Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

441–450 of 450 posts

Re: Encrypted email is still a pain

#441

Earlier quoted context omitted.

I don't understand. You've verified a Signal key but still felt the need to ask the question With a walled garden like Signal/Wire/etc, how do you get+trust the other's key? What cost were you talking about then?

Sorry if my earlier comment came off as rude. I was just trying to say that the walled gardens aren't really that much better than plain old PGP, and in practice they tend to lull people into a false sense of security. I think too many people are way too trusting of shiny new apps with a pretty UI. If you don't do the extra work of verifying the key, you're effectively letting the service provider act as your one and…

I didn't think it was rude, it just contradicted your other comment.

I still don't see what cost you were speaking about. Mistakes with PGP are at least as likely as mistakes with the shiny easy to use GUI.

Re: Encrypted email is still a pain

#442

Earlier quoted context omitted.

Re: metadata: I really like Riot/Matrix and have convinced a bunch of formerly non-IRC people to start using IRC through Matrix (the great free IRC bouncer in the sky!). However, a couple of things that bother me: - The fact that it appears to be impossible to disable typing notifications ("X is typing...") and read receipts. This can change the nature of a conversation and really should be optional. Coming from IRC,…

These are https://github.com/vector-im/riot-web/issue/3220 and https://github.com/vector-im/riot-web/issue/2295 respectively. Agreed that the info currently leaked in device info sucks - please vote on the issues to get them bumped up the todo list!

Thanks. Corrected URLs:

https://github.com/vector-im/riot-web/issues/3220

https://github.com/vector-im/riot-web/issues/2295

Re: Encrypted email is still a pain

#443

Earlier quoted context omitted.

These are https://github.com/vector-im/riot-web/issue/3220 and https://github.com/vector-im/riot-web/issue/2295 respectively. Agreed that the info currently leaked in device info sucks - please vote on the issues to get them bumped up the todo list!

Thanks. Corrected URLs: https://github.com/vector-im/riot-web/issues/3220 https://github.com/vector-im/riot-web/issues/2295

doh, thanks

Re: Encrypted email is still a pain

#444
post #434
post #226

Earlier quoted context omitted.

(edit: it's fixed now) First time I see it like that, I assume one of your plugins is blocking it (direct links to google profiles). I'll store the images & serve them directly. Thanks!

Still not fixed for me. (Firefox with Ublock Origin)

Ah, Firefox. Now fixed for real. Thanks!

Re: Encrypted email is still a pain

#445
post #439

Earlier quoted context omitted.

If you don't trust that individual to vouch for others then they are treated differently in your web of trust: set their trust level to "none". If you refuse to place trust in anyone, then no, the web of trust will not work for you. But it works for many others; it doesn't make it broken. The purpose of key signing is to verify that a person is legitimately who they claim to be---_that_ is what you are trusting in yo…

> If you don't trust that individual to vouch for others then they are treated differently in your web of trust: set their trust level to "none". Whom in the world do you actually trust to vouch for everyone else in the world? For me, at least, the answer is 'no-one,' — which is why neither XPKI nor the Web of Trust work for me. > But it works for many others; it doesn't make it broken. I suspect that no-one (older t…

I have confidence in certain people that they will follow a given protocol to the best of their ability. They're not vouching for someone: they're indicating the successful completion of a keysigning protocol.

But again: you don't have to trust a single person. As more people sign Alice's key, it's increasingly unlikely that Alice fooled every one of those people.

Re: Encrypted email is still a pain

#447

Earlier quoted context omitted.

I think your group of people would be highly disappointed whenever each person moves to a new device and finds that they have essentially "lost" all old messages and have to re-join groups afresh. > The details don't matter to ordinary people, but our approval matters much more than you think. I have very high hopes for Matrix.org. I agree on this part completely, and I try to introduce better tools to others too. Bu…

matrix e2e is still beta, and we just haven't implemented e2e session sharing yet. you can now export/import keys when migrating between devices as a workaround but proper sharing is coming soon.

I had a brief look at Matrix recently, and I'm really looking forward to it becoming mature. A decentralized solution with emphasis on security and privacy is what I've been praying for not just for myself, but for the sake of all humans!

Re: Encrypted email is still a pain

#448
post #351

Earlier quoted context omitted.

> You control which CAs you anchor your trust to locally. Theoretically, but doesn't it tend to use the same OS infrastructure as HTTPS? > The US Federal Government (FPKI) and US Department of Defense (DOD PKI) use S/MIME heavily. Indeed, but they are in a position to trust the US government (and more generally the international governmental system).

>Indeed, but they are in a position to trust the US government (and more generally the international governmental system). Not sure what trusting the government has to do with it, it has to do with trusting the CA system that's set up on the computer.

> Not sure what trusting the government has to do with it, it has to do with trusting the CA system that's set up on the computer.

Almost all computers ship with a bunch of governments set up as trust roots. It's not impossible to change this, but it's impractical for all but the largest organizations.

Re: Encrypted email is still a pain

#449
post #346

Earlier quoted context omitted.

It's more that a private actor can exclude you from any network. Maybe WhatsApp blacklist you for "abuse". Maybe they're right. But even if you kill someone you're allowed to use the telephone network, and send or receive letters. As long as the message silos aren't regulated as utilities, decentralised systems give us more of the freedoms. It's pretty easy to run a separate dns system - you can even blend your own p…

That's a fair point actually. Does the fact that signal is open source and based on phone numbers change that though? Seems that as long as you have access to the phone network you have access to the signal network...

No, because the servers are still centralised and they can blacklist you at that level.
Post reply on HN