Earlier quoted context omitted.
> What's the benefit of decentralization? Not being snarky, I just don't really see it. What does a decentralized PGP email have that I don't have with my Signal Messenger? It's a lot harder to block. You can have anyone run a mail server on any port (SSLed if necessary), which means you can use it for secure communications inside any "great firewall" (like that of China or Kazakhstan), or even in a country/region th…
https://whispersystems.org/blog/the-ecosystem-is-moving/ One of the explicit protocol level trade offs is federation: > One of the controversial things we did with Signal early on was to build it as an unfederated service. Nothing about any of the protocols we've developed requires centralization; it's entirely possible to build a federated Signal Protocol based messenger, but I no longer believe that it is possible…
Encrypted email is still a pain
241–250 of 450 posts
Re: Encrypted email is still a pain
#242Earlier quoted context omitted.
> Normal people --- and eventually the F-500's, too --- just use WhatsApp. Sure, but WhatsApp is a totally closed protocol owned by a company (Facebook) known for rampant issues with privacy. Security professionals have a responsibility to recommend open protocols like Signal that are dedicated to privacy.
This is the "have you stopped beating your wife yet" of security arguments.
Given what we have seen from Facebook so far I am not convinced they wouldn't sell data to anyone including Hitler as long as they paid for it somehow.
More realistically though I fully expect them to sell (misleading) data to insurance companies, Indian (and other) support scammers etc without asking many questions.
For that reason I prefer almost anything including email and Telegram.
(My opinions might be somewhat coloured by the fact that I was an enthusiastic Whatsapp user before Facebook bought them and even stayed and gave Facebook another chance with Whatsapp. )
Re: Encrypted email is still a pain
#243Re: Encrypted email is still a pain
#244I do not get why everyone thinks that encrypted email is GPG. S/MIME is supported by almost all email clients. S/MIME is far less of a pain (but still some pain and could be improved). It has a model of how to verify that keys belong to the right person, that actually works in practice in contrast to GPG where you basically have to verify keys by hand (adversarial CAs are a problem, but probably only for a tiny amoun…
a) The key management UX is even worse than GPG, at least IME. b) If you're willing to trust the CA system the advantages of using email rather than any transport-encrypted messenger (e.g. facebook messenger) seem decidedly marginal
The US Federal Government (FPKI) and US Department of Defense (DOD PKI) use S/MIME heavily.
Re: Encrypted email is still a pain
#245Earlier quoted context omitted.
> No, I fully understand the problem. If Google Mail vanished tomorrow, a pretty large number of people would probably stop emailing altogether. The number of people for whom that's true increases every year. I highly doubt that's true. Email is pretty essential to the functionality of the internet, from signing up accounts to getting notifications, to just plain discussions with professionals. It's pretty much the o…
Three responses: * Email remains important for middle-class Americans because it's used for business. But that is a small subset of the whole population, including very large numbers of Americans. * For almost all those users, email might as well be a Google, Yahoo, or Microsoft product. * Every year, the number of people and businesses that rely on email gets smaller --- in the last 5 years or so, by something like…
* You have to use one that is not economically or legally dependent on a jurisdiction hostile to you.
* There can never be many different centralized messaging systems that are economically viable because that requires network effects.
As a result, there will always be a large number of people who will not be able to find a centralized system that protects them reliably.
Re: Encrypted email is still a pain
#246Earlier quoted context omitted.
For personal use email is rarely self-hosted, but corporations, governments, and organisations often run their own email infrastructure. That effectively makes email a decentralized federated system. You might argue how a lot of email is either send to or send from Google, Apple, or Microsoft services, and that is thus somewhat centralized, but isn't that stretching the definition?
Is talking about government organizations hosting their own email servers really a point in email's favor in 2017?
Re: Encrypted email is still a pain
#247Earlier quoted context omitted.
Yes with no control over what happens to your key and you don't know if your message has been encrypted after it is sent and by default you aren't even told if the key of your recipient changes.
By making the discredited argument that WhatsApp's key-change behavior is a fatal flaw, you're disagreeing with: * The EFF * Moxie Marlinspike * Matthew Green * Bruce Schneier * Isis Lovecruft from Tor * the grugq * Matt Blaze * Avi Rubin * Steve Bellovin * Joseph Lorenzo Hall * Bart Preneel * Peter Honeyman * Jon Callas (who cofounded PGP Corp) * Paulo Barreto ... and about 50 more experts equally respected in the f…
No, the vulnerability was confirmed and the argument that it represents a fatal flaw for those needing fully secure communications is sound. No one competent (and intellectually honest) has disputed this, or would even try to do so. The open letter itself acknowledges it, and I know every open letter signer I followed did so as well.
What the open letter did was take issue with the language used by The Guardian, point out the potential for such language to scare some people into less secure solutions, and argue that the vulnerability is a reasonable trade-off for convenience that can benefit some users too.
Re: Encrypted email is still a pain
#248Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…
Re: Encrypted email is still a pain
#249Earlier quoted context omitted.
> No, I fully understand the problem. If Google Mail vanished tomorrow, a pretty large number of people would probably stop emailing altogether. The number of people for whom that's true increases every year. I highly doubt that's true. Email is pretty essential to the functionality of the internet, from signing up accounts to getting notifications, to just plain discussions with professionals. It's pretty much the o…
Wechat is what's doing this is China, and it's working fairly well for them. It's obviously impossible to do the same in the West (companies won't be trusted by people in Europe, nation-level apps won't be trusted in US) but it's not impossible to replace email. Note: mobile is gigantic compared to desktop in China, so this might also be a reason. I still believe email will outlast all the current solutions though, b…
Re: Encrypted email is still a pain
#250Earlier quoted context omitted.
Electronic conversations didn't even replace paper mail.
Replace? That's a strong word but it has more or less deprecated paper mail. Everything from insurance cards to my recent W2s are delivered electronically via e-mail now. I recently bought a car and all the paperwork was completed online. The bank uses electronic signatures for everything. The amount of first class mail delivered by USPS has halved over the last decade. Is paper mail dead? No. Is it on it's deathbed?…
https://i.imgur.com/Fp2LLCg.png
Annual per-capita mail delivery is down 50% in the US since Y2K.