Live data from Hacker News

Convenient End-To-End Encryption for E-Mail

autocrypt.org

141–150 of 190 posts

Re: Convenient End-To-End Encryption for E-Mail

#141
post #124

Earlier quoted context omitted.

> What do you need from Email that a messenger lacks? Discussion threads. Say I work on two different projects with the same colleague, or that I am also friends with a coworker and do things together outside of work. In whatsapp the different topics would all be mixed together into a big mess. With email I can just reply to a particular thread.

Huh, i think you've just identified (for me at least) the crux of the issue. What messaging system other than email allows for topic based discussion? I guess you could abuse groups to donsomething similar, but its not wuite the same. The underlying one person to one person philosophy of messaging apps is infuriating for organised discussion over time. It makes finding info discussed harder too. Does anyone have any…

You might want to check out TMail21 ( https://tmail21.com ). It is thread (topic)-oriented. It also adds shared (versioned) facts to threads which opens up an interesting set of use cases.

Re: Convenient End-To-End Encryption for E-Mail

#143

Earlier quoted context omitted.

Protonmail seems to pull it off. Though at the moment encryption only works inside their system. They are actively working to implement the ability to send secure messages to people outside their service with GPG, though. I believe the CEO said it’d be ready by early 2018.

Please correct me if I'm wrong, but they don't let you search in a protected manner. They enable searching of data they keep unprotected (the metadata so to speak) And proton mail bridge seems to be an "offline" (i.e. offline to them) email search engine that you run yourself, so it downloads your emails, and makes them fully searchable, but to do that, is also keeping them in an insecure state. compare to https://ww…

The local stuff isn’t necessarily insecure (depending on your paranoia level). The security of your computer system is totally unrelated to the encryption of your mail - even with GPG most people are keeping their private key on the same system they use to read their mail. Full disk encryption with something like Veracrypt or bitlocker or file vault or LUKS should be more than enough to keep your decrypted emails safe when you are not using your computer.

Re: Convenient End-To-End Encryption for E-Mail

#144
post #32

Earlier quoted context omitted.

> It's that we should stop using email pretty much altogether. Like I said: it's archaic Sorry but have you ever used Signal or any other IM to send anything longer than a few sentences? Email can be as long as you want, and it is totally appropriate when you want to write a longer document.

Yes, you can write as long a message as you want with signal. There are desktop clients. You can attach files. Or voice messages. Or use it to call them. Or video chat them. It’s a crazy robust full featured incredibly secure communications system.

I don’t know a single person who uses the desktop client, and there’s the rub: it’s fine if I can perfectly render a 1000 word essay on my huge monitor, but not one of my friends will want to read it on their mobile screen.

Re: Convenient End-To-End Encryption for E-Mail

#145
post #112

Earlier quoted context omitted.

I have colleagues and students that don't use smart phones. As much as I agree with your sentiment, the unfortunate truth is that right now there isn't a good drop in replacement that we could move to. Signal is drop in for WhatsApp and I can tell everyone I talk to on WhatsApp to just contact me on Signal instead. What do I tell people to move to from EMail?

WhatsApp is an ok substitute for Email in my opinion. Sure, it is not open source and but federated. Signal, Wire, Matrix, etc should catch up in the next years. What do you need from Email that a messenger lacks?

By far the most important: A desktop client that works without a smart-phone.

Identity management that is not smart-phone/phone-number based.

Better UI for long form messages, including citing previous lines.

Better support for adding people to ongoing conversations.

UI for conversations per topic rather than per person.

Mailing lists, and the ability to filter them to different folders (or equivalent UI elements).

Functioning as a searchable database of documents I have received. (Important detail: Attachments aren't independent messages: They are attached to often long form messages that describe their content).

Basically, WhatsApp does a subset of what EMail does but dramatically better and encrypted. But that covers only half of my email usage at most.

Re: Convenient End-To-End Encryption for E-Mail

#146
post #27
post #22

Earlier quoted context omitted.

Your dimissive post boils down to “less than 100% perfect security is not ‘practicable’ so let’s leave a massively used, default communication platform utterly unsecure.” At least three of your critiques of encrypted email could be made of HTTPS: it leaks metadata (what sites you visit and when), it is plaintext by default, and the archives of the secured material are persistent and searchable. Yet HTTPS is hugely va…

You seem to be relishing this takedown post. I don't want to harsh on that, since I enjoy writing a takedown as much as anyone, but I have to point out that you're attacking an argument I didn't make. It's not my argument that people should use special secure messaging applications when they need security, and email at other times. It's that we should stop using email pretty much altogether. Like I said: it's archaic…

> Which is why a lot of us look at our email inboxes these days and notice that most of what's in there is automated transactional stuff, with occasional cold inbound introductions that quickly transition off into some better medium.

If e-mail was gone tomorrow, where do you think all those automated transactional stuff would go? It won't disappear; suddenly, every business you pass will try to add itself to your contact list on $secure_im_of_choice, and you'll have just about the same volume of spam as on e-mail, just as a condition of being able to do any kind of business on-line.

Re: Convenient End-To-End Encryption for E-Mail

#147
post #8

Unpopular but very probably true fact: email can't practicably be made secure, and people should stop trying. Email is itself archaic, and there aren't good reasons people should use it for routine peer-to-peer communications that need secrecy. Why? Because: * It's default-plaintext. We don't generally love the way websites ensure they're viewed securely, but email doesn't even have the basic mechanisms HTTP has to p…

>Unpopular but very probably true fact

Meta nit: prefacing an argument with this is irritating and is essentially a dressed up "I'll probably get downvoted for saying this."

Don't tempt me to not like a statement ahead of time, just make the damn statement!

Re: Convenient End-To-End Encryption for E-Mail

#148
post #124

Earlier quoted context omitted.

> What do you need from Email that a messenger lacks? Discussion threads. Say I work on two different projects with the same colleague, or that I am also friends with a coworker and do things together outside of work. In whatsapp the different topics would all be mixed together into a big mess. With email I can just reply to a particular thread.

Huh, i think you've just identified (for me at least) the crux of the issue. What messaging system other than email allows for topic based discussion? I guess you could abuse groups to donsomething similar, but its not wuite the same. The underlying one person to one person philosophy of messaging apps is infuriating for organised discussion over time. It makes finding info discussed harder too. Does anyone have any…

>Does anyone have any suggestions for messaging apps that don't put person to person front and center but topic discussion like email?

IRC, Riot (Matrix in general), Slack, Discord, Rocket.Chat. There are quite a few.

I'm partial to Matrix, personally - you can invite a few friends for a room, and naming that room/setting a topic are optional, so either use case is fairly natural.

Re: Convenient End-To-End Encryption for E-Mail

#149
post #8

Unpopular but very probably true fact: email can't practicably be made secure, and people should stop trying. Email is itself archaic, and there aren't good reasons people should use it for routine peer-to-peer communications that need secrecy. Why? Because: * It's default-plaintext. We don't generally love the way websites ensure they're viewed securely, but email doesn't even have the basic mechanisms HTTP has to p…

>Unpopular but very probably true fact Meta nit: prefacing an argument with this is irritating and is essentially a dressed up "I'll probably get downvoted for saying this." Don't tempt me to not like a statement ahead of time, just make the damn statement!

You're right.

Re: Convenient End-To-End Encryption for E-Mail

#150

Earlier quoted context omitted.

I disagree, while also agreeing that IMAPS/SMTP-with-TLS is a huge improvement. The big difference between HTTPS and SMTP is that there's an implicit extra hop. I go to send you an email. I connect to my outgoing mail server over SMTP-with-TLS, and anyone monitoring my connection cannot see the content of the message. Awesome! Likewise, you retrieve the message using IMAPS, and anyone monitoring your connect cannot s…

> But in between, there's absolutely no guarantee that my email provider sent it to your email provider over SMTP-with-TLS. Don't accept non-STARTTLS traffic. Google doesn't, you shouldn't have to either. STARTTLS is widely available, and simply needs to be configured. Encouraging everyone to configure STARTTLS correctly is the easiest win we'll have. And I hope you don't take what I said to mean that IMAPS and SMTP…

Google won't accept inbound mail (from an MTA, not an MUA) that doesn't do STARTTLS? If that's true, I'm both impressed (at their resolve to make the Internet a better place), and concerned that messages from old ISPs that haven't upgraded in a decade won't ever reach my GMail account.
Post reply on HN