Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

161–170 of 450 posts

Re: Encrypted email is still a pain

#161
post #48
post #46

Earlier quoted context omitted.

> My conclusion is that the people who care about "decentralized" systems are a rounding error. I care about non-technologists managing to send asynchronous messages to each other that are well-encrypted by default. That's a solved problem. You don't understand the problem: if you rely on a service like this, two things can - and by the laws of probability, will - happen: a, a centralized service goes down and sudden…

No, I fully understand the problem. If Google Mail vanished tomorrow, a pretty large number of people would probably stop emailing altogether. The number of people for whom that's true increases every year. If you find that unthinkable, consider the bubble you might be living in. I appreciate that there are people that require a decentralized service for messaging and understand where they're coming from. I don't den…

Do you really understand the problem as you claim? The amount of people who require a decentralized system is irrelevant to the issue. The issue is in what users will do when their trusted system goes down, be it centralized or decentralized.

Say Gmail goes down (forever), will people use another of their emails? Or register for a new one somewhere else? Or start using another medium of communication alltogether? I assume all of the above will occur to some extent, but if that system was centralized, only the third option would be available. And if that centralized system was so good that it had killed all competition, then suddenly no one would be able to communicate.

It's not about the amount of people who scream for decentralized solutions. It's about the alternatives available in case something does go down, and how easy those alternatives are for users to adopt.

Re: Encrypted email is still a pain

#162
post #157

Isis? I guess we have to trust her after all the ioerror affair, right? Considering he's currently on trial for all her allegations. /sarcasm moxie HAS to agree with his protocol. thegrugq? Wasn't he selling exploits to the highest bidder? http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-th... I can't argue about their qualifications, I argue about their morality. .edit added link.

Are you seriously suggesting that a large portion of the crypto/security community is so inherently biased that you can't trust their expert opinion on the field that they're expert in? Who do you trust?

No, I'm just saying SOME of those people I don't trust. Feel free to trust them though.

Re: Encrypted email is still a pain

#163
post #159

Isis? I guess we have to trust her after all the ioerror affair, right? Considering he's currently on trial for all her allegations. /sarcasm moxie HAS to agree with his protocol. thegrugq? Wasn't he selling exploits to the highest bidder? http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-th... I can't argue about their qualifications, I argue about their morality. .edit added link.

[deleted]

Is that your expert opinion?

Re: Encrypted email is still a pain

#164
post #89

Earlier quoted context omitted.

> In modern messaging protocols, they don't have to care about encryption. The protocols are designed to reliably encrypt messages without user intervention, and security isn't "opt-in". Sounds good. Doesn't sound worth giving up decentralisation for. Doesn't even seem like something we'd need to give up OpenPGP to get - if client design were equal (and it isn't at the moment, but I see no reason it can't be) I'd far…

What's the benefit of decentralization? Not being snarky, I just don't really see it. What does a decentralized PGP email have that I don't have with my Signal Messenger? Also, given how PGP works I fail to see how you can claim that you can achieve comparable client design/ease of use/UX to Signal. At the very least it appears evident to me that the problem is much much harder than Signal (and it should be, Signal w…

> What's the benefit of decentralization?

No single point at which to apply judicial- and/or rubber-hose cryptography is the big one.

I do agree that the problem-space of attempting to make a reasonable UI for GPG has been explored for a long time with no useful results. I'd love someone to prove me wrong, but it seems like that's a hopeless endeavor.

It is worth asking why, though. I'm not a UI person, so apply appropriate weighting to my opinion. I think this is one area - application of the Unix philosophy to task-driven security software - results in software that only the really invested will use. A combination email encryption/key distribution system with most nonessential options stripped out, targeting one mail client (at least at first) might be simple enough to achieve something closer to Signal-level usability. And the rounding-errors can continue to use the full GPG for our weird open-source rituals.

But who knows. Maybe the entire model is just too complicated for mere mortals.

Re: Encrypted email is still a pain

#165
post #91
post #74

Earlier quoted context omitted.

Yes with no control over what happens to your key and you don't know if your message has been encrypted after it is sent and by default you aren't even told if the key of your recipient changes.

By making the discredited argument that WhatsApp's key-change behavior is a fatal flaw, you're disagreeing with: * The EFF * Moxie Marlinspike * Matthew Green * Bruce Schneier * Isis Lovecruft from Tor * the grugq * Matt Blaze * Avi Rubin * Steve Bellovin * Joseph Lorenzo Hall * Bart Preneel * Peter Honeyman * Jon Callas (who cofounded PGP Corp) * Paulo Barreto ... and about 50 more experts equally respected in the f…

"you're disagreeing with"

This is the problem with the security community, always with authoritative arguments. Building a religion around security is not going to end well. Some of those people already push government agendas and people eat it, because they were told not to question "experts".

Re: Encrypted email is still a pain

#166

Earlier quoted context omitted.

How does WhatsApp compare to email? I mean, how easy is it for me to contact MS CEO via email vs WhatsApp? Or my doctor. Or my mom. Or my friend I've not seen in a while. Or????

It's not that easy to compare the two. With WhatsApp, if you know the phone number of the person you want to contact, then you can send them a message or call them via WhatsApp. Both users need to have WhatsApp installed, but this is not a big problem in most countries outside of the US, since the install base is over 1 billion.

With email, you can usually do a simple search and find an email. Super simple.

Re: Encrypted email is still a pain

#167
post #91

Earlier quoted context omitted.

By making the discredited argument that WhatsApp's key-change behavior is a fatal flaw, you're disagreeing with: * The EFF * Moxie Marlinspike * Matthew Green * Bruce Schneier * Isis Lovecruft from Tor * the grugq * Matt Blaze * Avi Rubin * Steve Bellovin * Joseph Lorenzo Hall * Bart Preneel * Peter Honeyman * Jon Callas (who cofounded PGP Corp) * Paulo Barreto ... and about 50 more experts equally respected in the f…

Do you have sources for that? Because just looking at the first two you named the EFF (who marked WhatsApp down for being closed source). And the owner of the Signal protocol (which is what WhatsApp uses). Obviously he's not going to argue against it.

EFF has criticized WhatsApp for being closed source, but not for this particular aspect of the key exchange functionality.

Because of the history around how WhatsApp was criticism over this and some of the apparent results of that criticism, tptacek particularly doesn't want people to conflate "there is something bad, unfortunate, or inadequate about WhatsApp" with "WhatsApp has a 'backdoor' in its key exchange" (and I understand that!).

Re: Encrypted email is still a pain

#169
post #23

Earlier quoted context omitted.

So what, it's all or nothing for you? Even if there is an easy to use solution that you can set someone up with in about 10 minutes, that's absolutely valueless because it means that less than 100% of messages will use it?

What do you want to hear from me? Part of this is my own bias against email, but that's not all it is: I'm not making up the "emerging consensus" bit.

I'm a little concerned that the emerging consensus in question may be led by you, as you are a famous information security expert and people take your concerns and views very seriously. When you mention your view about this here or on Twitter, lots of people quarrel with you about it (some of them engaging with it seriously). A number of people have been persuaded by your arguments but a number of people keep strongly disagreeing.

But it's possible that more people agree with you and fewer disagree in contexts where people have more information security expertise or where more of them work on it professionally.

Re: Encrypted email is still a pain

#170
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> The emerging consensus among experts

"conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the laity, which, doesn't necessarily mean that you need to be an expert to use it: my friends and I learnt how to encrypt, decrypt and sign emails when we were still in high-school. And while you probably need to read a manual (something that may sound draconian by the current standards of the software industry) to learn how to use gpg, there is no other cryptography tool as powerful, versatile and secure as this.

Why bother? because e-mail is federated, Signal, WhatsApp, and Wire are not. Because you don't need to put all your trust on a device like a mobile phone, or a company like Facebook. Because you don't even need e-mail nor Internet to send encrypted mails to some journalist, for instance. But please don't get me wrong: I really appreciate the effort of messaging apps like Signal for casual conversations, but if my own life was at stake I wouldn't even touch my phone (except for taking out its battery).

Post reply on HN