Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

241–250 of 450 posts

Re: Encrypted email is still a pain

#241
post #172

Earlier quoted context omitted.

> What's the benefit of decentralization? Not being snarky, I just don't really see it. What does a decentralized PGP email have that I don't have with my Signal Messenger? It's a lot harder to block. You can have anyone run a mail server on any port (SSLed if necessary), which means you can use it for secure communications inside any "great firewall" (like that of China or Kazakhstan), or even in a country/region th…

https://whispersystems.org/blog/the-ecosystem-is-moving/ One of the explicit protocol level trade offs is federation: > One of the controversial things we did with Signal early on was to build it as an unfederated service. Nothing about any of the protocols we've developed requires centralization; it's entirely possible to build a federated Signal Protocol based messenger, but I no longer believe that it is possible…

All due respect it not exactly mind-blowing that to compete with some of the most successful businesses in the world you have to do things they can't. The author often likes to use catchy quotes so let's go with the classic "It is difficult to get a man to understand something, when his salary depends on his not understanding it". They make their money selling licenses and consulting for centralized messaging services. It's not in the interest of either party to have disagreements on this issue.

Re: Encrypted email is still a pain

#242
post #101

Earlier quoted context omitted.

> Normal people --- and eventually the F-500's, too --- just use WhatsApp. Sure, but WhatsApp is a totally closed protocol owned by a company (Facebook) known for rampant issues with privacy. Security professionals have a responsibility to recommend open protocols like Signal that are dedicated to privacy.

This is the "have you stopped beating your wife yet" of security arguments.

You usually seem like a very smart and reasonable man but here I feel you are missing major parts of the picture and I don't understand why you would.

Given what we have seen from Facebook so far I am not convinced they wouldn't sell data to anyone including Hitler as long as they paid for it somehow.

More realistically though I fully expect them to sell (misleading) data to insurance companies, Indian (and other) support scammers etc without asking many questions.

For that reason I prefer almost anything including email and Telegram.

(My opinions might be somewhat coloured by the fact that I was an enthusiastic Whatsapp user before Facebook bought them and even stayed and gave Facebook another chance with Whatsapp. )

Re: Encrypted email is still a pain

#244
post #217

I do not get why everyone thinks that encrypted email is GPG. S/MIME is supported by almost all email clients. S/MIME is far less of a pain (but still some pain and could be improved). It has a model of how to verify that keys belong to the right person, that actually works in practice in contrast to GPG where you basically have to verify keys by hand (adversarial CAs are a problem, but probably only for a tiny amoun…

a) The key management UX is even worse than GPG, at least IME. b) If you're willing to trust the CA system the advantages of using email rather than any transport-encrypted messenger (e.g. facebook messenger) seem decidedly marginal

You control which CAs you anchor your trust to locally. Additionally, the encryption part isn't tied to the CA system -- you encrypt directly with the public keys of your recipients. You can use the CA system to validate that the public key belongs to someone validated by some attributes -- certificates are used for this.

The US Federal Government (FPKI) and US Department of Defense (DOD PKI) use S/MIME heavily.

Re: Encrypted email is still a pain

#245
post #75

Earlier quoted context omitted.

> No, I fully understand the problem. If Google Mail vanished tomorrow, a pretty large number of people would probably stop emailing altogether. The number of people for whom that's true increases every year. I highly doubt that's true. Email is pretty essential to the functionality of the internet, from signing up accounts to getting notifications, to just plain discussions with professionals. It's pretty much the o…

Three responses: * Email remains important for middle-class Americans because it's used for business. But that is a small subset of the whole population, including very large numbers of Americans. * For almost all those users, email might as well be a Google, Yahoo, or Microsoft product. * Every year, the number of people and businesses that rely on email gets smaller --- in the last 5 years or so, by something like…

There's a big dilemma with using centralized systems for sensitive communication.

* You have to use one that is not economically or legally dependent on a jurisdiction hostile to you.

* There can never be many different centralized messaging systems that are economically viable because that requires network effects.

As a result, there will always be a large number of people who will not be able to find a centralized system that protects them reliably.

Re: Encrypted email is still a pain

#246
post #212

Earlier quoted context omitted.

For personal use email is rarely self-hosted, but corporations, governments, and organisations often run their own email infrastructure. That effectively makes email a decentralized federated system. You might argue how a lot of email is either send to or send from Google, Apple, or Microsoft services, and that is thus somewhat centralized, but isn't that stretching the definition?

Is talking about government organizations hosting their own email servers really a point in email's favor in 2017?

It means email federation is alive and well.

Re: Encrypted email is still a pain

#247
post #91
post #74

Earlier quoted context omitted.

Yes with no control over what happens to your key and you don't know if your message has been encrypted after it is sent and by default you aren't even told if the key of your recipient changes.

By making the discredited argument that WhatsApp's key-change behavior is a fatal flaw, you're disagreeing with: * The EFF * Moxie Marlinspike * Matthew Green * Bruce Schneier * Isis Lovecruft from Tor * the grugq * Matt Blaze * Avi Rubin * Steve Bellovin * Joseph Lorenzo Hall * Bart Preneel * Peter Honeyman * Jon Callas (who cofounded PGP Corp) * Paulo Barreto ... and about 50 more experts equally respected in the f…

> By making the discredited argument that WhatsApp's key-change behavior is a fatal flaw, you're disagreeing with... and about 50 more experts equally respected in the field if less known to the typical HN reader.

No, the vulnerability was confirmed and the argument that it represents a fatal flaw for those needing fully secure communications is sound. No one competent (and intellectually honest) has disputed this, or would even try to do so. The open letter itself acknowledges it, and I know every open letter signer I followed did so as well.

What the open letter did was take issue with the language used by The Guardian, point out the potential for such language to scare some people into less secure solutions, and argue that the vulnerability is a reasonable trade-off for convenience that can benefit some users too.

Re: Encrypted email is still a pain

#248
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

I would appreciate if you would stop recommending Whatsapp so uncritically at this point.

Re: Encrypted email is still a pain

#249
post #79

Earlier quoted context omitted.

> No, I fully understand the problem. If Google Mail vanished tomorrow, a pretty large number of people would probably stop emailing altogether. The number of people for whom that's true increases every year. I highly doubt that's true. Email is pretty essential to the functionality of the internet, from signing up accounts to getting notifications, to just plain discussions with professionals. It's pretty much the o…

Wechat is what's doing this is China, and it's working fairly well for them. It's obviously impossible to do the same in the West (companies won't be trusted by people in Europe, nation-level apps won't be trusted in US) but it's not impossible to replace email. Note: mobile is gigantic compared to desktop in China, so this might also be a reason. I still believe email will outlast all the current solutions though, b…

While WeChat is somewhat more advanced then its rivals, the reason it works is because Chinese businesses are less 'sophisticated' than western ones and much more human based. WeChat is to a large extent a phone call replacement, which is especially useful in a country of multiple languages and dialects but a common written one. Western messaging services are mainly replacing things like text messages and other instant messengers not e-mail. (e-mail is probably still the de facto most insecure protocol on the internet and should be replaced).

Re: Encrypted email is still a pain

#250

Earlier quoted context omitted.

Electronic conversations didn't even replace paper mail.

Replace? That's a strong word but it has more or less deprecated paper mail. Everything from insurance cards to my recent W2s are delivered electronically via e-mail now. I recently bought a car and all the paperwork was completed online. The bank uses electronic signatures for everything. The amount of first class mail delivered by USPS has halved over the last decade. Is paper mail dead? No. Is it on it's deathbed?…

Out of curiosity, I plotted first class mail delivery vs. population:

https://i.imgur.com/Fp2LLCg.png

Annual per-capita mail delivery is down 50% in the US since Y2K.

Post reply on HN