Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights
1–10 of 55 posts
Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights
#2'Technology companies currently use encryption positively to keep your bank transactions and online purchases safe and secure. Encryption has many other uses throughout everyday life, but some social media companies such as Meta are proposing to implement or already have implemented E2EE in private messaging spaces.
E2EE overrides current controls in place that help to keep children safe and potentially poses a huge risk."
https://www.gov.uk/government/publications/end-to-end-encryp...
Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights
#3But think of the children!! 'Technology companies currently use encryption positively to keep your bank transactions and online purchases safe and secure. Encryption has many other uses throughout everyday life, but some social media companies such as Meta are proposing to implement or already have implemented E2EE in private messaging spaces. E2EE overrides current controls in place that help to keep children safe a…
Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights
#4This is exactly why I use e2ee in my app. I sleep better knowing that the keys to the castle are not solely in my hands, but rather with each user. They will always have a say in how their data is used because they ultimately control access.
Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights
#5I wish there was something like Let's encrypt but for email. Just make it trivial to sign and encrypt your mail. Also, mail clients should give a huge warning for unencrypted and/or unsigned mail, just like browsers do with web sites. Right now, at least on Outlook for macOS, you only get a happy green padlock on signed email, if you ever receive one.
Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights
#6One of the largest holes in encrypted communication is still the fact that the vast majority of email is still neither digitally signed, nor encrypted. And even if they are, the usual schemes do not encrypt the subject line. I wish there was something like Let's encrypt but for email. Just make it trivial to sign and encrypt your mail. Also, mail clients should give a huge warning for unencrypted and/or unsigned mail…
Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights
#7One of the largest holes in encrypted communication is still the fact that the vast majority of email is still neither digitally signed, nor encrypted. And even if they are, the usual schemes do not encrypt the subject line. I wish there was something like Let's encrypt but for email. Just make it trivial to sign and encrypt your mail. Also, mail clients should give a huge warning for unencrypted and/or unsigned mail…
I agree with the sentiment, but I question how useful this would really be. Most people nowadays unfortunately use web clients, so the keys are going to have to be stored somewhere else, since backing up a browser's local storage is no easy task. If you don't have sole access to keys, but rather the keys are controlled by the same entities that control your email, I don't think there will be any benefit.
Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights
#8But think of the children!! 'Technology companies currently use encryption positively to keep your bank transactions and online purchases safe and secure. Encryption has many other uses throughout everyday life, but some social media companies such as Meta are proposing to implement or already have implemented E2EE in private messaging spaces. E2EE overrides current controls in place that help to keep children safe a…
There are no controls in place.
This line is becoming quite a pattern in UK (Tory) government rhetoric. They forcefully state wishful thinking as if it were a fact.
There are no controls because there is no possibility of controls, as a matter of mathematics. But by exploiting ignorance, the tories managed to beast parliament into an intractable "just imagine if..." clause in the Online Safety Bill... a law that provisionally exists if and only if the impossible becomes possible.
And then they sit back, fold their arms and call those "controls".
Controls must be effective, otherwise they're just buttons for show, that aren't wired to anything.
The reason nation states are losing ground to BigTech is because they are using 18th century power politics to fight 21st century logic.
I do wish my government would go take some basic CS and cryptography classes.
Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights
#9One of the largest holes in encrypted communication is still the fact that the vast majority of email is still neither digitally signed, nor encrypted. And even if they are, the usual schemes do not encrypt the subject line. I wish there was something like Let's encrypt but for email. Just make it trivial to sign and encrypt your mail. Also, mail clients should give a huge warning for unencrypted and/or unsigned mail…
I agree with the sentiment, but I question how useful this would really be. Most people nowadays unfortunately use web clients, so the keys are going to have to be stored somewhere else, since backing up a browser's local storage is no easy task. If you don't have sole access to keys, but rather the keys are controlled by the same entities that control your email, I don't think there will be any benefit.
The bigger problem is trustworthy user discovery service i.e. a directory to exchange public keys. This exists at an enterprise level (active directory) but not globally.
Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights
#10One of the largest holes in encrypted communication is still the fact that the vast majority of email is still neither digitally signed, nor encrypted. And even if they are, the usual schemes do not encrypt the subject line. I wish there was something like Let's encrypt but for email. Just make it trivial to sign and encrypt your mail. Also, mail clients should give a huge warning for unencrypted and/or unsigned mail…
If we care about secure communication, then we should be nudging users towards protocols that enable encryption, rather than fighting against it. For 99% of cases, that probably means Signal.
[1]: https://www.latacora.com/blog/2020/02/19/stop-using-encrypte...