From the white paper, it appears as if this system requires its users to trust the server. That's not end-to-end encryption. What do I have wrong here? Further, it looks like the email encryption provided by this system only works between users of Skiff. At that point, why use email at all? Why not use a real secure messenger? Instead of building an "encrypted email service", you could literally just build an email-f…
Founding engineer at Skiff here. >From the white paper, it appears as if this system requires its users to trust the server. That's not end-to-end encryption. What do I have wrong here? It doesn't. All data is encrypted client side across all apps - Skiff Mail, Drive, Pages, and Calendar. For sending external, the whitepaper is very clear how this case is handled in section 8.2 as securely as possible (without having…
Skiff – Privacy-first end-to-end encrypted email
31–40 of 201 posts
Re: Skiff – Privacy-first end-to-end encrypted email
#32Re: Skiff – Privacy-first end-to-end encrypted email
#33And now I'm seeing Skiff, which is great, it's clear that people want this. I just no longer know who the players in the space are.
Re: Skiff – Privacy-first end-to-end encrypted email
#34Earlier quoted context omitted.
Founding engineer at Skiff here. >From the white paper, it appears as if this system requires its users to trust the server. That's not end-to-end encryption. What do I have wrong here? It doesn't. All data is encrypted client side across all apps - Skiff Mail, Drive, Pages, and Calendar. For sending external, the whitepaper is very clear how this case is handled in section 8.2 as securely as possible (without having…
Section 8.2 seems to talk about how you send plaintext email via SMTP to users who aren't using Skiff. But that's not what I'm talking about with respect to end-to-end encryption. The white paper refers repeatedly to "browser" users. Your server can feed arbitrary Javascript to browsers and subvert encryption in a variety of ways, can't it? I'm still not clear why you designed a new, simplistic cryptosystem at all he…
That's how literally any website works. How do you encrypt in the browser if the server doesn't send JavaScript to encrypt data? You also trust Signal not to issue an update that sends data in plaintext over the network. Unless you're building an app from source, you implicitly trust the developer to some extent.
Re: Skiff – Privacy-first end-to-end encrypted email
#35Re: Skiff – Privacy-first end-to-end encrypted email
#36Re: Skiff – Privacy-first end-to-end encrypted email
#37Earlier quoted context omitted.
Section 8.2 seems to talk about how you send plaintext email via SMTP to users who aren't using Skiff. But that's not what I'm talking about with respect to end-to-end encryption. The white paper refers repeatedly to "browser" users. Your server can feed arbitrary Javascript to browsers and subvert encryption in a variety of ways, can't it? I'm still not clear why you designed a new, simplistic cryptosystem at all he…
> Your server can feed arbitrary Javascript to browsers and subvert encryption in a variety of ways, can't it? That's how literally any website works. How do you encrypt in the browser if the server doesn't send JavaScript to encrypt data? You also trust Signal not to issue an update that sends data in plaintext over the network. Unless you're building an app from source, you implicitly trust the developer to some ex…
Re: Skiff – Privacy-first end-to-end encrypted email
#38Re: Skiff – Privacy-first end-to-end encrypted email
#39So what's the state of the art with respect to end-to-end email these days? Lavabit is back, but it seems like everyone uses Protonmail these days? But didn't they get into some sort of controversy a while back that made some people drop them? And now I'm seeing Skiff, which is great, it's clear that people want this. I just no longer know who the players in the space are.
Host your own + GPG
Re: Skiff – Privacy-first end-to-end encrypted email
#40That would then actually be email rather than not-email-over-smtp.
Another service delegated to trust a 3rd party isn't.