Earlier quoted context omitted.
Forcing iMessage to open will immediately result in MITM iMessage proxies that users can use to store iMessages that are meant to auto-delete, so that they can violate the wishes of the other party. These do not exist today because Apple binds iMessage to your hardware and bans your entire device when anyone is found to be operating such a service, either for themselves or others. Do you want open source clients that…
You can violate the wishes of the other party by taking a screenshot or, in the extreme, a photo of the screen. You're only preventing the very lazy/unmotivated from retaining messages.
The PGP Problem
101–110 of 369 posts
Re: The PGP Problem
#102Earlier quoted context omitted.
Forcing iMessage to open will immediately result in MITM iMessage proxies that users can use to store iMessages that are meant to auto-delete, so that they can violate the wishes of the other party. These do not exist today because Apple binds iMessage to your hardware and bans your entire device when anyone is found to be operating such a service, either for themselves or others. Do you want open source clients that…
iMessage doesn't have any kind of auto deleted messages - it's a feature that messages are persistent across all your devices.
Re: The PGP Problem
#103So what do I use for encrypted messaging that can, like, replace email, then? Nobody seems to have provided any sort of satisfactory answer to this question. To be clear, an answer this has to not just be a secure way of sending messages, it also has to replicate the social affordances of email. E.g., things distinguishing how email is used from how text-messaging is used: 1. Email is potentially long-form. I sit dow…
I don't get what's insecure about normal unencrypted email. It's sent over https, isn't it? It's not like I can read your emails unless I break into Google's servers, no? And even if I do, they probably aren't even stored in plaintext. I just don't get the encrypted email obsession. It's impossible for an individual to withstand a targetted cyber attack so it seems pointless to go above and beyond to ultra encrypt ev…
Re: The PGP Problem
#104Earlier quoted context omitted.
Good question. Not sure. Although I don't see why I wouldn't, if they have a PGP key listed? (I guess there is some question over whether the listed key is actually them?) But my point is that, well, email is a good way to do that, and Signal isn't, so I'm going to use email rather than Signal. Honestly, I wouldn't focus on (3), because as I see it, if you can replicate the feel of email, things like (1)-(2), so that…
How does one list a public PGP key, is there a verified central listing service?
Re: The PGP Problem
#105Earlier quoted context omitted.
> And then I would be _very_ surprised if google doesn't use the content of your emails for advertisement and tracking purposes. That would go against their own privacy policy. But they are one change away from doing it.
Really? When gmail came out they were explicitly up front about using the content of the email to deliver targeted ads. Has that changed?
Re: The PGP Problem
#106Really, all I did here was combine posts from Matthew Green, Filippo Valsorda, and George Tankersley into one post, and then talk to my partner LVH about it. So blame them. (also 'pvg, who said i should write this, and it's been nagging at me ever since)
What are your thoughts on Keybase as a secure Slack replacement?
It's getting better, but not close being business ready imo.
Re: The PGP Problem
#107This is not really helpful. For all its shortcomings, PGP is pretty much all we have. If used in a straightforward way it actually can protect email from nation state level actors for a significant time. That's gotta count for something.
Re: The PGP Problem
#108Really, all I did here was combine posts from Matthew Green, Filippo Valsorda, and George Tankersley into one post, and then talk to my partner LVH about it. So blame them. (also 'pvg, who said i should write this, and it's been nagging at me ever since)
The closest advice to this in the article would be "use Signal" which has various issues of its own, unrelated to crypto: it has Signal Foundation as a SPOF and its ID mechanism is outright wonky, as phone numbers are IDs that are location bound, hard to manage multiple for a person, hard to manage multiple persons per ID, hard to roll over.
To me that seems to be a much bigger issue than "encrypting files for purposes that aren't {all regular purposes}".
Re: The PGP Problem
#109Earlier quoted context omitted.
Why not? I mean, that's what publicly listing your public key is for, right?
Nope. I have at least three public never-expiring keys that I am unable revoke and that remain listed as valid because the keyservers don’t occasionally revalidate proof of ability to decrypt.
[0]How it caused a problem: I added an email address to my public key (or maybe it expired or something, I forget), and asked people to refresh their copy of my key. One person instead downloaded it entirely anew from a keyserver and got the old one. Oops. (Admittedly I didn't explicitly use the word "refresh".) Anyway yeah -- though this problem had happened to me, it hadn't ocurred to me that it might be common; maybe this is more of a problem than I thought...
Re: The PGP Problem
#110Earlier quoted context omitted.
> And then I would be _very_ surprised if google doesn't use the content of your emails for advertisement and tracking purposes. That would go against their own privacy policy. But they are one change away from doing it.
Really? When gmail came out they were explicitly up front about using the content of the email to deliver targeted ads. Has that changed?
https://safety.google/privacy/ads-and-data/
> Google does not use keywords or messages in your inbox to show you ads. Nobody reads your email in order to show you ads.