Live data from Hacker News

Skiff – Privacy-first end-to-end encrypted email

skiff.com

71–80 of 201 posts

Re: Skiff – Privacy-first end-to-end encrypted email

#71
post #67

Earlier quoted context omitted.

Open source does not mean anything in the first place. Terms like Libre or Free Software exist for a reason.

"Open source" is defined by this page, which has been around since the 1990s: https://opensource.org/osd/

Yet it is so poorly understood and you see open source mentioned like here when its not meeting such definition. The name is just plain bad.

Re: Skiff – Privacy-first end-to-end encrypted email

#72
post #66
post #29

Earlier quoted context omitted.

Section 8.2 seems to talk about how you send plaintext email via SMTP to users who aren't using Skiff. But that's not what I'm talking about with respect to end-to-end encryption. The white paper refers repeatedly to "browser" users. Your server can feed arbitrary Javascript to browsers and subvert encryption in a variety of ways, can't it? I'm still not clear why you designed a new, simplistic cryptosystem at all he…

What do you think of Lavabit? I think they operated in the same way, but the US government forced them out of business for refusing to hand over their TLS keys to allow the US to spy on Snowden. https://en.wikipedia.org/wiki/Lavabit

Lavabit is the one that used user passwords to encrypt the messages, thus ensuring that they had access to all the necessary secrets to decrypt user messages any time the user was viewing them?

And that had complied previously with US government subpoenas to provide metadata and data for users?

Re: Skiff – Privacy-first end-to-end encrypted email

#73
post #72
post #66

Earlier quoted context omitted.

What do you think of Lavabit? I think they operated in the same way, but the US government forced them out of business for refusing to hand over their TLS keys to allow the US to spy on Snowden. https://en.wikipedia.org/wiki/Lavabit

Lavabit is the one that used user passwords to encrypt the messages, thus ensuring that they had access to all the necessary secrets to decrypt user messages any time the user was viewing them? And that had complied previously with US government subpoenas to provide metadata and data for users?

+1

Re: Skiff – Privacy-first end-to-end encrypted email

#74
post #66
post #29

Earlier quoted context omitted.

Section 8.2 seems to talk about how you send plaintext email via SMTP to users who aren't using Skiff. But that's not what I'm talking about with respect to end-to-end encryption. The white paper refers repeatedly to "browser" users. Your server can feed arbitrary Javascript to browsers and subvert encryption in a variety of ways, can't it? I'm still not clear why you designed a new, simplistic cryptosystem at all he…

What do you think of Lavabit? I think they operated in the same way, but the US government forced them out of business for refusing to hand over their TLS keys to allow the US to spy on Snowden. https://en.wikipedia.org/wiki/Lavabit

See below, Lavabit not a good comparison as it was not end-to-end encrypted. Also read https://arstechnica.com/information-technology/2013/11/op-ed...

Re: Skiff – Privacy-first end-to-end encrypted email

#75

Earlier quoted context omitted.

> Your server can feed arbitrary Javascript to browsers and subvert encryption in a variety of ways, can't it? That's how literally any website works. How do you encrypt in the browser if the server doesn't send JavaScript to encrypt data? You also trust Signal not to issue an update that sends data in plaintext over the network. Unless you're building an app from source, you implicitly trust the developer to some ex…

> How do you encrypt in the browser if the server doesn't send JavaScript to encrypt data? Meta has done some work along with Cloudflare on this for WhatsApp Web, specifically. In general, JS crypto is always going to be suspect if the threat model involves distrusting the server (like in e2ee protocols like Signal).

JS crypto functions now interface with browser crypto functions for the last decade or so. https://developer.mozilla.org/en-US/docs/Web/API/Crypto

Re: Skiff – Privacy-first end-to-end encrypted email

#76
post #71

Earlier quoted context omitted.

"Open source" is defined by this page, which has been around since the 1990s: https://opensource.org/osd/

Yet it is so poorly understood and you see open source mentioned like here when its not meeting such definition. The name is just plain bad.

They are most likely using the open source name to increase their media/marketing coverage, not because they don’t know what it actually means.

Re: Skiff – Privacy-first end-to-end encrypted email

#77

Earlier quoted context omitted.

Founding engineer at Skiff here. >From the white paper, it appears as if this system requires its users to trust the server. That's not end-to-end encryption. What do I have wrong here? It doesn't. All data is encrypted client side across all apps - Skiff Mail, Drive, Pages, and Calendar. For sending external, the whitepaper is very clear how this case is handled in section 8.2 as securely as possible (without having…

Worth noting that Google does not do what you're describing. Google has never literally "sold" data from Gmail and stopped using it for their own ads ~6 years ago.

https://www.theverge.com/2023/5/5/23712440/gmail-ads-more-an... this is from 2023...

Re: Skiff – Privacy-first end-to-end encrypted email

#78

How has Skiff's email deliverability been? I'm curious if your emails go to spam more frequently, being a smaller player in an established hegemony. You have a generous free tier which may attract spammers. How do you deal with IP reputation?

Deliverability is a constant challenge for us to improve on. We have rate limits that do try to protect email deliverability. Things should be good today but it will always be something to watch.

Re: Skiff – Privacy-first end-to-end encrypted email

#79
post #4

The pricing page is confusing to me. It doesn’t mention anything about email in the free tier. It just says: > Unlimited pages > Desktop, tablet, and mobile access > IPFS support > Full text search Which seems to be all about the document service, but it also doesn’t mention how much storage I get. I assume it’s not unlimited despite saying “Unlimited pages.” Also, I can see that Skiff has raised over $14M in VC fund…

> Skiff has raised over $14M in VC funds, so as a privacy-focused product... They seemed to have pivoted from web3? https://news.ycombinator.com/item?id=29797691

You can resolve ENS names to actual email addresses, which is still the case, no pivot

Re: Skiff – Privacy-first end-to-end encrypted email

#80
post #14

Earlier quoted context omitted.

Yes, we have custom domain support with DKIM/DMARC/SPF all enabled.

I use FastMail but would consider moving. Can I have unlimited aliases when using my own domain? I use their MaskedEmail function to generate aliases for each service and have > 150 at this point.

Yes, unlimited aliases on any domain
Post reply on HN