works. I have no idea if it does. Why bother? Encrypted email isn't going anywhere. The track record on things like this is quite bad.)

So what, it's all or nothing for you? Even if there is an easy to use solution that you can set someone up with in about 10 minutes, that's absolutely valueless because it means that less than 100% of messages will use it?
Post reply on HN