Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

321–330 of 450 posts

Re: Encrypted email is still a pain

#321

Earlier quoted context omitted.

A bold statement like that without a source just screams bullshit.

I think tptacek thinks in a way where he's giving you charity in an uneven discussion, so he's not obligated to go further; perhaps harsh, but his reputation warrants a little pause before simply saying "bullshit".

His reputation is specifically why I asked for a source. While I don't doubt he's an intelligent individual, I've noticed that he also likes to "shoot from the hip" without providing evidence of many claims he makes on both here and Twitter.

Re: Encrypted email is still a pain

#322
post #106
post #65

The more this topic comes up, the more I start to wonder if the "difficulty" in email encryption is actually people just being lazy. We have IM and texting apps like Signal. You install, and if your friends install then you're secure. Most people skip verifying fingerprints, not doing IRL face to face verification. Yes the install process is simple and requires no real work to start encrypting things, but that still…

>I start to wonder if the "difficulty" in email encryption is actually people just being lazy I think it's a combination of this and perhaps some ignorance as to the implications of skipping these processes, hence they aren't taken seriously. I'm not sure if more education on this is the solution or not, since it seems a lot of people don't really care about these internals and don't want to take the time to understa…

> not sure if more education on this is the solution

Security education is a never ending battle. Just like "use condoms", "floss your teeth", "wash your hands", etc. It also changes. Today "Use a password manager" is the new "change your password".

Re: Encrypted email is still a pain

#323
post #113

Earlier quoted context omitted.

Agree about Matrix. You get addresses such as @username:example.com , which work somewhat like email addresses. The example.com part is the homeserver, analogous to gmail.com or yahoo.com in emails. Users can communicate across homeservers. It's also fast to setup. Took me about 30 minutes to set up a homeserver and host a customized riot client to use it. It's not completely decentralized yet, and you can only use f…

Just to clarify: identity servers are strictly optional and are used just for mapping 3rd party IDs (3PIDs) such as phone numbers and email addresses to matrix IDs so you can be discovered or discover other users by 3PID. They are only centralised atm because we haven't really started to attack the problem of decentralising them. What we really need is a decentralised equivalent of Keybase, but nobody has really buil…

Re: metadata: I really like Riot/Matrix and have convinced a bunch of formerly non-IRC people to start using IRC through Matrix (the great free IRC bouncer in the sky!). However, a couple of things that bother me:

- The fact that it appears to be impossible to disable typing notifications ("X is typing...") and read receipts. This can change the nature of a conversation and really should be optional. Coming from IRC, it just feels plain creepy. A friend flat-out refused to use Riot because of this.

- The fact that device information is leaked to everyone who happens to be in the same channel. So I can join #matrix and click on any of the >5k users and see information about all the devices a particular user has used. Here's from one random person: "https://riot.im/app/ via Chrome on Mac OS", "https://riot.im/app/ via Chrome on Windows", E5823 (ah, J. Doe is using a Sony Xperia Z5 Compact!), etc. Sometimes things like "Joe's iPhone" is exposed -- and I don't think Joe had any idea of that. This is bad.

Re: Encrypted email is still a pain

#324
post #101

Earlier quoted context omitted.

> Normal people --- and eventually the F-500's, too --- just use WhatsApp. Sure, but WhatsApp is a totally closed protocol owned by a company (Facebook) known for rampant issues with privacy. Security professionals have a responsibility to recommend open protocols like Signal that are dedicated to privacy.

This is the "have you stopped beating your wife yet" of security arguments.

More like the "you're telling your wife to trust a guy that repeatedly beat her and a bunch of other women?" of security arguments. Expecting abuse from a known abuser or situation known to lead to it. Very reasonable expectation. Best to avoid the abusive party and warn others to do the same.

Re: Encrypted email is still a pain

#325

Earlier quoted context omitted.

The fact that Osama Bin Laden didn't use PGP should be the final nail in its coffin.

That the NSA said GPG was gsme over for mass collection in the Snowden lesks should be a reason for everyone to try to improve its UI.

thats a pretty terrible argument. And how it follows for your own logic is beyond me.

Re: Encrypted email is still a pain

#326
post #234
post #170

Earlier quoted context omitted.

> The emerging consensus among experts "conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the lai…

Why use PGP anymore when you can use Keybase and the next generation of key management? Instead of having one master key for your identity, the paradigm is changed: Identity is a set of claims "X on domain A is Y on domain B". That's it. "Domain" can refer to a server-based service such as reddit, or a client app on a device. Such proofs are easy: 1) For public identity on sites which don't support this scheme, X sim…

I would love to be able to use Keybase to send encrypted email. Sadly currently Keybase does have a email as a main property on the profile and fetching it from the GPG is not very cool.

I really want to be able to type Twitter, Hacker News or Github names into emails.

Re: Encrypted email is still a pain

#327
If you find 'gpg --gen-key' too hard to use, I don't know what to tell you.

It presents (at least on my system) a very clear prompt to type a passphrase. Maybe you should blame your distribution instead of gpg?

Re: Encrypted email is still a pain

#328
post #189

Earlier quoted context omitted.

There are federated options for messengers, the fact that the current darlings aren't is not a mark against the option itself. Riot exists. Can you find a security expert RECOMMENDING email? That would be a better example of how it's not a consensus, like you claim.

Riot might be a great platform for doing business, but it's pretty useless for any other kind of activity. If you're a political activist having an app called 'Riot' on your phone or computer is not going to look good to anyone in law enforcement.

"having an app called riot" is the absolute least of an actual activists concern when selecting something to help them communicate. One of the most well known leftist platforms for email is riseup.

Re: Encrypted email is still a pain

#329

Earlier quoted context omitted.

That the NSA said GPG was gsme over for mass collection in the Snowden lesks should be a reason for everyone to try to improve its UI.

thats a pretty terrible argument. And how it follows for your own logic is beyond me.

That the NSA cracked, backdoored, or intercepted most providers people trusted but couldnt beat GPG isnt an argument for GPG being secure? I think it's quite an endorsement for GPG given most people's adversaries will be weaker than NSA.

Re: Encrypted email is still a pain

#330
post #170

Earlier quoted context omitted.

> The emerging consensus among experts "conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the lai…

You know, I've been having this conversation ever since PGP first came into existence. And much as I love the idea of encryption, and despite having invested lots of time in arguing for the right to encrypt and to share encryption algorithms etc. etc. I've always had to admit that if you're not a geek who loves computing for its own sake then encrypting all your email is a massive pain in the ass, whose costs substan…

I'm hoping Apple will lead the way. They have enough devices in the wild that could force others to adopt over time. They did it with floppy drives and optical drives. I don't see why they couldn't do it with encrypted e-mails. With their stance on no backdoors, they could raise their privacy profile for consumers and increase sales of iPhones at the same time.
Post reply on HN