Earlier quoted context omitted.
The thing is, there's different degrees of failure. You can make email much more secure than it already is for a massive amount of users without sacrificing user experience. Just because it's not possible to make email the most perfectly secure messaging system invented by man doesn't mean we shouldn't make it more secure.
[CITATION NEEDED] as they say. Email providers are doing things like that - TLS encryption between systems is a legit improvement with no significant downsides. And there's work on improving that: https://tools.ietf.org/wg/uta/ (SMTP-STS, SMTP-REQUIRETLS, etc) And nobody's objecting to that. People are objecting to the idea of changing email to be a dumb blob payload transport for encrypted blobs, because: (a) you ca…
Convenient End-To-End Encryption for E-Mail
91–100 of 190 posts
Re: Convenient End-To-End Encryption for E-Mail
#92Earlier quoted context omitted.
An individual server-to-server communication happens in milliseconds, but these systems layer on top of existing email clients, which do not have a polling interval of milliseconds. I wouldn't hold your breath on email crypto from Moxie.
I don't think you know how Signal or the underlying protocol works based on this comment, so I'll just leave the discussion there. Feel free to read the specification. It's quite comprehensible and well-written.
Re: Convenient End-To-End Encryption for E-Mail
#93Earlier quoted context omitted.
> It's that we should stop using email pretty much altogether. Like I said: it's archaic Sorry but have you ever used Signal or any other IM to send anything longer than a few sentences? Email can be as long as you want, and it is totally appropriate when you want to write a longer document.
Yes, I've used Signal and other messengers, including "IM's", to send things longer than a sentence. And, when I send email to people, if I have something more complicated than a paragraph or two to send, I make an actual document anyways. So what's your argument?
I could do this in Slack, but unlike email this is not even close to being universally supported.
Re: Convenient End-To-End Encryption for E-Mail
#94Earlier quoted context omitted.
Please correct me if I'm wrong, but they don't let you search in a protected manner. They enable searching of data they keep unprotected (the metadata so to speak) And proton mail bridge seems to be an "offline" (i.e. offline to them) email search engine that you run yourself, so it downloads your emails, and makes them fully searchable, but to do that, is also keeping them in an insecure state. compare to https://ww…
I can search full text of my email on Protonmail. At least I'm pretty sure that's what I'm doing.
Re: Convenient End-To-End Encryption for E-Mail
#95Unpopular but very probably true fact: email can't practicably be made secure, and people should stop trying. Email is itself archaic, and there aren't good reasons people should use it for routine peer-to-peer communications that need secrecy. Why? Because: * It's default-plaintext. We don't generally love the way websites ensure they're viewed securely, but email doesn't even have the basic mechanisms HTTP has to p…
E-Mails are mostly used for work-related information exchange. Those emails are usually sent from a PC in some corporate setting. The IT departments could enforce the use of encryption but nobody cares -- maybe also because management isn't aware of how email works and doesn't care until it is forced to.
Re: Convenient End-To-End Encryption for E-Mail
#96Unpopular but very probably true fact: email can't practicably be made secure, and people should stop trying. Email is itself archaic, and there aren't good reasons people should use it for routine peer-to-peer communications that need secrecy. Why? Because: * It's default-plaintext. We don't generally love the way websites ensure they're viewed securely, but email doesn't even have the basic mechanisms HTTP has to p…
Anyway, even if email security cannot be perfect, I agree with the sentiment behind RFC 7435[2] - some protection is better than nothing.
If anything, I feel that they didn't go far enough in this compromise. Most people interact with their email through the provider's webmail client. Autocrypt is fundamentally incompatible with this[3]. This means that it will really not be useful for the majority of users.
1: https://signal.org/blog/the-ecosystem-is-moving/
2: https://tools.ietf.org/html/rfc7435.html
3: https://autocrypt.org/level1.html#requirements-on-mua-e-mail...
Re: Convenient End-To-End Encryption for E-Mail
#97Unpopular but very probably true fact: email can't practicably be made secure, and people should stop trying. Email is itself archaic, and there aren't good reasons people should use it for routine peer-to-peer communications that need secrecy. Why? Because: * It's default-plaintext. We don't generally love the way websites ensure they're viewed securely, but email doesn't even have the basic mechanisms HTTP has to p…
> tptacek
> Unpopular but very probably true fact: email can't
practicably be made secure, and people should stop trying. E
Why is this childish stupid comment on top? Ah right he has such high karma point ratio, the troll stays on top and can't be downvoted enough. Comment system broken.Re: Convenient End-To-End Encryption for E-Mail
#98Unpopular but very probably true fact: email can't practicably be made secure, and people should stop trying. Email is itself archaic, and there aren't good reasons people should use it for routine peer-to-peer communications that need secrecy. Why? Because: * It's default-plaintext. We don't generally love the way websites ensure they're viewed securely, but email doesn't even have the basic mechanisms HTTP has to p…
Your individual concerns are all valid, but that doesn't mean they come together to make a compelling argument that email will always be horribly insecure. Heck, you could probably take most of the points in the parent comment, change a few words, and have a pretty solid argument to take back to 2008 and convince everyone that mobile device messaging will never be secure.
There's nothing inherent to the concept of "email" that says we have to use any of these individual flawed components, or that we have to use them together in exactly the same way as we're doing now. For example - What's to stop somebody from taking the Signal code and hacking up support for a mail client that uses Signal with SMTP as the transport?
Re: Convenient End-To-End Encryption for E-Mail
#99Earlier quoted context omitted.
You seem to be relishing this takedown post. I don't want to harsh on that, since I enjoy writing a takedown as much as anyone, but I have to point out that you're attacking an argument I didn't make. It's not my argument that people should use special secure messaging applications when they need security, and email at other times. It's that we should stop using email pretty much altogether. Like I said: it's archaic…
I think it's naive to expect email to be replaced any time soon. Despite all the attempts over the years, it remains and persists. There are essentially no major ongoing efforts to replace it by any of the big players, which is what would be required. IM is not a substitute and never will be.
There are use cases for all of the different methods and the level of security you require will usually dictate what methods you employ when it comes time to transmit any certain type of given message. The substitutes work for us based on convenience and preference and, for the most part, most people don't truly need secured end-to-end encryption for their daily correspondence (even though I personally think it would be a great habit to get into before it's an absolute requirement to ensure personal / private / public safety).
Things like Signal are steps in the right direction but I only see a few notifications a month about friends and family joining. I'm not seeing rapid enough adoption from the "every (wo)man" to indicate that the public at large sees the need for end-to-end encryption, yet. Since we already got Snowden's revelations I'm not sure that time will ever come. Frustrating, it is.
Re: Convenient End-To-End Encryption for E-Mail
#100Earlier quoted context omitted.
I can search full text of my email on Protonmail. At least I'm pretty sure that's what I'm doing.
Pretty sure you're searching the "metadata", who, when, subject https://protonmail.com/support/knowledge-base/search/
In the longer term / larger scale, it's not going to be sufficient though.