Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

271–280 of 450 posts

Re: Encrypted email is still a pain

#271
post #189
post #170

Earlier quoted context omitted.

> The emerging consensus among experts "conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the lai…

There are federated options for messengers, the fact that the current darlings aren't is not a mark against the option itself. Riot exists. Can you find a security expert RECOMMENDING email? That would be a better example of how it's not a consensus, like you claim.

For those(like me) who are looking for the famous reference Implementation Vector, it got a rename[0] to Riot[1] lately.

[0]Rename: https://medium.com/@RiotChat/lets-riot-f5b0aa99dc8e#.3toozs7...

Homepage: https://matrix.org/docs/projects/client/riot.html

Re: Encrypted email is still a pain

#272
post #170
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> The emerging consensus among experts "conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the lai…

You know, I've been having this conversation ever since PGP first came into existence. And much as I love the idea of encryption, and despite having invested lots of time in arguing for the right to encrypt and to share encryption algorithms etc. etc. I've always had to admit that if you're not a geek who loves computing for its own sake then encrypting all your email is a massive pain in the ass, whose costs substantially exceed the benefits for most people. Given that this argument has been going on for 20 years and that hardly anyone encrypts their emails on a daily basis, I'd say that the empirical evidence is that your solution, while clever, is Not Good because it doesn't meet people's actual needs.

Stop telling me why you like it and build something that's easy for other people to use. In your pursuit of technical excellence you are completely ignoring the importance of network effects on adoption and the disutility of standing out from the crowd by your use of super-solid encryption. Nobody wants to maintain a collection of public keys for every single person they know. No matter how bad things get politically there is not going to be a sudden mass awakening that will cause everyone to start using public key encryption for email, or we'd have already seen it take off like wildfire in politically repressive jurisdictions.

It's. Not. Going. To. Happen.

Re: Encrypted email is still a pain

#273

Earlier quoted context omitted.

Replace? That's a strong word but it has more or less deprecated paper mail. Everything from insurance cards to my recent W2s are delivered electronically via e-mail now. I recently bought a car and all the paperwork was completed online. The bank uses electronic signatures for everything. The amount of first class mail delivered by USPS has halved over the last decade. Is paper mail dead? No. Is it on it's deathbed?…

Out of curiosity, I plotted first class mail delivery vs. population: https://i.imgur.com/Fp2LLCg.png Annual per-capita mail delivery is down 50% in the US since Y2K.

So 20 years of internet, the rise of mobile and hi-speed connectivity, the multiplication of communications means including emails, chats, text and social network and the paper mail is still here.

I still receive all my most important communications through the mail box, including anything related to administration, voting, my landlord, invitations to major life events, bank details, etc.

Now if you hope to kill email, you gonna have to remember that.

Re: Encrypted email is still a pain

#274
post #31

For what it's worth, I used to use encrypted mail some time ago as much as possible, before realising it was fundamentally flawed: — the key retention is the biggest issue. You need to keep your key around for a long time, probably storing copies of it. This increases the probability of a leak. — there is no method to revoke a key with a 100% assurance that nobody will use or trust it afterwards. — if a key is broken…

> the key retention is the biggest issue. You need to keep your key around for a long time, probably storing copies of it. As I get it, this one is a fundamental issue, not specific to messaging at all, but is just a secure storage problem. You either keep a copy of the message (and need some key to decrypt it, unless you keep it unencrypted), or you throw it away. No amount of engineering can solve this.

That's what 'perfect forward security' is intended to solve. For more details please look up the Off The Record (otr) protocol overlay.

The basic idea is that any given session is authenticated temporally; when a session is completed the details for it are leaked so that anyone could forge content as having been within that session. Thus there is reasonable doubt about anything that was said/transferred having actually been said/transferred.

Re: Encrypted email is still a pain

#275
post #73

gpg2 broke when I updated from Ubuntu 14.04 to Ubuntu 16.04. I had to export the keys using gpg and import them using gpg2. Before the upgrade gpg2 was able to read the keys just fine. Now, that's not the only problem after the upgrade, Enigmail is having some other issues... It's a mess.

The problem was likely that gpg2 made a /copy/ of your gpg(1) keyring when it first ran. After that they were out of sync.

gpg2 really just needs a gpg1 comparability shim that's good enough that it /replaces/ the gpg1 tools on a system and seamlessly gets them to use the gpg2 keyring.

Re: Encrypted email is still a pain

#276

Earlier quoted context omitted.

Did you also notice that Google's messaging system pretty much died out around that point in favor of Skype and similar? I used to see people mention GTalk all the time, but I haven't seen anything similar in years. No one has mentioned G+ or Allo. That decision by Google may have been the thing that killed its user base.

No, it turned into Hangouts, which is alive and kicking, specially for companies using Google Apps.

But really only internally, at least in my experience

Re: Encrypted email is still a pain

#277
post #189
post #170

Earlier quoted context omitted.

> The emerging consensus among experts "conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the lai…

There are federated options for messengers, the fact that the current darlings aren't is not a mark against the option itself. Riot exists. Can you find a security expert RECOMMENDING email? That would be a better example of how it's not a consensus, like you claim.

Riot might be a great platform for doing business, but it's pretty useless for any other kind of activity. If you're a political activist having an app called 'Riot' on your phone or computer is not going to look good to anyone in law enforcement.

Re: Encrypted email is still a pain

#278
post #4

Ooh, I know this one! I think. Doesn't Apple Mail have this built in? I go to Keychain Access, choose the option to generate a key. Two clicks. Head to Mail, encryption options are there. Now, to import his key. Do some googling on that. Wait, what? Apple Mail supports S/MIME, not GPG. Competing standards strike again. If the other person has S/MIME, Apple Mail does have a very easy experience. I can't speak for the…

GPG makes a big deal of doing its own thing and trying to avoid "standards" which they believe might be tainted? It's very unclear to me. For smart cards, GPG wants to own the card completely, and does not want to play with anybody else or use the existing PKCS standards.

So it turns out that the "standard" email encryption is actually S/MIME, and it works pretty much everywhere (non-webmail) out of the box, with fairly decent UI. It even works on iPhones.

Re: Encrypted email is still a pain

#279
post #41

Earlier quoted context omitted.

The modern messaging services agree with you. Nobody has completely nailed the UX for long-term long-form conversations, but services like Signal are designed with those kinds of conversations in mind. At the same time: if you had to compare the UX of running a long-term secret conversation over Signal versus the UX of trying to reliably encrypt messages over email, no normal user would ever choose the latter. Secure…

> Nobody has completely nailed the UX for long-term long-form conversations, but services like Signal are designed with those kinds of conversations in mind. No, they're actually not designed with any kind of "long termness" in mind! Case in point - one cannot move to a new device and still have access to conversations that happened on the older device with Signal. All old conversations just have to die with the old…

Also, no way to have multiple separate conversations with the same person, or threaded conversations.

These may just be app problems -- there may be protocol support for future applications to provide these (this is where Matrix stands today). But the lack of interest in these things doesn't look good.

Re: Encrypted email is still a pain

#280
post #170
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> The emerging consensus among experts "conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the lai…

I've been using email since 1992 in a huge variety of work, study and personal contexts. I installed PGP now and then in the '90's out of curiosity but never sent a single encrypted email as I never came across any recipients with it installed. I have never had anyone request email encryption. I don't know what the expert consensus is. But the user consensus is that PGP is invisible, and will never be used outside of a few tiny niches.
Post reply on HN