Live data from Hacker News

Skiff – Privacy-first end-to-end encrypted email

skiff.com

111–120 of 201 posts

Re: Skiff – Privacy-first end-to-end encrypted email

#111
post #102

Earlier quoted context omitted.

> Except there is a reason. Encrypting email has very little to no benefit, since it is transmitted in plaintext and usually stored in plaintext on the recipient's side, your emails almost always exist in unencrypted form. On top of that it has major usability drawbacks, for example you cant ask the server to search emails for you anymore - all emails have to be downloaded on all your devices to be able to search - w…

Unfortunately not even close. When the server gets the email it is not encrypted (unless the sender has a skiff address too, which is a very tiny portion...). And when you send an email to anyone outside skiff it is the same problem, the email has to be unencrypted so the server can send it in a form readable by the recepient. Without anything like PGP the server does not know the reciepent's public key, so it is imp…

We might be talking about different encryption, since that does not sound E2EE at all. The point of the encryption is that server never sees the content.

But that is true that if you use skiff to send message for someone, who is not using skiff, the message is unencrypted because receiver has no means to decrypt it.

That is standrdisation issue. Apparantly PGP is not considered good enough.

But if we had standards, we have techology to provide E2EE emails.

Re: Skiff – Privacy-first end-to-end encrypted email

#112
post #12

Earlier quoted context omitted.

Hello! Yes, we're working on this. Note that our UI, cryptography, and editor libraries are MIT licensed.

Why does the claim remain 3 weeks after admitted false?

Free marketing at the expense of user trust

Re: Skiff – Privacy-first end-to-end encrypted email

#113
post #111

Earlier quoted context omitted.

Unfortunately not even close. When the server gets the email it is not encrypted (unless the sender has a skiff address too, which is a very tiny portion...). And when you send an email to anyone outside skiff it is the same problem, the email has to be unencrypted so the server can send it in a form readable by the recepient. Without anything like PGP the server does not know the reciepent's public key, so it is imp…

We might be talking about different encryption, since that does not sound E2EE at all. The point of the encryption is that server never sees the content. But that is true that if you use skiff to send message for someone, who is not using skiff, the message is unencrypted because receiver has no means to decrypt it. That is standrdisation issue. Apparantly PGP is not considered good enough. But if we had standards, w…

Totally agree... it is just disappointing that services like Skiff advertise total E2EE to unsuspecting users with no mention of this in their marketing, luring users into a false sense of security

Re: Skiff – Privacy-first end-to-end encrypted email

#114
post #71

Earlier quoted context omitted.

"Open source" is defined by this page, which has been around since the 1990s: https://opensource.org/osd/

Yet it is so poorly understood and you see open source mentioned like here when its not meeting such definition. The name is just plain bad.

Which is why we have to keep fighting misuse, the same way those companies will fight for trademarks.

Re: Skiff – Privacy-first end-to-end encrypted email

#115
post #95
post #54

Earlier quoted context omitted.

Signal's servers can't backdoor the Signal Client. From what I understand of Skiff, Skiff's servers are the client.

Not directly. They would have to roll out an update with the backdoor to the App Store. But as a user I’d be none the wiser. I wish there was some way on iOS to prove that some particular version of an app was built from a certain git hash. That way these sort of attacks would be easier to detect.

That would be ideal. F-Droid on android can do this: https://f-droid.org/en/docs/Reproducible_Builds/

However there is still one advantage of even appstor: They have to push the backdoored version to everyone (or large set of users). So that drastically increases risk of being caught. Website under their control can backdoor one specific user or even just one session, making detection harder.

Re: Skiff – Privacy-first end-to-end encrypted email

#116
After getting fed up with ProtonMail recently I went on a quest to find an alternative. Unfortunately Skiff doesn't have SMTP or even an export feature so once you go Skiff you can't go back, you're locked in.

ProtonMail does have import/export and the SMTP bridge (for paid users) and those things work but ProtonMail mangles emails: it removes plaintext body where there's a HTML body and it screws with headers.

Ultimately the best option I could come up with was self-hosting my email address. Incoming emails go directly to a box sitting in my office, with TLS enforced.

I put this off for years fearing deliverability issues but finally realised that incoming and outgoing email can be hosted in different places. So though the box in my office receives my email, I send email through either a Hetzner box or Mailgun (with retention disabled). Haven't encountered any issues with this so far.

Re: Skiff – Privacy-first end-to-end encrypted email

#118
post #116

After getting fed up with ProtonMail recently I went on a quest to find an alternative. Unfortunately Skiff doesn't have SMTP or even an export feature so once you go Skiff you can't go back, you're locked in. ProtonMail does have import/export and the SMTP bridge (for paid users) and those things work but ProtonMail mangles emails: it removes plaintext body where there's a HTML body and it screws with headers. Ultim…

> After getting fed up with ProtonMail recently I went on a quest to find an alternative. Unfortunately Skiff doesn't have SMTP or even an export feature so once you go Skiff you can't go back, you're locked in.

wow, an e-mail service without smtp nor imap?? no thanks

Re: Skiff – Privacy-first end-to-end encrypted email

#119
post #12

Their website describes this as open source but their linked repo is under CC BY-NC-SA 4.0 [1] so not commonly regarded as open source, but instead source available. They have been made aware of this [2]. Additionally, I think it may only be the front-end parts of their apps that are source available, I'm not sure the server-side parts of their app have sources published. [1] https://creativecommons.org/licenses/by-n…

Hello! Yes, we're working on this. Note that our UI, cryptography, and editor libraries are MIT licensed.

hello, how can I be sure the service mentioned above is really e2e encrypted ?

Re: Skiff – Privacy-first end-to-end encrypted email

#120
post #111

Earlier quoted context omitted.

We might be talking about different encryption, since that does not sound E2EE at all. The point of the encryption is that server never sees the content. But that is true that if you use skiff to send message for someone, who is not using skiff, the message is unencrypted because receiver has no means to decrypt it. That is standrdisation issue. Apparantly PGP is not considered good enough. But if we had standards, w…

Totally agree... it is just disappointing that services like Skiff advertise total E2EE to unsuspecting users with no mention of this in their marketing, luring users into a false sense of security

European based Tutanota offers possibility for send E2EE for non-Tutanota users. It works by setting password for the content, and you need to deliver the password in other means. But usability suffers on this case, but at least there is a possibility.
Post reply on HN