Live data from Hacker News

Skiff – Privacy-first end-to-end encrypted email

skiff.com

161–170 of 201 posts

Re: Skiff – Privacy-first end-to-end encrypted email

#161

"privacy first" Yet the web UI downloads remote images by default. Granted, it hides your IP address by proxying the request. But it still leaks that the message was read. I used https://www.emailprivacytester.com to test this. No image was fetched until I clicked the email to read it.

We offer a block remote content feature. There is no foolproof way to load any remote content without possibly exposing email open information.

Even more worrying, I just went into the settings and toggled on "Block remote content" and then sent my self another test through https://www.emailprivacytester.com, and it still triggered a remote content load when I viewed the email.

It's saying that the images were blocked, but that didn't stop them being fetched. Entirely defeating the point of the setting.

Re: Skiff – Privacy-first end-to-end encrypted email

#162

"privacy first" Yet the web UI downloads remote images by default. Granted, it hides your IP address by proxying the request. But it still leaks that the message was read. I used https://www.emailprivacytester.com to test this. No image was fetched until I clicked the email to read it.

We offer a block remote content feature. There is no foolproof way to load any remote content without possibly exposing email open information.

> There is no foolproof way to load any remote content without possibly exposing email open information.

Also, this is false. You could download all remote content at time of delivery. That way it would be impossible for a sender to differentiate between an email simply being delivered and one being read.

Re: Skiff – Privacy-first end-to-end encrypted email

#163

Earlier quoted context omitted.

We offer a block remote content feature. There is no foolproof way to load any remote content without possibly exposing email open information.

My point was that defaults matter, and your default is not privacy preserving. Yet you claim to be a "privacy first" service. There are many email clients which do not download remote content by default. I would argue that they preserve privacy better than Skiff does.

What mail providers block all remote content by default?

Re: Skiff – Privacy-first end-to-end encrypted email

#164

Earlier quoted context omitted.

My point was that defaults matter, and your default is not privacy preserving. Yet you claim to be a "privacy first" service. There are many email clients which do not download remote content by default. I would argue that they preserve privacy better than Skiff does.

What mail providers block all remote content by default?

I don't have a list for you. I would have thought you'd have this data yourself given the business you're in.

Re: Skiff – Privacy-first end-to-end encrypted email

#165
post #86

Earlier quoted context omitted.

What difference does this make to the thread model in the previous comment?

Before this basic cryptography was downloaded via JS files which yields no security and gave web cryptography a bad reputation. That is not true now.

There's literally nothing stopping the page from simply not encrypting the data.

Re: Skiff – Privacy-first end-to-end encrypted email

#166
post #159

Earlier quoted context omitted.

Skiff encrypts all received emails with user public keys immediately on receipt. This is quite clear in our security model page and whitepaper. Skiff does not have access to any user emails, including external received ones.

Unfortunately this does not matter, since the trust model is same as it would not be encrypted at all. We still need to trust the third party. Somehow the infrastructure should be transparent so that outsider can verify indeed at any time, that you don't collect logs from that traffic, or have no other means to inspect traffic if you want to. There are currently no other means than just to use E2E encryption. There i…

We use an open-source mailserver (Haraka), but security audits are the most trustworthy way to do this. We've had 4: skiff.com/transparency. Audits cover infrastructure.

Re: Skiff – Privacy-first end-to-end encrypted email

#167

Earlier quoted context omitted.

What mail providers block all remote content by default?

I don't have a list for you. I would have thought you'd have this data yourself given the business you're in.

Yes - privacy focused mail providers offer this as an option but do not enable it by default. Mainstream mail providers do not even have it as an option.

Re: Skiff – Privacy-first end-to-end encrypted email

#168
post #116

After getting fed up with ProtonMail recently I went on a quest to find an alternative. Unfortunately Skiff doesn't have SMTP or even an export feature so once you go Skiff you can't go back, you're locked in. ProtonMail does have import/export and the SMTP bridge (for paid users) and those things work but ProtonMail mangles emails: it removes plaintext body where there's a HTML body and it screws with headers. Ultim…

I could recommend Fastmail with PGP (when it matters). They have good documentation on how to do this [0].

More expensive than self hosting, but still quite cheap, and no weird vendor-specific lockin for the important parts.

[0] https://www.fastmail.com/blog/pgp-tools-with-fastmail/

Re: Skiff – Privacy-first end-to-end encrypted email

#169
post #159

Earlier quoted context omitted.

Unfortunately this does not matter, since the trust model is same as it would not be encrypted at all. We still need to trust the third party. Somehow the infrastructure should be transparent so that outsider can verify indeed at any time, that you don't collect logs from that traffic, or have no other means to inspect traffic if you want to. There are currently no other means than just to use E2E encryption. There i…

We use an open-source mailserver (Haraka), but security audits are the most trustworthy way to do this. We've had 4: skiff.com/transparency. Audits cover infrastructure.

You can't audit a non-E2EE design into E2EE security!

Re: Skiff – Privacy-first end-to-end encrypted email

#170

Earlier quoted context omitted.

I don't have a list for you. I would have thought you'd have this data yourself given the business you're in.

Yes - privacy focused mail providers offer this as an option but do not enable it by default. Mainstream mail providers do not even have it as an option.

Are you joking? I've never even come across an email client or provider that doesn't have options to toggle loading remote images. What mainstream mail providers don't have this option?

The only difference between your option and other providers are:

1. Yours doesn't even work. It still loads the remote images. It just doesn't display them

2. Yours has the wrong default.

Your "block remote content" option is even worse than just forcibly loading remote images and not even having the option in the first place, because it tricks the user into thinking that it will preserve privacy, like it does for other providers, but it does not preserve privacy in your case as it still loads the images.

Post reply on HN