Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

211–220 of 450 posts

Re: Encrypted email is still a pain

#211
post #194

Earlier quoted context omitted.

What's the benefit of decentralization? Not being snarky, I just don't really see it. What does a decentralized PGP email have that I don't have with my Signal Messenger? Also, given how PGP works I fail to see how you can claim that you can achieve comparable client design/ease of use/UX to Signal. At the very least it appears evident to me that the problem is much much harder than Signal (and it should be, Signal w…

Harder to prevent access to, harder to wire-tap. As other people pointed out WhatsApp has been blocked in countries before. Not to mention that with WhatsApp having a central location all messages are routed through we really don't have any guarantee that there isn't a compromised actor in there intercepting everything. Even if WhatsApp's crytpo is as flawless in implementation as we'd like FB still has access to all…

> Even if WhatsApp's crytpo is as flawless in implementation as we'd like FB still has access to all that metadata.

Note that this argument is even more problematic for OpenPGP-encrypted email, as such email sends all metadata and some message data in plaintext.

Re: Encrypted email is still a pain

#212
post #191

Earlier quoted context omitted.

By that logic shouldn't we try to encrypt SMS? Email as a protocol has huge security issues, and email as it is currently used honestly is NOT federated or decentralized.

For personal use email is rarely self-hosted, but corporations, governments, and organisations often run their own email infrastructure. That effectively makes email a decentralized federated system. You might argue how a lot of email is either send to or send from Google, Apple, or Microsoft services, and that is thus somewhat centralized, but isn't that stretching the definition?

Is talking about government organizations hosting their own email servers really a point in email's favor in 2017?

Re: Encrypted email is still a pain

#215
It's not hard though, it's just hard to do it without any third-party in a way that provides an easy user experience. iMessage is a good example of encrypted E2E messaging that "just works", but it is setup and maintained by a third party.

I would say one of the biggest hurdles to increased security is the debilitating nature of secure from the security people themselves. Everyone wants a perfect solution and postulates endlessly about every edge case. So much so that the community won't accept any solution that has even a little bit of hair on it, so nothing gets done except everyones individual homebrew mechanisms. I swear there's not a pragmatic bone in their bodies, and if you doubt me then join some popular crypto mailing lists and see the tinfoil hattery for yourselves.

Re: Encrypted email is still a pain

#216
post #209

Earlier quoted context omitted.

I don't think the real problem with OpenPGP is the UI issues. OpenKeychain and K9-Mail together provide a not terrible UI for OpenPGP, and if someone wanted to more tightly integrate them with each other,the UI could probably be improved further. But PGP-over-SMTP would still leak important metadata, and you would still have problems with forward secrecy and key revocation. Matrix looks like a much better decentraliz…

> But PGP-over-SMTP would still leak important metadata, and you would still have problems with forward secrecy and key revocation. I don't think a well-integrated PGP-over-SMTP client would leak any more metadata than the likes of Signal does? Build in a good subkey rotation config and you'd solve most of the forward secrecy issues, and good defaults for how to treat revocation (including better expiry defaults) wou…

You would still leak unencrypted headers, which in SMTP are numerous and interesting. A client could minimize the useful content of the message headers, but you're always going to have at least the envelope headers available to every intermediate mail host.

I do not know enough to be sure about your point about forward secrecy. You may be right.

Re: Encrypted email is still a pain

#217

I do not get why everyone thinks that encrypted email is GPG. S/MIME is supported by almost all email clients. S/MIME is far less of a pain (but still some pain and could be improved). It has a model of how to verify that keys belong to the right person, that actually works in practice in contrast to GPG where you basically have to verify keys by hand (adversarial CAs are a problem, but probably only for a tiny amoun…

a) The key management UX is even worse than GPG, at least IME.

b) If you're willing to trust the CA system the advantages of using email rather than any transport-encrypted messenger (e.g. facebook messenger) seem decidedly marginal

Re: Encrypted email is still a pain

#219
post #99

Earlier quoted context omitted.

> Better to move sensitive conversations to things like Signal, WhatsApp, or Wire Really? Come on! WhatsApp is owned by a company whose business is done by retrieving all the information it can from users and by tracking their behaviors.

Funny how it wasn't until after they were acquired by that company that they began the project to adopt the protocol that would make reading their messages cryptographically hard. It's almost as if you can't start from some tiny set of first principles about the world and use it to reason through any problem in a message board comment.

We never trusted Microsoft with their practice of Embrace-Extend-Extinguish. Why should we trust Facebook here?

If Facebook were collaborating with the NSA I see no reason they'd operate differently than we see from the outside now.

Re: Encrypted email is still a pain

#220
post #169
post #23

Earlier quoted context omitted.

What do you want to hear from me? Part of this is my own bias against email, but that's not all it is: I'm not making up the "emerging consensus" bit.

I'm a little concerned that the emerging consensus in question may be led by you, as you are a famous information security expert and people take your concerns and views very seriously. When you mention your view about this here or on Twitter, lots of people quarrel with you about it (some of them engaging with it seriously). A number of people have been persuaded by your arguments but a number of people keep strongl…

There is a presentation[1] by grugq on how to communicate securely. Using gpg with email is hard. Anecdotally, people reply in cleartext quoting the encrypted message. If you can train and test your co-conspirators before sending them incriminating evidence about yourself, maybe it can be done. But mistakes happen so often, people who have secrets that can get them killed or jailed for a long time just switched to Signal. That's what tptacek means.

1 - https://grugq.github.io/presentations/COMSEC%20beyond%20encr...

Post reply on HN