Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

421–430 of 450 posts

Re: Encrypted email is still a pain

#421
post #96

Earlier quoted context omitted.

There are also people that use OpenOffice on Desktop Linux, and believe in their bones that everyone else should too.

I sometimes preferred it even on Windows and even when I have a valid office subscription. Some people really manage to mess up styles and Open or LibreOffice used to make it much easier to clean up those docs. (I'd switch back to get page numbers right though :-/)

I've also preferred it on Windows, having a valid Office subscription, because I've needed to open obscure/obsolete file formats that Word/Excel don't support.

Re: Encrypted email is still a pain

#422
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> Better to move sensitive conversations to things like Signal, WhatsApp, or Wire Just download an app that requires you to register with your phone number and then hand out your phone number to anyone you want to chat to. I mean, all the NSA-proof crypto is fantastic, but they didn't exactly test it with anyone who has had to worry about less theoretical non-state actors like, oh, jealous exes, abusive partners, cre…

Yes, I find this a worrisome feature.

I understand why they make this tradeoff -- it makes onboarding trivial. And it lets them piggyback contact discovery off of people's existing address books. But the downsides are very significant and rarely acknowledged.

Re: Encrypted email is still a pain

#423
post #238

A client's admin sends credentials via email - including logins and passwords for mission critical infrastructure. When asking him about security concerns he said: "Our mail server's using HTTPS, everything is secure" I haven't responded to that.

Noob question: what are the problems here? Mail server being compromised, and/or any of the sender/recipient machines?

Re: Encrypted email is still a pain

#424

Earlier quoted context omitted.

You usually seem like a very smart and reasonable man but here I feel you are missing major parts of the picture and I don't understand why you would. Given what we have seen from Facebook so far I am not convinced they wouldn't sell data to anyone including Hitler as long as they paid for it somehow. More realistically though I fully expect them to sell (misleading) data to insurance companies, Indian (and other) su…

Facebook see your whatsapp contacts (social graph) and can sell that, but they really can't see the content of conversations. If being known to be in contact with certain people (e.g. human rights activists) can be damaging to you, you need to use something other than whatsapp or to somehow make sure the phone number whatsapp knows cannot be connected to your identity.

Facebook see your whatsapp contacts (social graph) and can sell that, but they really can't see the content of conversations.

Exactly the problem. My conversations should be utterly unexiting for anyone capable of getting hold if them.

I am personally more worried about FB selling (misleading) data to insurance companies. If their ad targeting is at the same level as everyone else they could get whatever conclusions they want from whatever data.

And then there is the issue about actual human rights activists and while I am not very active (monthly payment to amnesty) I don't want to support a system that scoops everyones data into the hands of "they trusted me" Zuckerberg.

Even worse I was with Whatsapp and gave Facebook another chance until it was clear that datamining everyone was the only reason they bought the company.

Re: Encrypted email is still a pain

#425
post #156

...Or you could just use https://www.mailpile.is/ , which is a genuinely less painful way to do encrypted email.

Thanks for the shout out. We're not ready for public consumption yet though, still working on it. We always need more developers and "skilled" testers though!

Wow that looks great! I'll keep an eye on this :)

Re: Encrypted email is still a pain

#426
post #170
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

> The emerging consensus among experts "conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the lai…

Whilst you focus on "consensus" as the key word, I focused on "emerging" as the key word. Perhaps "a few blog posts" is where this consensus is emerging.

Re: Encrypted email is still a pain

#427

Earlier quoted context omitted.

I got a group of about 30 non-technies using Signal, not because they knew what what perfect forward secrecy is, but because they grew vaguely suspicious of the motivations of governments and Facebook, and people/Google-results they trusted were positive. The details don't matter to ordinary people, but our approval matters much more than you think. I have very high hopes for Matrix.org.

I think your group of people would be highly disappointed whenever each person moves to a new device and finds that they have essentially "lost" all old messages and have to re-join groups afresh. > The details don't matter to ordinary people, but our approval matters much more than you think. I have very high hopes for Matrix.org. I agree on this part completely, and I try to introduce better tools to others too. Bu…

matrix e2e is still beta, and we just haven't implemented e2e session sharing yet. you can now export/import keys when migrating between devices as a workaround but proper sharing is coming soon.

Re: Encrypted email is still a pain

#428
post #417
post #356

Earlier quoted context omitted.

> you're always going to have at least the envelope headers available to every intermediate mail host. Sure, so any intermediate server would see who was talking to who. But that's the case with Signal et al as well isn't it?

”But that's the case with Signal et al as well isn’t it?” No. ”Because your phone will be connecting to Signal’s servers, your cellular carrier can determine whether or not you are using the service. However, your carrier cannot gather any information about the individuals or groups with whom you are communicating.” Source: https://github.com/WhisperSystems/Signal-iOS/wiki/FAQ#what-a...

Right, but Signal's servers see who you're communicating with, and they're the equivalent of the intermediate mail servers here.

Re: Encrypted email is still a pain

#430
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

>emerging consensus among experts

Citation needed.

>at best you're attempting to tunnel encrypted messaging over an unencrypted transport

Like every encryption scheme ever.

>A protocol that leaks metadata

They all do? At best you get to choose which provider sees it, and even then timing attacks usually make short work.

>browser clients that can't meaningfully implement crypto

>search that can only be delivered efficiently at scale by databases of plaintext (most likely at centralized servers).

Technically, nobody uses browser clients; browsers can't talk SMTP. They use browser interfaces to cloud clients, over encrypted connections. The centralization is the main problem - you cede both security and control. Plaintext search is a weird example. That can trivially be done on a mobile phone.

Why bother? Because email isn't going away. Any encryption is a strict improvement. And it's federated! No network, federated or no, comes close to email's ubiquity.

Again, the main problem is the centralization to large providers. It makes it very hard to add encryption support as a protocol addon - you have to convince every provider that it's worth their while. The One True Solution is for people to start running their own mailboxes - which seems daunting, but plenty of once-sophisticated tech setups have been productized.

By analogy, I use SilenceIM for encrypted text messages. This is a very similar scenario to email - federated, plethora of unencrypted clients, no handshaking. The difference is the message gets delivered straight to me instead of a server somewhere, and I am free to install a new program that knows how to handle it. Mobile phones have actually provoked a once-unexpected shift back towards native clients for things (there was a time when people were predicting that web would completely eat desktop - thankfully they've piped down now).

Post reply on HN