Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

201–210 of 450 posts

Re: Encrypted email is still a pain

#201
post #170

Earlier quoted context omitted.

> The emerging consensus among experts "conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the lai…

The hardest problem, IMHO, has been key management. How do you get+trust the other's key? I think a combination of keybase + a useful client can help, but the reasons listed in parent are pretty convincing.

If you care about the physical identity of someone: web of trust.

At some point, you'll have to ideally meet at least one person in the flesh to exchange keys and verify their identity. After that point, it's possible that others you are trying to communicate with might be within your web of trust. If not, you'll have to go through your keysigning procedure again.

  https://www.gnupg.org/gph/en/manual/x334.html
Some organizations facilitate keysigning:

  https://wiki.debian.org/Keysigning/Coordination
But that might not be necessary for you. For example, I don't necessarily care about the physical identity for some of the people I communicate with online. If I see in e-mail archives that person is using the same key to sign their mail for the past N years, I'll use that key to encrypt to them. Similarly with commit signing and such. In that case, I just care that my message is reaching the intended recipient.

I communicate with a number of GNU hackers. Package maintainers upload their signing keys to Savannah, and sign each of their releases with that key. If I simply want to know that my message is reaching that maintainer, I can get the key that way.

But if I want to know that I'm actually speaking to the person that the maintainer _claims_ to be, I'd want to use the web of trust. They could very well be an imposter!

Re: Encrypted email is still a pain

#202
post #13

A secring is a "secret keyring" that contains a number of private keys. I agree that consistency of "secret" versus "private" would be helpful, but the concepts of a key and a keyring are distinct (and a reasonably effective metaphor IMO - you have a keyring which your keys are on). The extent to which the tools should push you towards having a single key versus rotating is arguable; people criticise GPG for being to…

Kmail is the only GPG experience I have ever found that just worked. It has a selection of keyservers by default, and if you email someone with a key on one of them it just magically uses it like its supposed to.

Combine that with the KDE GPG manager which is also painless to generate and upload your own key, and its the only time I have ever been able to get "muggles" using GPG successfully.

Re: Encrypted email is still a pain

#203
post #14

Earlier quoted context omitted.

> But: why bother? Email is just one of dozens of messaging systems available to Internet users. No, it's not. It's the only widely available, decentralized system, with which you can send to anyone, if you know the address. None of the big ones is this open. XMPP tried to address this and failed; now Matrix is trying again.

> No, it's not. It's the only widely available, decentralized system, with which you can send to anyone, if you know the address. They have to be email users to have an address. Granted, it's so widespread that even signing up for one of the other messengers often requires an email address, so even the non-email users have email addresses. But I still think email is going to go the way of usenet, non-internet phone c…

I'm more interested in seeing something that maintains the desirable properties of email while dropping backward compatibility with SMTP. But the 'encrypted messenger' community isn't interested in working on that because they think (apparently?) that email does not have any desirable properties compared to siloed IM systems.

Re: Encrypted email is still a pain

#204
post #172

Earlier quoted context omitted.

> What's the benefit of decentralization? Not being snarky, I just don't really see it. What does a decentralized PGP email have that I don't have with my Signal Messenger? It's a lot harder to block. You can have anyone run a mail server on any port (SSLed if necessary), which means you can use it for secure communications inside any "great firewall" (like that of China or Kazakhstan), or even in a country/region th…

https://whispersystems.org/blog/the-ecosystem-is-moving/ One of the explicit protocol level trade offs is federation: > One of the controversial things we did with Signal early on was to build it as an unfederated service. Nothing about any of the protocols we've developed requires centralization; it's entirely possible to build a federated Signal Protocol based messenger, but I no longer believe that it is possible…

The maintainer of the "Conversations" XMPP client wrote an interesting response to that article:

https://gultsch.de/objection.html

Re: Encrypted email is still a pain

#205
If you want more-secure methods adopted, they have to be easy to use.

I find that encrypted PDFs are a reasonable option, even when reading on mobile.

If I want to send myself something sensitive, I attach a password-protected PDF; then even if I open the “E-mail” on my iPhone, I am prompted for a password before I am allowed to view it.

And frankly, I wish that web sites would stop trying to implement their own clunky mail-like “secure” messaging systems and just use password PDF. I hate receiving these “you have a secure message on oursite.com!” messages that are impossible to deal with on mobile (not to mention they appear very spam-like at first).

Re: Encrypted email is still a pain

#206
post #187

Earlier quoted context omitted.

http://matrix.org/ is a promising decentralized communications protocol. The popular https://riot.im is built on top.

> The popular https://riot.im is built on top. Thanks, so it's basically a opensource and federated slack? How does this solve the email encryption use case? (longer form text not requiring presence)

As is, it doesn't. It should be possible to build an app with the email nature on top of the Matrix protocols though, and I'm led to understand there are people working on it.

Re: Encrypted email is still a pain

#207
post #89

Earlier quoted context omitted.

> In modern messaging protocols, they don't have to care about encryption. The protocols are designed to reliably encrypt messages without user intervention, and security isn't "opt-in". Sounds good. Doesn't sound worth giving up decentralisation for. Doesn't even seem like something we'd need to give up OpenPGP to get - if client design were equal (and it isn't at the moment, but I see no reason it can't be) I'd far…

What's the benefit of decentralization? Not being snarky, I just don't really see it. What does a decentralized PGP email have that I don't have with my Signal Messenger? Also, given how PGP works I fail to see how you can claim that you can achieve comparable client design/ease of use/UX to Signal. At the very least it appears evident to me that the problem is much much harder than Signal (and it should be, Signal w…

>What's the benefit of decentralization?

Decentralization/Federalization + Standard Protocols. To really get the full potential, one needs both, since only then the network is truly free.

Nobody can tell you how to access the Network, what software to use, who you can communicate with, etc.

If you try using an unofficial WhatsApp client (eg. when you don't have you're phone), they can delete your account, and you can't do anything against that. This is IMO just too much control the central server has over the client.

Re: Encrypted email is still a pain

#208
post #46
post #22

Earlier quoted context omitted.

WhatsApp has over a billion users. There are big places where its market share exceeds that of SMS --- another big centralized service that has a userbase comparable to that of email. My conclusion is that the people who care about "decentralized" systems are a rounding error. I care about non-technologists managing to send asynchronous messages to each other that are well-encrypted by default. That's a solved proble…

> My conclusion is that the people who care about "decentralized" systems are a rounding error. I care about non-technologists managing to send asynchronous messages to each other that are well-encrypted by default. That's a solved problem. You don't understand the problem: if you rely on a service like this, two things can - and by the laws of probability, will - happen: a, a centralized service goes down and sudden…

If you're actually in a "great firewall" type situation, though, what are the chances that an average user is going to correctly run your own server securely? Configuring an email server securely is even more complicated than setting up PGP.

Re: Encrypted email is still a pain

#209
post #164

Earlier quoted context omitted.

> What's the benefit of decentralization? No single point at which to apply judicial- and/or rubber-hose cryptography is the big one. I do agree that the problem-space of attempting to make a reasonable UI for GPG has been explored for a long time with no useful results. I'd love someone to prove me wrong, but it seems like that's a hopeless endeavor. It is worth asking why, though. I'm not a UI person, so apply appr…

I don't think the real problem with OpenPGP is the UI issues. OpenKeychain and K9-Mail together provide a not terrible UI for OpenPGP, and if someone wanted to more tightly integrate them with each other,the UI could probably be improved further. But PGP-over-SMTP would still leak important metadata, and you would still have problems with forward secrecy and key revocation. Matrix looks like a much better decentraliz…

> But PGP-over-SMTP would still leak important metadata, and you would still have problems with forward secrecy and key revocation.

I don't think a well-integrated PGP-over-SMTP client would leak any more metadata than the likes of Signal does? Build in a good subkey rotation config and you'd solve most of the forward secrecy issues, and good defaults for how to treat revocation (including better expiry defaults) would resolve that issue. No?

Re: Encrypted email is still a pain

#210
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

As a messaging system Signal, Whatsapp can be considered as a replacement for email. But email is also used as your identity online. All auth systems use email for signup, login, password reset. How will this use case of email work with messengers?

In Signal, Whatsapp, messages are end to end encrypted, but one way where this encryption is undone in some ways is the backup process. Whatsapp allows users to backup messages and media to Google drive and it's unencrypted. So these messengers still don't solve the problem of having e2e communication + encrypted archives of data.

Post reply on HN