Live data from Hacker News

Email encryption is here – use STARTTLS everywhere

dwheeler.com

1–10 of 74 posts

Re: Email encryption is here – use STARTTLS everywhere

#3
post #2

Sure, STARTTLS is better than nothing, but your email provider still reads your email. When we talk about email encryption, we mean end-to-end encryption.

> STARTTLS is not an end-to-end encryption system. [...] But for various reasons it’s hard to deploy end-to-end email encryption, and we’ve spent decades trying. Also, STARTTLS works just fine with end-to-end encryption.

> Please indulge me: I think a small rant is appropriate here. There are some security specialists who think that only the perfect is acceptable. Nonsense! Requiring perfection is crazy. [...] For almost all users, email encryption with STARTTLS is a major improvement over what they had before. Let’s keep working to deploy even better systems, but let’s take partial victories where we can get them.

Re: Email encryption is here – use STARTTLS everywhere

#4
Between this and SMS, the NSA (et al) had a gold mine of data when they directly tapped the lines.

I remember reading they were really upset when this email providers started using this by default... always a good sign when warrantless/dragnet surveillance is made harder.

Re: Email encryption is here – use STARTTLS everywhere

#5
post #3
post #2

Sure, STARTTLS is better than nothing, but your email provider still reads your email. When we talk about email encryption, we mean end-to-end encryption.

> STARTTLS is not an end-to-end encryption system. [...] But for various reasons it’s hard to deploy end-to-end email encryption, and we’ve spent decades trying. Also, STARTTLS works just fine with end-to-end encryption. > Please indulge me: I think a small rant is appropriate here. There are some security specialists who think that only the perfect is acceptable. Nonsense! Requiring perfection is crazy. [...] For al…

[deleted]

Re: Email encryption is here – use STARTTLS everywhere

#6
post #2

Sure, STARTTLS is better than nothing, but your email provider still reads your email. When we talk about email encryption, we mean end-to-end encryption.

So you are saying you do not trust your e-mail provider to secure your email. At that point I suggest finding another provider or running your own service. This secures a significant point of interception and modification of data.

Re: Email encryption is here – use STARTTLS everywhere

#7
post #6
post #2

Sure, STARTTLS is better than nothing, but your email provider still reads your email. When we talk about email encryption, we mean end-to-end encryption.

So you are saying you do not trust your e-mail provider to secure your email. At that point I suggest finding another provider or running your own service. This secures a significant point of interception and modification of data.

In general, if a government asks your provider for access to your emails then will hand them over. The only way to mitigate this threat is to use e2e encryption or host the email server on premises but then you start encountering deliverability issues.

Re: Email encryption is here – use STARTTLS everywhere

#8
post #2

Sure, STARTTLS is better than nothing, but your email provider still reads your email. When we talk about email encryption, we mean end-to-end encryption.

I am my own provider. It's really not that hard to configure a mail server. Other peoples' providers, however... so I tried using PGP. It's somehow manages to be more difficult to use than configuring and running your own mailsystem which doesn't deliver straight to gmails' spam folder, but I digress; but then my emails are at mercy of the end devices: who knows if outlook doesn't send a plaintext email home as "telemetry"? Same thing about chrome with all the extensions for using PGP... I mean, security is hard as-is, but security of an ubiquitous thing, especially when people have been conditioned to undervalue security and privacy, is a lost cause. It's best to treat emails as being in the same category as phone calls, conversations in subway and sms'es - public.

Re: Email encryption is here – use STARTTLS everywhere

#10
post #7
post #6

Earlier quoted context omitted.

So you are saying you do not trust your e-mail provider to secure your email. At that point I suggest finding another provider or running your own service. This secures a significant point of interception and modification of data.

In general, if a government asks your provider for access to your emails then will hand them over. The only way to mitigate this threat is to use e2e encryption or host the email server on premises but then you start encountering deliverability issues.

That's FUD. If a system is correctly set up, you'll have no deliverability issues.

Edit: srsly guys, HACKER news people say that it's impossible for a person to have a proper mailserver set up? That's hilarious, if not sad!

Post reply on HN