Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

251–260 of 450 posts

Re: Encrypted email is still a pain

#251
post #41

Earlier quoted context omitted.

This is all true, but IM is not email. What I want out of email that IM does not (generally) deliver: 1) UI optimized for longer form messages. 2) Decentralized system where you can send to anyone if you know their address, which may be long-lasting and not tied to the fortunes of a single private company. I don't demand compatibility or interoperability with SMTP, but I also don't want to throw the baby out with the…

The modern messaging services agree with you. Nobody has completely nailed the UX for long-term long-form conversations, but services like Signal are designed with those kinds of conversations in mind. At the same time: if you had to compare the UX of running a long-term secret conversation over Signal versus the UX of trying to reliably encrypt messages over email, no normal user would ever choose the latter. Secure…

> Nobody has completely nailed the UX for long-term long-form conversations, but services like Signal are designed with those kinds of conversations in mind.

No, they're actually not designed with any kind of "long termness" in mind! Case in point - one cannot move to a new device and still have access to conversations that happened on the older device with Signal. All old conversations just have to die with the old device, and the new device starts as if Signal was installed for the very first time - including starting conversations with people, getting into groups, etc. Backing up the old device and restoring that into the new one wouldn't help for this. There is no message migration feature available (separately) when one changes devices, and what's worse, in my limited observation, the Signal team just closes feature requests and issues filed on this front on Github. The ugliest part is that this is not even explained when someone installs the app or activates Signal on a new device.

So Signal is good only for ephemeral messaging where one doesn't care about past messages and their availability. Wire has the exact same problem too. One might as well treat apps like Signal and Wire like voice call apps rather than as text/photo messaging apps.

It seems like these apps make some naïve assumptions about the target user either not changing devices for many years (self-defeating in a way with smartphones, where security updates stop after 4-5 years, maximum) and/or not caring about having access to older messages whenever the users gets a new device.

Re: Encrypted email is still a pain

#252
post #84

Earlier quoted context omitted.

Yes.

A bold statement like that without a source just screams bullshit.

I think tptacek thinks in a way where he's giving you charity in an uneven discussion, so he's not obligated to go further; perhaps harsh, but his reputation warrants a little pause before simply saying "bullshit".

Re: Encrypted email is still a pain

#253
post #237

Earlier quoted context omitted.

Note that this argument is even more problematic for OpenPGP-encrypted email, as such email sends all metadata and some message data in plaintext. I ususally respect tptacek a lot but when it comes to Whatsapp I actively avoid it if at all possible, preferring Telegram even if the crypto is more than questionable. Same goes for mail: I prefer it - even unencrypted - over Whatsapp. For some of us our treat model is mo…

I agree with not using WhatsApp due to it's ties to FB and metadata issues, but Telegram is arguably even worse. They've been (rightfully) panned for implementing their own crypto and doing it poorly. You should be using Signal on a phone if you're trying to use a secure messenger.

You should be using Signal on a phone if you're trying to use a secure messenger.

I am not trying to use a secure messenger. I am trying to use a good one without ratting on my friends to the worst (as in size x badness) company I am aware of. Ohh, and I don't want to be be part of their network effect either.)

Re: Encrypted email is still a pain

#254
post #167

Earlier quoted context omitted.

Do you have sources for that? Because just looking at the first two you named the EFF (who marked WhatsApp down for being closed source). And the owner of the Signal protocol (which is what WhatsApp uses). Obviously he's not going to argue against it.

EFF has criticized WhatsApp for being closed source, but not for this particular aspect of the key exchange functionality. Because of the history around how WhatsApp was criticism over this and some of the apparent results of that criticism, tptacek particularly doesn't want people to conflate "there is something bad, unfortunate, or inadequate about WhatsApp" with "WhatsApp has a 'backdoor' in its key exchange" (and…

> EFF has criticized WhatsApp for being closed source, but not for this particular aspect of the key exchange functionality.

The articles I've seen appeared carefully worded so as to achieve some balance, but did express some criticism and concern.

"Nevertheless, this is certainly a vulnerability of WhatsApp, and they should give users the choice to opt into more restrictive Signal-like defaults." from:

https://www.eff.org/deeplinks/2017/01/google-launches-key-tr...

Key change notification concerns paragraph from:

https://www.eff.org/deeplinks/2016/10/where-whatsapp-went-wr...

Re: Encrypted email is still a pain

#255

I do not get why everyone thinks that encrypted email is GPG. S/MIME is supported by almost all email clients. S/MIME is far less of a pain (but still some pain and could be improved). It has a model of how to verify that keys belong to the right person, that actually works in practice in contrast to GPG where you basically have to verify keys by hand (adversarial CAs are a problem, but probably only for a tiny amoun…

S/MIME works fine. Key management isn't a big of deal as many make it out to be. You can pin your key to your linkedin profile or facebook or whatever. Or have a one-time plain-text email asking "Hey, whats your public key?" Right-click, import. Call them on the phone if youre worried that one email was fake.

The problem with HN is that its mostly web-dev startup scene and college students. They've never worked in a company that took security seriously. S/MIME implementations are everywhere in these types of companies and work fine.

If you wanted encrypted email right now you could have it trivially. The problem is that most people don't value it yet. Considering all the hacks and leaks we're seeing, I suspect encrypted email is going to be part of HIPAA or PCI in the next ten years. It makes no sense to use plaintext email in a business setting.

Re: Encrypted email is still a pain

#256
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport

Can you elaborate on what you mean by this? If the message is encrypted (for example: PGP/GPG) why do I care whether the transport is secure or not?

Re: Encrypted email is still a pain

#257
post #234
post #170

Earlier quoted context omitted.

> The emerging consensus among experts "conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the lai…

Why use PGP anymore when you can use Keybase and the next generation of key management? Instead of having one master key for your identity, the paradigm is changed: Identity is a set of claims "X on domain A is Y on domain B". That's it. "Domain" can refer to a server-based service such as reddit, or a client app on a device. Such proofs are easy: 1) For public identity on sites which don't support this scheme, X sim…

Planned to say this as well. The Keybase model is working well for me, and there's nothing special about that network: similarly implemented alternatives could probably strengthen one another.

Re: Encrypted email is still a pain

#259
post #15

Your key is not importable :D $ gpg --import stanley.asc gpg: CRC error; C68D2A - 29357C gpg: read_block: read error: Invalid keyring gpg: import from `stanley.asc' failed: Invalid keyring gpg: Total number processed: 0 Edit: Your key is way too short.

This was my mistake! It's not too short. I search-and-replaced my h2 tags with h3, which broke the key. Oops. I've fixed it now.

Now it works, nevertheless it still is (too) short, because you are using a soon-to-be insecure key size:

https://www.gnupg.org/faq/gnupg-faq.html#default_rsa2048

"In 2010, France’s Agence Nationale de la Securite des Systems d’Information stated they had confidence in RSA-2048 until at least 2020."

Re: Encrypted email is still a pain

#260
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

>"* An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport." These reasons seems to suggest that encrypted email is "all or nothing" and I'm not sure why that is. I am not interested in using encrypted email with all of my conversations. For non personal emails I am perfectly OK with sending email in clear test…

You're absolutely right! If you're willing to be disciplined and communicate solely with similarly disciplined people, encrypted email can be very secure.

The basic problem with email is that the protocol does not adapt well to encrypted content. Too much usable data is in the envelope. On top of this, there are decades of UX expectations and conventions that become unsafe in encrypted contexts. As a result, most users will be highly unsafe by default, and any given person is likely to be significantly less safe than they believe.

But again, you're completely right! It's very possible to use it in a smaller group of people who understand and accept all the tradeoffs. It's just marginally less than ideal for mass adoption, which is where much of the thought is going.

Post reply on HN