Live data from Hacker News

Convenient End-To-End Encryption for E-Mail

autocrypt.org

111–120 of 190 posts

Re: Convenient End-To-End Encryption for E-Mail

#111
post #27
post #22

Earlier quoted context omitted.

Your dimissive post boils down to “less than 100% perfect security is not ‘practicable’ so let’s leave a massively used, default communication platform utterly unsecure.” At least three of your critiques of encrypted email could be made of HTTPS: it leaks metadata (what sites you visit and when), it is plaintext by default, and the archives of the secured material are persistent and searchable. Yet HTTPS is hugely va…

You seem to be relishing this takedown post. I don't want to harsh on that, since I enjoy writing a takedown as much as anyone, but I have to point out that you're attacking an argument I didn't make. It's not my argument that people should use special secure messaging applications when they need security, and email at other times. It's that we should stop using email pretty much altogether. Like I said: it's archaic…

I have colleagues and students that don't use smart phones. As much as I agree with your sentiment, the unfortunate truth is that right now there isn't a good drop in replacement that we could move to.

Signal is drop in for WhatsApp and I can tell everyone I talk to on WhatsApp to just contact me on Signal instead. What do I tell people to move to from EMail?

Re: Convenient End-To-End Encryption for E-Mail

#112
post #27

Earlier quoted context omitted.

You seem to be relishing this takedown post. I don't want to harsh on that, since I enjoy writing a takedown as much as anyone, but I have to point out that you're attacking an argument I didn't make. It's not my argument that people should use special secure messaging applications when they need security, and email at other times. It's that we should stop using email pretty much altogether. Like I said: it's archaic…

I have colleagues and students that don't use smart phones. As much as I agree with your sentiment, the unfortunate truth is that right now there isn't a good drop in replacement that we could move to. Signal is drop in for WhatsApp and I can tell everyone I talk to on WhatsApp to just contact me on Signal instead. What do I tell people to move to from EMail?

WhatsApp is an ok substitute for Email in my opinion.

Sure, it is not open source and but federated. Signal, Wire, Matrix, etc should catch up in the next years.

What do you need from Email that a messenger lacks?

Re: Convenient End-To-End Encryption for E-Mail

#113
post #105
post #27

Earlier quoted context omitted.

You seem to be relishing this takedown post. I don't want to harsh on that, since I enjoy writing a takedown as much as anyone, but I have to point out that you're attacking an argument I didn't make. It's not my argument that people should use special secure messaging applications when they need security, and email at other times. It's that we should stop using email pretty much altogether. Like I said: it's archaic…

> a lot of us look at our email inboxes these days and notice that most of what's in there is automated transactional stuff, with occasional cold inbound introductions that quickly transition off into some better medium Just wanted to point out: that's certainly not true for everyone. The overwhelming majority of my work communication is done by email, and an important part of my social communication with friends and…

>Just wanted to point out: that's certainly not true for everyone.

Very true. I use email for almost all my communication. It's not because I refuse to use anything else. I'm very much open to better solutions. But messengers linked to phone numbers can never be that solution for me.

Phone numbers come with way too many strings attached. They are country specifc. They can only be linked to one SIM card and one device at a time and that is almost never the device I want to use for written communication. They are subject to onerous contractual agreements and restrictions imposed by phone companies. By default, they allow everyone to call me. I don't usually want to be called on the phone.

Re: Convenient End-To-End Encryption for E-Mail

#114
post #109
post #105

Earlier quoted context omitted.

> a lot of us look at our email inboxes these days and notice that most of what's in there is automated transactional stuff, with occasional cold inbound introductions that quickly transition off into some better medium Just wanted to point out: that's certainly not true for everyone. The overwhelming majority of my work communication is done by email, and an important part of my social communication with friends and…

>Is there another communication system that is decentralized (...), and is also widely used? XMPP, maybe?

In rhe Eastern Europe XMPP is widely used for online drug purchases, even widely than telegram, which unlike XMPP requires burner phone to register.

Re: Convenient End-To-End Encryption for E-Mail

#115
post #32
post #27

Earlier quoted context omitted.

You seem to be relishing this takedown post. I don't want to harsh on that, since I enjoy writing a takedown as much as anyone, but I have to point out that you're attacking an argument I didn't make. It's not my argument that people should use special secure messaging applications when they need security, and email at other times. It's that we should stop using email pretty much altogether. Like I said: it's archaic…

> It's that we should stop using email pretty much altogether. Like I said: it's archaic Sorry but have you ever used Signal or any other IM to send anything longer than a few sentences? Email can be as long as you want, and it is totally appropriate when you want to write a longer document.

How often do you send emails longer than a few sentences?

I don't really see a problem with long messages on Signal. The only annoyance is that the desktop clients are always browser-based (Electron or website or plugin).

Re: Convenient End-To-End Encryption for E-Mail

#116
post #41

Earlier quoted context omitted.

Yes, I've used Signal and other messengers, including "IM's", to send things longer than a sentence. And, when I send email to people, if I have something more complicated than a paragraph or two to send, I make an actual document anyways. So what's your argument?

Here is something that I have a need of pretty often, but don't know how to do in things outside email (Whatsapp, Signal, etc): a point by point interleaving of the original message and the reply; for instance in a technical argument. I could do this in Slack, but unlike email this is not even close to being universally supported.

For such technical discussions, I prefer an issue tracker, wiki, or forum. It should be a centralized searchable archive and not hidden in personal mailboxes.

Sure, you can use email as an interface to an issue tracker. Debian is probably the most prominent example. That is worse than anything web-based in my opinion.

Re: Convenient End-To-End Encryption for E-Mail

#117
post #104

Earlier quoted context omitted.

Yes, you can write as long a message as you want with signal. There are desktop clients. You can attach files. Or voice messages. Or use it to call them. Or video chat them. It’s a crazy robust full featured incredibly secure communications system.

It's a centralized system, with a single point of failure, and you cannot use it without a phone number.

Then use Matrix or wait for Wire to open-source and federate, but securing email has failed for decades now.

Re: Convenient End-To-End Encryption for E-Mail

#118

Earlier quoted context omitted.

The email address format is so useful for domain-based identity. We still haven't squared Zooko's Triangle. What is the practical way to get a function like "document was sent with best effort for some legal purpose to a known party"? Are we just stuck with "login to the secure messaging site" emails from our banks?

> The email address format is so useful for domain-based identity. Agreed. But this is also where the problems of spam begin. Perhaps if we chose to 'phase out' MX records in DNS for something new, say 'MSG'. A domain could then have an MX as well as a MSG server... A local MTA would route to the 'new shiny messaging system', so that clients could use the one system to read emails. Remote MTAs could also lookup and s…

Bayesian filters solved this problem.

My only email volume problem anymore is entirely opt-in / self inflicted. Some percentage of global bandwidth is still wasted on spam, but it is a vanishingly small proportion of traffic for that to matter anymore. ¯\_(ツ)_/¯

Re: Convenient End-To-End Encryption for E-Mail

#119
post #112

Earlier quoted context omitted.

I have colleagues and students that don't use smart phones. As much as I agree with your sentiment, the unfortunate truth is that right now there isn't a good drop in replacement that we could move to. Signal is drop in for WhatsApp and I can tell everyone I talk to on WhatsApp to just contact me on Signal instead. What do I tell people to move to from EMail?

WhatsApp is an ok substitute for Email in my opinion. Sure, it is not open source and but federated. Signal, Wire, Matrix, etc should catch up in the next years. What do you need from Email that a messenger lacks?

I guess you only use a cellphone then.

Whatsapp desktop/web is terribly slow and requires your cellphone to be on at all times. Also, you cannot have whatsapp desktop/web active on more than one computer at any time.

Also, I do have several identities (work, leisure, even one-offs for website registration/communications) and no, I don't want to give my personal cell number to everyone.

Re: Convenient End-To-End Encryption for E-Mail

#120
post #96
post #8

Unpopular but very probably true fact: email can't practicably be made secure, and people should stop trying. Email is itself archaic, and there aren't good reasons people should use it for routine peer-to-peer communications that need secrecy. Why? Because: * It's default-plaintext. We don't generally love the way websites ensure they're viewed securely, but email doesn't even have the basic mechanisms HTTP has to p…

Unfortunately, Signal is not decentralized or federated (for good reasons[1]). Email is. This is an important feature for those of us who worry about the growing centralization of the web, as well as the very many users who still mainly use email for communication. When you leave a job, you may not keep your email address, but at least you can still communicate with people across organizational boundaries. Anyway, ev…

Webmail is indeed a very tricky one. Mailvelope does a fairly good job, but without some provider support that allows setting/reading headers and sending custom mime parts, there is sadly no good way to solve this problem.
Post reply on HN