Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

21–30 of 450 posts

Re: Encrypted email is still a pain

#21
post #3
post #2

https://gpgtools.org/ works great for Mac.

For technical folk, yeah. For nontechnical folk, nothing seems to come even close though. The great thing about HTTPS, for example, is all users need to care about is a little green lock. (And frequently, they have no idea what HTTPS is, but know that little green lock === safe)

HTTPS is easy because it only provides encryption in transit. It is analogous to opportunistic encryption of SMTP, which is already in widespread use.

Another reason HTTPS is easy is that it uses a centralized trust model, relying on CAs to vet each website.

GPG is neither. It tries to provide encryption at rest, and relies on a web of trust that we cannot reasonably expect everyone to operate securely.

Re: Encrypted email is still a pain

#22
post #14
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> But: why bother? Email is just one of dozens of messaging systems available to Internet users. No, it's not. It's the only widely available, decentralized system, with which you can send to anyone, if you know the address. None of the big ones is this open. XMPP tried to address this and failed; now Matrix is trying again.

WhatsApp has over a billion users. There are big places where its market share exceeds that of SMS --- another big centralized service that has a userbase comparable to that of email. My conclusion is that the people who care about "decentralized" systems are a rounding error. I care about non-technologists managing to send asynchronous messages to each other that are well-encrypted by default. That's a solved problem.

Re: Encrypted email is still a pain

#23
post #17

Earlier quoted context omitted.

No? Virtually nobody uses Protonmail. If the only thing between encrypted email and no encrypted email was a single provider that implemented PGP, we'd have had universal encrypted email in 1999. (I'm stipulating that anything Protonmail does actually, you know, works. I have no idea if it does. Why bother? Encrypted email isn't going anywhere. The track record on things like this is quite bad.)

So what, it's all or nothing for you? Even if there is an easy to use solution that you can set someone up with in about 10 minutes, that's absolutely valueless because it means that less than 100% of messages will use it?

What do you want to hear from me? Part of this is my own bias against email, but that's not all it is: I'm not making up the "emerging consensus" bit.

Re: Encrypted email is still a pain

#25
post #14
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> But: why bother? Email is just one of dozens of messaging systems available to Internet users. No, it's not. It's the only widely available, decentralized system, with which you can send to anyone, if you know the address. None of the big ones is this open. XMPP tried to address this and failed; now Matrix is trying again.

As a happy user of matrix (via riot.im), I sure hope matrix takes off!

Re: Encrypted email is still a pain

#26

Do any of these keyservers perform email verification? It would go a good way towards some kind of verification that a user's GPG key corresponds to their email. Otherwise, anyone can generate a key with any email address and push it up to the servers. The standard way of verifying it (key-signing parties) is somewhat difficult.

Only https://keyserver.pgp.com performs email verification, the others don't.

See: https://lkml.org/lkml/2016/8/15/445

Re: Encrypted email is still a pain

#27
post #18
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

There is still very much a set of users in the incident response community that relies on PGP. These are professional teams that need to communicate with each other. They talk about upcoming disclosures, current abuse, upcoming operations or patches, et cetera. This stuff is almost all short to mid-term secret. Most of this will become public in a month or so. Leaking meta-data is an assumed risk (or too much hassle…

I use PGP pretty regularly, too. But what does that have to do with the comment I wrote?

Re: Encrypted email is still a pain

#28
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

Yes! Thank you.

Email is not and will never be secure. Sorry people but it just fucking sucks when it comes to encryption.

We have many other great communication protocols that were designed from the ground up to be secure as they can be.

Re: Encrypted email is still a pain

#29
post #4

Ooh, I know this one! I think. Doesn't Apple Mail have this built in? I go to Keychain Access, choose the option to generate a key. Two clicks. Head to Mail, encryption options are there. Now, to import his key. Do some googling on that. Wait, what? Apple Mail supports S/MIME, not GPG. Competing standards strike again. If the other person has S/MIME, Apple Mail does have a very easy experience. I can't speak for the…

For Apple Mail there is this: https://gpgtools.org/index.html

I use it (in El Capitan), it works really well, it's the first time I've been regularly signing my messages with PGP.

Re: Encrypted email is still a pain

#30
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> Encrypted email is pretty much over in 2017.

One could make the argument that encrypted email was never a thing outside a tiny, miniscule, group of folks.

Is it possible those same people probably bought more scrutiny than others simply because they used encryption?

Post reply on HN