Live data from Hacker News

Skiff – Privacy-first end-to-end encrypted email

skiff.com

31–40 of 201 posts

Re: Skiff – Privacy-first end-to-end encrypted email

#31
post #21

From the white paper, it appears as if this system requires its users to trust the server. That's not end-to-end encryption. What do I have wrong here? Further, it looks like the email encryption provided by this system only works between users of Skiff. At that point, why use email at all? Why not use a real secure messenger? Instead of building an "encrypted email service", you could literally just build an email-f…

Founding engineer at Skiff here. >From the white paper, it appears as if this system requires its users to trust the server. That's not end-to-end encryption. What do I have wrong here? It doesn't. All data is encrypted client side across all apps - Skiff Mail, Drive, Pages, and Calendar. For sending external, the whitepaper is very clear how this case is handled in section 8.2 as securely as possible (without having…

It really is not backed by cryptographic security at all. Since your server has access to plaintext emails when sending and recieving (99.99999% of email addresses would be outside skiff), which completely subverts the whole point of encryption. A vulnerability on the server could leak all user emails, without needing their keys.... This is a solution theoretically only as strong as encryption at rest.

Re: Skiff – Privacy-first end-to-end encrypted email

#33
So what's the state of the art with respect to end-to-end email these days? Lavabit is back, but it seems like everyone uses Protonmail these days? But didn't they get into some sort of controversy a while back that made some people drop them?

And now I'm seeing Skiff, which is great, it's clear that people want this. I just no longer know who the players in the space are.

Re: Skiff – Privacy-first end-to-end encrypted email

#34
post #29

Earlier quoted context omitted.

Founding engineer at Skiff here. >From the white paper, it appears as if this system requires its users to trust the server. That's not end-to-end encryption. What do I have wrong here? It doesn't. All data is encrypted client side across all apps - Skiff Mail, Drive, Pages, and Calendar. For sending external, the whitepaper is very clear how this case is handled in section 8.2 as securely as possible (without having…

Section 8.2 seems to talk about how you send plaintext email via SMTP to users who aren't using Skiff. But that's not what I'm talking about with respect to end-to-end encryption. The white paper refers repeatedly to "browser" users. Your server can feed arbitrary Javascript to browsers and subvert encryption in a variety of ways, can't it? I'm still not clear why you designed a new, simplistic cryptosystem at all he…

> Your server can feed arbitrary Javascript to browsers and subvert encryption in a variety of ways, can't it?

That's how literally any website works. How do you encrypt in the browser if the server doesn't send JavaScript to encrypt data? You also trust Signal not to issue an update that sends data in plaintext over the network. Unless you're building an app from source, you implicitly trust the developer to some extent.

Re: Skiff – Privacy-first end-to-end encrypted email

#37
post #29

Earlier quoted context omitted.

Section 8.2 seems to talk about how you send plaintext email via SMTP to users who aren't using Skiff. But that's not what I'm talking about with respect to end-to-end encryption. The white paper refers repeatedly to "browser" users. Your server can feed arbitrary Javascript to browsers and subvert encryption in a variety of ways, can't it? I'm still not clear why you designed a new, simplistic cryptosystem at all he…

> Your server can feed arbitrary Javascript to browsers and subvert encryption in a variety of ways, can't it? That's how literally any website works. How do you encrypt in the browser if the server doesn't send JavaScript to encrypt data? You also trust Signal not to issue an update that sends data in plaintext over the network. Unless you're building an app from source, you implicitly trust the developer to some ex…

Signal doesn’t have a web client. Most of the stores it is distributed through have fairly strong resistance to compel orders.

Re: Skiff – Privacy-first end-to-end encrypted email

#39

So what's the state of the art with respect to end-to-end email these days? Lavabit is back, but it seems like everyone uses Protonmail these days? But didn't they get into some sort of controversy a while back that made some people drop them? And now I'm seeing Skiff, which is great, it's clear that people want this. I just no longer know who the players in the space are.

>what's the state of the art with respect to end-to-end email these days?

Host your own + GPG

Post reply on HN