Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

101–110 of 450 posts

Re: Encrypted email is still a pain

#101
post #34

If you're OK with using a third-party and would rather stick to GUI's, Virtru is a very easy solution for email encryption: https://www.virtru.com/

Where by "email encryption" we mean "mail people a link to a service they can register with and then upload messages and file to, so that SMTP is used only to relay links to messages, not the messages themselves, and email is encrypted by dint of TLS connections". That's what most F-500 companies do to solve this problem. It's a more viable approach than direct encryption of PGP. Normal people --- and eventually the…

> Normal people --- and eventually the F-500's, too --- just use WhatsApp.

Sure, but WhatsApp is a totally closed protocol owned by a company (Facebook) known for rampant issues with privacy.

Security professionals have a responsibility to recommend open protocols like Signal that are dedicated to privacy.

Re: Encrypted email is still a pain

#102
post #99
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> Better to move sensitive conversations to things like Signal, WhatsApp, or Wire Really? Come on! WhatsApp is owned by a company whose business is done by retrieving all the information it can from users and by tracking their behaviors.

Funny how it wasn't until after they were acquired by that company that they began the project to adopt the protocol that would make reading their messages cryptographically hard.

It's almost as if you can't start from some tiny set of first principles about the world and use it to reason through any problem in a message board comment.

Re: Encrypted email is still a pain

#103
post #81

Earlier quoted context omitted.

> Setting up my own federated XMPP instance is much more problematic Actually, I believe it's the contrary. With email you have to obtain a valid TLS certificate, set up SPF, DKIM, and keep eye on the DNSRBLs so you're in good standing. And if Big Company's mail service suddenly decides they don't like you, it won't help. Oh, and spamassasin/rspamd/milter/greylisting/etc stuff so your email server doesn't get thousan…

> XMPP has less adoption, spam exists but is much rare, so there's less stuff to do. Install a package, get a TLS cert, publish an SRV record (IIRC that's not even strictly required), and that's it. A bit fewer steps. That's what I thought as well. Please link tutorial on this.

Personally, I'm using ejabberd, but I wouldn't recommend it. Don't have any good tutorial links at hand, sorry.

I'd agree with /u/problems suggestion to try Prosody. http://prosody.im/doc/install + http://prosody.im/doc/configure + http://prosody.im/doc/dns#srv_records + http://prosody.im/doc/certificates are probably all you have to do to get it up and running.

Re: Encrypted email is still a pain

#104
post #101
post #34

Earlier quoted context omitted.

Where by "email encryption" we mean "mail people a link to a service they can register with and then upload messages and file to, so that SMTP is used only to relay links to messages, not the messages themselves, and email is encrypted by dint of TLS connections". That's what most F-500 companies do to solve this problem. It's a more viable approach than direct encryption of PGP. Normal people --- and eventually the…

> Normal people --- and eventually the F-500's, too --- just use WhatsApp. Sure, but WhatsApp is a totally closed protocol owned by a company (Facebook) known for rampant issues with privacy. Security professionals have a responsibility to recommend open protocols like Signal that are dedicated to privacy.

This is the "have you stopped beating your wife yet" of security arguments.

Re: Encrypted email is still a pain

#105
post #22

Earlier quoted context omitted.

WhatsApp has over a billion users. There are big places where its market share exceeds that of SMS --- another big centralized service that has a userbase comparable to that of email. My conclusion is that the people who care about "decentralized" systems are a rounding error. I care about non-technologists managing to send asynchronous messages to each other that are well-encrypted by default. That's a solved proble…

Isn't it also true that the people who care about "secure" systems are a rounding error? Average Joe is perfectly fine with just "100% secure" label. Add some "military grade hurr durr" nonsense (okay, maybe it's a bit outdated buzzword) and Joe's even willing to pay for it. No need for any actual security.

Again: the Venn diagram between people who want encryption and people who need encryption has very little overlap. And, thankfully, modern secure messaging systems work for both populations.

Re: Encrypted email is still a pain

#106
post #65

The more this topic comes up, the more I start to wonder if the "difficulty" in email encryption is actually people just being lazy. We have IM and texting apps like Signal. You install, and if your friends install then you're secure. Most people skip verifying fingerprints, not doing IRL face to face verification. Yes the install process is simple and requires no real work to start encrypting things, but that still…

>I start to wonder if the "difficulty" in email encryption is actually people just being lazy

I think it's a combination of this and perhaps some ignorance as to the implications of skipping these processes, hence they aren't taken seriously. I'm not sure if more education on this is the solution or not, since it seems a lot of people don't really care about these internals and don't want to take the time to understand what's going on. I'm not sure I'd describe this as laziness or just stubbornness.

Users tend to be very goal-oriented and with (for example) TLS certificate validation errors, these simply stand in the way of what the end-user is trying to achieve. There have been a couple of studies done on how users tend to just dismiss these errors http://static.usenix.org/legacy/events/sec09/tech/full_paper...

Re: Encrypted email is still a pain

#107

Earlier quoted context omitted.

Isn't it also true that the people who care about "secure" systems are a rounding error? Average Joe is perfectly fine with just "100% secure" label. Add some "military grade hurr durr" nonsense (okay, maybe it's a bit outdated buzzword) and Joe's even willing to pay for it. No need for any actual security.

Again: the Venn diagram between people who want encryption and people who need encryption has very little overlap. And, thankfully, modern secure messaging systems work for both populations.

Which also applies to the distributed systems - email, in context of this particular discussion. Same logic here: email works for both.

And doesn't apply to IM systems, because it's just not possible for Whatsapp user to contact Signal user and invite Wire user in a group. IM app fatigue is a real problem. Or maybe it's just that nearly everyone in my bubble has load of apps just to contact all their peers.

Re: Encrypted email is still a pain

#109
post #96
post #89

Earlier quoted context omitted.

> In modern messaging protocols, they don't have to care about encryption. The protocols are designed to reliably encrypt messages without user intervention, and security isn't "opt-in". Sounds good. Doesn't sound worth giving up decentralisation for. Doesn't even seem like something we'd need to give up OpenPGP to get - if client design were equal (and it isn't at the moment, but I see no reason it can't be) I'd far…

There are also people that use OpenOffice on Desktop Linux, and believe in their bones that everyone else should too.

They're wrong, obviously. LibreOffice is much better.

Re: Encrypted email is still a pain

#110

This article: what a shitfest. But seriously, I was expecting some actual discussion about how GPG still isn't easy (or possible for that matter) in modern webmail clients, or even something relating to the usability of common GPG GUIs, but instead just got a guy complaining about how he was pressing enter too fast and missed a dialog box, among other nonsense complaints. Personally, the GPG CLI acts exactly as I exp…

A messaging standard that only advanced users can use is basically useless. That's the point of the article.
Post reply on HN