Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

411–420 of 450 posts

Re: Encrypted email is still a pain

#411

Earlier quoted context omitted.

That's what 'perfect forward security' is intended to solve. For more details please look up the Off The Record (otr) protocol overlay. The basic idea is that any given session is authenticated temporally; when a session is completed the details for it are leaked so that anyone could forge content as having been within that session. Thus there is reasonable doubt about anything that was said/transferred having actual…

No. PFS is about when messages are in transit. Sure thing, it makes sense to encrypt them with ephemeral keys rather than a long-living ones. However, that particular point I've quoted was - as I understood it - about message archives. Short-lived keys are just fundamentally incompatible with long-term storage. We either keep data, or we don't. PFS helps for about another point raised, "if a key is broken or leaked..…

> However, that particular point I've quoted was - as I understood it - about message archives.

In a sense you're right, but the archive in question is the one your adversary accrued while they were intercepting your in-flight emails, which you encrypted with your static key. Any archive you have control over is sort of beside the point.

Re: Encrypted email is still a pain

#412
The main challenge for me seems to be that users do not have a concept of maintaining a digital identity and the key management that goes along with it. They just expect their real world identity to somehow translate automatically.

This just does not happen. Though I wonder if government-issued digital ID might be of benefit here to encourage good practices. Estonian ID-cards carry key pairs, so if email clients supported GPG email with smartcard-hosted keys (uhh maybe some do but I never heard of one) then this might be an approach worth undertaking.

Re: Encrypted email is still a pain

#413

Earlier quoted context omitted.

This was my mistake! It's not too short. I search-and-replaced my h2 tags with h3, which broke the key. Oops. I've fixed it now.

Now it works, nevertheless it still is (too) short, because you are using a soon-to-be insecure key size: https://www.gnupg.org/faq/gnupg-faq.html#default_rsa2048 "In 2010, France’s Agence Nationale de la Securite des Systems d’Information stated they had confidence in RSA-2048 until at least 2020."

:( That was the default size suggested to me by gpg.

Re: Encrypted email is still a pain

#414
post #237

Earlier quoted context omitted.

I agree with not using WhatsApp due to it's ties to FB and metadata issues, but Telegram is arguably even worse. They've been (rightfully) panned for implementing their own crypto and doing it poorly. You should be using Signal on a phone if you're trying to use a secure messenger.

You should be using Signal on a phone if you're trying to use a secure messenger. I am not trying to use a secure messenger. I am trying to use a good one without ratting on my friends to the worst (as in size x badness) company I am aware of. Ohh, and I don't want to be be part of their network effect either.)

All reasonable views, but I don't think that's a Telegram given their track record. At this point I'd put more trust in a transport-encrypted-without-end-to-end messenger than Telegram, and there are plenty of good options in that space (e.g. Discord, or hell, AIM). And if you want genuine security there are good decentralised options: XMPP (Conversations et al), Riot/Matrix, possibly Wire.

Re: Encrypted email is still a pain

#415
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> Better to move sensitive conversations to things like Signal, WhatsApp, or Wire

Just download an app that requires you to register with your phone number and then hand out your phone number to anyone you want to chat to. I mean, all the NSA-proof crypto is fantastic, but they didn't exactly test it with anyone who has had to worry about less theoretical non-state actors like, oh, jealous exes, abusive partners, creepy Tinder dates and so on.

Why do I need to give someone my phone number to use an IP-based chat service?

Re: Encrypted email is still a pain

#416

Earlier quoted context omitted.

Now it works, nevertheless it still is (too) short, because you are using a soon-to-be insecure key size: https://www.gnupg.org/faq/gnupg-faq.html#default_rsa2048 "In 2010, France’s Agence Nationale de la Securite des Systems d’Information stated they had confidence in RSA-2048 until at least 2020."

:( That was the default size suggested to me by gpg.

2048-bit RSA keys are still very common and the least of your worries for quite a while.

Re: Encrypted email is still a pain

#417
post #356

Earlier quoted context omitted.

You would still leak unencrypted headers, which in SMTP are numerous and interesting. A client could minimize the useful content of the message headers, but you're always going to have at least the envelope headers available to every intermediate mail host. I do not know enough to be sure about your point about forward secrecy. You may be right.

> you're always going to have at least the envelope headers available to every intermediate mail host. Sure, so any intermediate server would see who was talking to who. But that's the case with Signal et al as well isn't it?

”But that's the case with Signal et al as well isn’t it?”

No.

”Because your phone will be connecting to Signal’s servers, your cellular carrier can determine whether or not you are using the service. However, your carrier cannot gather any information about the individuals or groups with whom you are communicating.”

Source: https://github.com/WhisperSystems/Signal-iOS/wiki/FAQ#what-a...

Re: Encrypted email is still a pain

#418
post #61
post #14

Earlier quoted context omitted.

> But: why bother? Email is just one of dozens of messaging systems available to Internet users. No, it's not. It's the only widely available, decentralized system, with which you can send to anyone, if you know the address. None of the big ones is this open. XMPP tried to address this and failed; now Matrix is trying again.

Forgive my ignorance, but what caused XMPP to fail? Simply the lack of uptake or is there some other reason?

See this essay for some insights: https://whispersystems.org/blog/the-ecosystem-is-moving/

Re: Encrypted email is still a pain

#419

Earlier quoted context omitted.

This is the "have you stopped beating your wife yet" of security arguments.

You usually seem like a very smart and reasonable man but here I feel you are missing major parts of the picture and I don't understand why you would. Given what we have seen from Facebook so far I am not convinced they wouldn't sell data to anyone including Hitler as long as they paid for it somehow. More realistically though I fully expect them to sell (misleading) data to insurance companies, Indian (and other) su…

Facebook see your whatsapp contacts (social graph) and can sell that, but they really can't see the content of conversations.

If being known to be in contact with certain people (e.g. human rights activists) can be damaging to you, you need to use something other than whatsapp or to somehow make sure the phone number whatsapp knows cannot be connected to your identity.

Re: Encrypted email is still a pain

#420
post #204

Earlier quoted context omitted.

The maintainer of the "Conversations" XMPP client wrote an interesting response to that article: https://gultsch.de/objection.html

Thanks, I wasn't aware of this. Though to be honest, I am not exactly convinced. Calling HTML federated seems a real stretch. My browser doesn't have to talk to other browsers, just servers, and those can speak many languages. The network effects are really _very_ fundamentally different. The reality is that, no matter how much I wanted xmpp (and google wave for that matter) to succeed, Signal (and if you are willing…

Have you tried Conversations? You might want to give it a try. On the whole, the user experience is not significantly worse than Signal. With both sides using OMEMO encryption, privacy should be about the same.

Trade offs:

Onboarding is trivially more complex. You have to enter your JID and a password -- registration of a new JID adds one checkbox to that.

Contact discovery does not piggyback on phone numbers, so you will have to add JIDs to your address book if you want Conversations to pick them up.

Another new XMPP-based app, Zom (https://zom.im/) makes some of this easier by letting you automatically register on their hosted XMPP server, locking you into sane default settings, etc. Android app seems still a little buggy, though.

Post reply on HN