Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

181–190 of 450 posts

Re: Encrypted email is still a pain

#181
post #22
post #14

Earlier quoted context omitted.

> But: why bother? Email is just one of dozens of messaging systems available to Internet users. No, it's not. It's the only widely available, decentralized system, with which you can send to anyone, if you know the address. None of the big ones is this open. XMPP tried to address this and failed; now Matrix is trying again.

WhatsApp has over a billion users. There are big places where its market share exceeds that of SMS --- another big centralized service that has a userbase comparable to that of email. My conclusion is that the people who care about "decentralized" systems are a rounding error. I care about non-technologists managing to send asynchronous messages to each other that are well-encrypted by default. That's a solved proble…

How many times has WhatsApp been blocked in Brazil? What's your advice for those 100 million users when it stops working? Switch to another centralized messenger, and convince their friends and family members around the world to do the same so they can continue communicating?

What would happen if e-mail didn't exist, and a site like HN listed their WhatsApp contact information instead of an e-mail address? Suddenly, the Brazilian user base here would be unable to contact HN. They might be completely out of luck, or if the user base was large enough, HN could add an alternative contact method for users in restricted regions. "Contact us on WhatsApp. If you're in Brazil, you'll need to contact us on ABC messenger instead. If you're in China, and unable to access both, you'll need to send us a message on XYZ messenger."

Re: Encrypted email is still a pain

#182
post #172

Earlier quoted context omitted.

What's the benefit of decentralization? Not being snarky, I just don't really see it. What does a decentralized PGP email have that I don't have with my Signal Messenger? Also, given how PGP works I fail to see how you can claim that you can achieve comparable client design/ease of use/UX to Signal. At the very least it appears evident to me that the problem is much much harder than Signal (and it should be, Signal w…

> What's the benefit of decentralization? Not being snarky, I just don't really see it. What does a decentralized PGP email have that I don't have with my Signal Messenger? It's a lot harder to block. You can have anyone run a mail server on any port (SSLed if necessary), which means you can use it for secure communications inside any "great firewall" (like that of China or Kazakhstan), or even in a country/region th…

Also, is it really true that a state actor could not effectively block email? Or for that matter all encrypted email? They are, after all, blocking web pages. It seems to me (as a lay man observer) that at the state actor level the Internet is relying on centralized resources already, maybe that's why decentralization seems intuitively less important to me. This is not to disagree with your points.

Re: Encrypted email is still a pain

#183

Earlier quoted context omitted.

It's not that easy to compare the two. With WhatsApp, if you know the phone number of the person you want to contact, then you can send them a message or call them via WhatsApp. Both users need to have WhatsApp installed, but this is not a big problem in most countries outside of the US, since the install base is over 1 billion.

With email, you can usually do a simple search and find an email. Super simple.

And we go to great lengths trying to avoid this because of email harvesters for spam.

However I would not like it to transform into phone number harvesters for spam.

Re: Encrypted email is still a pain

#184
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

>"* An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport."

These reasons seems to suggest that encrypted email is "all or nothing" and I'm not sure why that is. I am not interested in using encrypted email with all of my conversations. For non personal emails I am perfectly OK with sending email in clear test. For people who I communicate with only via encrypted email, I simply add them to my "encrypted email" contact list any my email client encrypts those emails. The reverse of this would be true on this recipients end. So the idea that its all or nothing is no different than HTTP traffic, example - I don't care if some trivial blog about cats isn't HTTPs.

> * A protocol that leaks metadata, including some message content, at the envelope layer.

This is true of some IPSEC modes as well example Tunnel Mode vs Transport Mode. If I am OK with just payload being encrypted then so what? Again why does this have to be all or nothing with regard to email?

>"Hundreds of millions of users that primarily access messages through browser clients that can't meaningfully implement crypto."

And encrypted email in this context would simply be "unavailable." This is not that much different from down-level versions of browsers or Java not being able to use newer versions of TLS.

>"* An unencrypted installed base that ensures encryption will be opt-in for the foreseeable future, meaning that users will routinely reveal plaintext accidentally by, for instance, quoting messages and forgetting to encrypt"

What is wrong with opt-in? Again why is it all or nothing? I either choose to add someone as an encrypted contact or not. People already leak all of kinds of information via forwarding email. Why is this an issue? I can also take a screen shot of an iMessage that was sent to me encrypted on my phone and paste it to someone else.

>"End user demands for things like search that can only be delivered efficiently at scale by databases of plaintext (most likely at centralized servers)"

Clients can maintain a local copy of an encrypted index. I don't think this is a non-starter.

Re: Encrypted email is still a pain

#185
post #79

Earlier quoted context omitted.

Wechat is what's doing this is China, and it's working fairly well for them. It's obviously impossible to do the same in the West (companies won't be trusted by people in Europe, nation-level apps won't be trusted in US) but it's not impossible to replace email. Note: mobile is gigantic compared to desktop in China, so this might also be a reason. I still believe email will outlast all the current solutions though, b…

Electronic conversations didn't even replace paper mail.

Replace? That's a strong word but it has more or less deprecated paper mail. Everything from insurance cards to my recent W2s are delivered electronically via e-mail now. I recently bought a car and all the paperwork was completed online. The bank uses electronic signatures for everything. The amount of first class mail delivered by USPS has halved over the last decade. Is paper mail dead? No. Is it on it's deathbed? Probably.

Re: Encrypted email is still a pain

#186
post #84
post #80

Earlier quoted context omitted.

re @tptacek > Every year, the number of people and businesses that rely on email gets smaller --- in the last 5 years or so, by something like 15%. Are you sure that's not just the spam decreasing?

Yes.

A bold statement like that without a source just screams bullshit.

Re: Encrypted email is still a pain

#187
post #14

Earlier quoted context omitted.

> But: why bother? Email is just one of dozens of messaging systems available to Internet users. No, it's not. It's the only widely available, decentralized system, with which you can send to anyone, if you know the address. None of the big ones is this open. XMPP tried to address this and failed; now Matrix is trying again.

> No, it's not. It's the only widely available, decentralized system, with which you can send to anyone, if you know the address. None of the big ones is this open. SS7 is internet connected and federated and it's arguably as big as email. > XMPP tried to address this and failed; now Matrix is trying again. Oh, agreed on XMPP. Encryption was a very much after the fact addition to it though. I haven't heard about Matr…

http://matrix.org/ is a promising decentralized communications protocol.

The popular https://riot.im is built on top.

Re: Encrypted email is still a pain

#188
post #170

Earlier quoted context omitted.

> The emerging consensus among experts "conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the lai…

The hardest problem, IMHO, has been key management. How do you get+trust the other's key? I think a combination of keybase + a useful client can help, but the reasons listed in parent are pretty convincing.

>How do you get+trust the other's key?

Snail mail + several other out of band methods. Or you can exchange a one time pad, physically.

Re: Encrypted email is still a pain

#189
post #170
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> The emerging consensus among experts "conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the lai…

There are federated options for messengers, the fact that the current darlings aren't is not a mark against the option itself. Riot exists.

Can you find a security expert RECOMMENDING email? That would be a better example of how it's not a consensus, like you claim.

Re: Encrypted email is still a pain

#190
post #75

Earlier quoted context omitted.

Three responses: * Email remains important for middle-class Americans because it's used for business. But that is a small subset of the whole population, including very large numbers of Americans. * For almost all those users, email might as well be a Google, Yahoo, or Microsoft product. * Every year, the number of people and businesses that rely on email gets smaller --- in the last 5 years or so, by something like…

> * Every year, the number of people and businesses that rely on email gets smaller --- in the last 5 years or so, by something like 15%. If that's true then where's that stat from and how are these businesses getting contacted online? There's no decent replacement for email in that department at all to my knowledge.

Can't answer the source of the stat, but where they're getting contacted - FB messenger or Twitter, for starters.

I've done most of my non-B2B communication with businesses over the last year or so via FB messenger, Twitter or phone.

Post reply on HN