Live data from Hacker News

Convenient End-To-End Encryption for E-Mail

autocrypt.org

151–160 of 190 posts

Re: Convenient End-To-End Encryption for E-Mail

#151
post #112

Earlier quoted context omitted.

WhatsApp is an ok substitute for Email in my opinion. Sure, it is not open source and but federated. Signal, Wire, Matrix, etc should catch up in the next years. What do you need from Email that a messenger lacks?

I guess you only use a cellphone then. Whatsapp desktop/web is terribly slow and requires your cellphone to be on at all times. Also, you cannot have whatsapp desktop/web active on more than one computer at any time. Also, I do have several identities (work, leisure, even one-offs for website registration/communications) and no, I don't want to give my personal cell number to everyone.

> Whatsapp desktop/web is terribly slow and requires your cellphone to be on at all times.

They have a rather sound reason for the cellphone requirement, though. It's because the messages are stored only there and the desktop/web application is just a gateway to your phone.

https://faq.whatsapp.com/en/web/28080002

This seems like a more secure way to do it than what the others do, which is to store the messages in their servers.

Re: Convenient End-To-End Encryption for E-Mail

#152
post #77

Earlier quoted context omitted.

I agree with you on everything here except for your "don't use email" point in the followups. For 99+% of people, being able to recover your archive when you forget your password or lose your device is more valuable than being secure against a state-level adversary. I think the security debate around email suffers from an over-supply of confidentiality absolutists, in which both integrity and availability take the ba…

Indeed just getting most senders and servers to use TLS would be a good start. That said, lots of businesses deal with sophisticated attackers who are trying to steal trade secrets, patents in progress, etc. Sometimes these attackers are state sponsored too (I would definitely suspect China, US and Russia for this kind of crimes).

Secure cryptographic end-to-end protocols have a fun way of making it harder to actually run restricted, secure networks, because it makes enforcing content-based policies rather interesting.

Re: Convenient End-To-End Encryption for E-Mail

#153
post #151

Earlier quoted context omitted.

I guess you only use a cellphone then. Whatsapp desktop/web is terribly slow and requires your cellphone to be on at all times. Also, you cannot have whatsapp desktop/web active on more than one computer at any time. Also, I do have several identities (work, leisure, even one-offs for website registration/communications) and no, I don't want to give my personal cell number to everyone.

> Whatsapp desktop/web is terribly slow and requires your cellphone to be on at all times. They have a rather sound reason for the cellphone requirement, though. It's because the messages are stored only there and the desktop/web application is just a gateway to your phone. https://faq.whatsapp.com/en/web/28080002 This seems like a more secure way to do it than what the others do, which is to store the messages in th…

Yes, but it means it will never be an email replacement.

The people without smartphones that I work with can use email.

I can get to my email anywhere, everywhere, whether I have a phone or not.

Of course that may be considered an anti-feature from the point of view of security, but it explains why IM apps can not replace email.

Re: Convenient End-To-End Encryption for E-Mail

#154
post #109

Earlier quoted context omitted.

>Is there another communication system that is decentralized (...), and is also widely used? XMPP, maybe?

In rhe Eastern Europe XMPP is widely used for online drug purchases, even widely than telegram, which unlike XMPP requires burner phone to register.

Is this an argument against any decentralized communications?

Re: Convenient End-To-End Encryption for E-Mail

#155
post #8

Unpopular but very probably true fact: email can't practicably be made secure, and people should stop trying. Email is itself archaic, and there aren't good reasons people should use it for routine peer-to-peer communications that need secrecy. Why? Because: * It's default-plaintext. We don't generally love the way websites ensure they're viewed securely, but email doesn't even have the basic mechanisms HTTP has to p…

Intra-organizational email is pretty secure. Like where I work, we’re all on gmail with client carts.

How using Gmail could be called secure? According to Snowden docs Google is cooperating with N/S/A. So all your data is collected and stored for future analysis when needed. If you consider this to be "secure" then the whole discussion on security is pointless.

Re: Convenient End-To-End Encryption for E-Mail

#157

Metadata is more important than content. Metadata is surveillance. There is no way to hide metadata with computers. The only way to get around this is through anonymity. You put the info out there, but it can't be correlated to you by someone else except your intended recipient. This is approaching impossible even with the best, security-minded infosec professional. The safeguards you need to employ are very extraord…

Tackling header privacy is harder in an existing platform. Memoryhole ( https://github.com/autocrypt/memoryhole ) has some ideas but it's some way off implementation right now.

Re: Convenient End-To-End Encryption for E-Mail

#158
post #116

Earlier quoted context omitted.

Here is something that I have a need of pretty often, but don't know how to do in things outside email (Whatsapp, Signal, etc): a point by point interleaving of the original message and the reply; for instance in a technical argument. I could do this in Slack, but unlike email this is not even close to being universally supported.

For such technical discussions, I prefer an issue tracker, wiki, or forum. It should be a centralized searchable archive and not hidden in personal mailboxes. Sure, you can use email as an interface to an issue tracker. Debian is probably the most prominent example. That is worse than anything web-based in my opinion.

That answer isn't workable for those of us in shorter term projects which lack that sort of infrastructure. The need remains for a flexible messaging system to take over for those kinds of messages that need some permanence. It sounds like what people familiar with email workflow want is the email a document interface so we have something tho point to after the fact. I don't think anything else does that though Wire may at some point.

Re: Convenient End-To-End Encryption for E-Mail

#159
post #96
post #8

Unpopular but very probably true fact: email can't practicably be made secure, and people should stop trying. Email is itself archaic, and there aren't good reasons people should use it for routine peer-to-peer communications that need secrecy. Why? Because: * It's default-plaintext. We don't generally love the way websites ensure they're viewed securely, but email doesn't even have the basic mechanisms HTTP has to p…

Unfortunately, Signal is not decentralized or federated (for good reasons[1]). Email is. This is an important feature for those of us who worry about the growing centralization of the web, as well as the very many users who still mainly use email for communication. When you leave a job, you may not keep your email address, but at least you can still communicate with people across organizational boundaries. Anyway, ev…

> Anyway, even if email security cannot be perfect, I agree with the sentiment behind RFC 7435[2] - some protection is better than nothing.

Opportunistic encryption (or any kind of negotiable security) is prone to downgrades by a MITM. Either both sides require strong security, or you must assume lowest common denominator.

While I have your attention, please do yourself a favor and pin some strong, modern ciphers for your SSH client: https://wiki.mozilla.org/Security/Guidelines/OpenSSH#Modern

Re: Convenient End-To-End Encryption for E-Mail

#160

Earlier quoted context omitted.

Please correct me if I'm wrong, but they don't let you search in a protected manner. They enable searching of data they keep unprotected (the metadata so to speak) And proton mail bridge seems to be an "offline" (i.e. offline to them) email search engine that you run yourself, so it downloads your emails, and makes them fully searchable, but to do that, is also keeping them in an insecure state. compare to https://ww…

The local stuff isn’t necessarily insecure (depending on your paranoia level). The security of your computer system is totally unrelated to the encryption of your mail - even with GPG most people are keeping their private key on the same system they use to read their mail. Full disk encryption with something like Veracrypt or bitlocker or file vault or LUKS should be more than enough to keep your decrypted emails saf…

My guess is that bridge is run as a service. i.e. you make reuests via web site which are encrypted with local javascript (so that proton mail can't interpose), protonmail forwards to the service user runs which provides an encrypted response which local javascript then decrypts and displays.

In that case, you have to run a service that is always running that is effectively keeping the e-mails available in the clear. Is it better security than keeping them in the clear on a central server? sure. But is it really any different than running my own smtp/imap/webmail server on aws without encrypting any emails which I access? In practice it would seem to be a similar threat model and I'm not convinced many would view that to be particularly secure, just a tad more private.

Post reply on HN