Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

61–70 of 450 posts

Re: Encrypted email is still a pain

#61
post #14
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> But: why bother? Email is just one of dozens of messaging systems available to Internet users. No, it's not. It's the only widely available, decentralized system, with which you can send to anyone, if you know the address. None of the big ones is this open. XMPP tried to address this and failed; now Matrix is trying again.

Forgive my ignorance, but what caused XMPP to fail? Simply the lack of uptake or is there some other reason?

Re: Encrypted email is still a pain

#62
post #48
post #46

Earlier quoted context omitted.

> My conclusion is that the people who care about "decentralized" systems are a rounding error. I care about non-technologists managing to send asynchronous messages to each other that are well-encrypted by default. That's a solved problem. You don't understand the problem: if you rely on a service like this, two things can - and by the laws of probability, will - happen: a, a centralized service goes down and sudden…

No, I fully understand the problem. If Google Mail vanished tomorrow, a pretty large number of people would probably stop emailing altogether. The number of people for whom that's true increases every year. If you find that unthinkable, consider the bubble you might be living in. I appreciate that there are people that require a decentralized service for messaging and understand where they're coming from. I don't den…

> No, I fully understand the problem. If Google Mail vanished tomorrow, a pretty large number of people would probably stop emailing altogether. The number of people for whom that's true increases every year.

I highly doubt that's true. Email is pretty essential to the functionality of the internet, from signing up accounts to getting notifications, to just plain discussions with professionals. It's pretty much the only thing that does what it does.

To use non-nerd examples people in my life have done recently via email: contacting the school registrar's office, updating insurance information, discussing minor problems with a recent surgery with their doctor. Especially for people with anxiety issues who have problems on the phone, email is a life saver.

I lived off email when buying a house through a builder last year. Everyone went through email and nothing else was even offered in many cases. The builder, bankers, lawyers, electricians, everything was email.

Re: Encrypted email is still a pain

#63
post #61
post #14

Earlier quoted context omitted.

> But: why bother? Email is just one of dozens of messaging systems available to Internet users. No, it's not. It's the only widely available, decentralized system, with which you can send to anyone, if you know the address. None of the big ones is this open. XMPP tried to address this and failed; now Matrix is trying again.

Forgive my ignorance, but what caused XMPP to fail? Simply the lack of uptake or is there some other reason?

I've been running my email server for a decade without serious glitches. Setting up my own federated XMPP instance is much more problematic and people are already complaining about how hard email is.

I'd love to see an up-to-date tutorial that opposes my statement, eg. setting up prosody (or something lightweight) on debian (or similar) with multiple domains for multiple accounts, sending and receiving test messages from another XMPP hub, so if you know one, please link it.

Re: Encrypted email is still a pain

#64
post #58
post #22

Earlier quoted context omitted.

WhatsApp has over a billion users. There are big places where its market share exceeds that of SMS --- another big centralized service that has a userbase comparable to that of email. My conclusion is that the people who care about "decentralized" systems are a rounding error. I care about non-technologists managing to send asynchronous messages to each other that are well-encrypted by default. That's a solved proble…

People who care about encryption are a rounding error too. I care about non-technologists managing to send asynchronous messages to each other that are not controlled by a centralized entity (especially not one based in a country who's interests are often adverse to my own). That's a solved problem that you seem to be trying very hard to unsolve.

That's exactly the point. Take a step back and think about what you just said. It's true: most people don't care about crypto. But here's are two other true statements:

* In modern messaging protocols, they don't have to care about encryption. The protocols are designed to reliably encrypt messages without user intervention, and security isn't "opt-in".

* The people who most need encryption are not the ones who are most aware of the need. In fact, the Venn diagram of "need" and "want" for crypto has very little overlap.

Re: Encrypted email is still a pain

#65
The more this topic comes up, the more I start to wonder if the "difficulty" in email encryption is actually people just being lazy.

We have IM and texting apps like Signal. You install, and if your friends install then you're secure. Most people skip verifying fingerprints, not doing IRL face to face verification. Yes the install process is simple and requires no real work to start encrypting things, but that still doesn't make the process secure. If anything, having these types of security models where you aren't forced to verify the other end continues to breed this lazy mentality. Security is hard and requires all end users to actually put time and thought into what they are doing. We can always make a better mouse trap when it comes to security but that will not change people's minds on how they interact with security when online.

Re: Encrypted email is still a pain

#66
It's only a pain if you're still trying to use PGP. You can download Inky (http://inky.com) for any platform and use any email account to exchange S/MIME-encrypted email simply by checking a button. We're focused on large enterprises now (because we've found consumers and small business don't care about encrypting their email, or think TLS=encryption) but there's nothing stopping individuals from trying it out. It makes e2e encryption of email using any email account basically invisible. You can send encrypted mail to non-Inky users as well.

Re: Encrypted email is still a pain

#67
post #31

For what it's worth, I used to use encrypted mail some time ago as much as possible, before realising it was fundamentally flawed: — the key retention is the biggest issue. You need to keep your key around for a long time, probably storing copies of it. This increases the probability of a leak. — there is no method to revoke a key with a 100% assurance that nobody will use or trust it afterwards. — if a key is broken…

> the key retention is the biggest issue. You need to keep your key around for a long time, probably storing copies of it.

As I get it, this one is a fundamental issue, not specific to messaging at all, but is just a secure storage problem.

You either keep a copy of the message (and need some key to decrypt it, unless you keep it unencrypted), or you throw it away. No amount of engineering can solve this.

Re: Encrypted email is still a pain

#68
post #59
post #37

Earlier quoted context omitted.

No. I don't know if it's a generational thing, but people on message boards today seem pretty convinced that Snowden invented concern over dragnet encryption. Get a copy of Applied Cryptography and thumb through it; it's shot through with the mindset that NSA (specifically: NSA) is reading all your mail. The 1990s were the decade of the cipherpunks, the Clipper Chip, the crypto wars, Echelon, and the hacker crackdown…

NSA, of course. But NSA - I really hope - doesn't sell your data for profit to insurance and medical companies, so there's a difference. If NSA picks up something serious about you, you're in deep trouble, but the current data sniffer companies can make your life really hard without you even realizing it.

I'm not advocating plaintext email. I'm advocating for no email. But since it'll be 10-15 years before email takes its place alongside ICQ among protocols normal people never use, in the meantime, the right solution is to keep email banal, and keep sensitive stuff on secure messaging protocols.

Re: Encrypted email is still a pain

#69
Years ago, working at a friend's security company everyone used Apple Mail with GPG. That is the only time anyone insisted on using encrypted email.

Fast forward to the present: I support and like ProtonMail, but I can't talk anyone else into using it. I don't understand why more small companies, wanting to protect their intellectual property, don't use ProtonMail (or something like it).

Re: Encrypted email is still a pain

#70
post #61
post #14

Earlier quoted context omitted.

> But: why bother? Email is just one of dozens of messaging systems available to Internet users. No, it's not. It's the only widely available, decentralized system, with which you can send to anyone, if you know the address. None of the big ones is this open. XMPP tried to address this and failed; now Matrix is trying again.

Forgive my ignorance, but what caused XMPP to fail? Simply the lack of uptake or is there some other reason?

Google's embrace-extend-extinguish destroyed XMPP. They made their chat system XMPP compatible for a short time which caused many people to swap to their solution. When they ended support, most users simply stopped using XMPP.
Post reply on HN