Live data from Hacker News

Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

blog.torproject.org

11–20 of 55 posts

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#11

Earlier quoted context omitted.

I agree with the sentiment, but I question how useful this would really be. Most people nowadays unfortunately use web clients, so the keys are going to have to be stored somewhere else, since backing up a browser's local storage is no easy task. If you don't have sole access to keys, but rather the keys are controlled by the same entities that control your email, I don't think there will be any benefit.

There are plenty of email users on IMAP, and they use web mail to host mail storage. The IMAP clients can do S/MIME (or PGP I suppose). The bigger problem is trustworthy user discovery service i.e. a directory to exchange public keys. This exists at an enterprise level (active directory) but not globally.

Usually anyone that buys into the viability of PGP email will also tell me with a straight face that the MIT keyserver is completely appropriate for civilians.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#13
post #2

But think of the children!! 'Technology companies currently use encryption positively to keep your bank transactions and online purchases safe and secure. Encryption has many other uses throughout everyday life, but some social media companies such as Meta are proposing to implement or already have implemented E2EE in private messaging spaces. E2EE overrides current controls in place that help to keep children safe a…

> E2EE overrides current controls in place There are no controls in place. This line is becoming quite a pattern in UK (Tory) government rhetoric. They forcefully state wishful thinking as if it were a fact. There are no controls because there is no possibility of controls, as a matter of mathematics. But by exploiting ignorance, the tories managed to beast parliament into an intractable "just imagine if..." clause i…

[deleted]

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#15
post #5

One of the largest holes in encrypted communication is still the fact that the vast majority of email is still neither digitally signed, nor encrypted. And even if they are, the usual schemes do not encrypt the subject line. I wish there was something like Let's encrypt but for email. Just make it trivial to sign and encrypt your mail. Also, mail clients should give a huge warning for unencrypted and/or unsigned mail…

I think Latacora's (famous?) post[1] sums the situation up here nicely: email is designed in such a way that precludes an encryption scheme that actually works for ordinary users. Even power users consistently fail to use email encryption correctly. If we care about secure communication, then we should be nudging users towards protocols that enable encryption, rather than fighting against it. For 99% of cases, that p…

I don't think that Signal is a proper substitute for anything that email is used for. Maybe it would be better to work on more secure successors or extensions to email.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#16
And for hiding the activities of pedophiles and terrorists.

Encryption isn't solely beneficial to human rights, it enables considerable harm to be shielded from scrutiny. There has to be a balance with the extent to which applications of encryption are permitted in society.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#17

And for hiding the activities of pedophiles and terrorists. Encryption isn't solely beneficial to human rights, it enables considerable harm to be shielded from scrutiny. There has to be a balance with the extent to which applications of encryption are permitted in society.

Without encryption, the pedophiles and terrorists have access to your communication as well. Not a very bright world.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#18
post #15

Earlier quoted context omitted.

I think Latacora's (famous?) post[1] sums the situation up here nicely: email is designed in such a way that precludes an encryption scheme that actually works for ordinary users. Even power users consistently fail to use email encryption correctly. If we care about secure communication, then we should be nudging users towards protocols that enable encryption, rather than fighting against it. For 99% of cases, that p…

I don't think that Signal is a proper substitute for anything that email is used for. Maybe it would be better to work on more secure successors or extensions to email.

Lots of people, including my parents, use email as an asynchronous messaging platform. For those people, Signal is an eminently suitable replacement.

As the post points out: email cannot be extended into a secure position. Attempts to do so either fail to interoperate or fail outright.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#19
post #15

Earlier quoted context omitted.

I don't think that Signal is a proper substitute for anything that email is used for. Maybe it would be better to work on more secure successors or extensions to email.

Lots of people, including my parents, use email as an asynchronous messaging platform. For those people, Signal is an eminently suitable replacement. As the post points out: email cannot be extended into a secure position. Attempts to do so either fail to interoperate or fail outright.

Email as a concept can evolve. We can break backward compatiblity. Call it email v2 and include some killer features. If enough major players and users get involved then it'll happen.

My hope is it'll be something like Dark Mail, yet with a carve out for enterprise recipients to inject their controls and anti-malware before end-user delivery. (To combat spam and malware.)

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#20

Earlier quoted context omitted.

Lots of people, including my parents, use email as an asynchronous messaging platform. For those people, Signal is an eminently suitable replacement. As the post points out: email cannot be extended into a secure position. Attempts to do so either fail to interoperate or fail outright.

Email as a concept can evolve. We can break backward compatiblity. Call it email v2 and include some killer features. If enough major players and users get involved then it'll happen. My hope is it'll be something like Dark Mail, yet with a carve out for enterprise recipients to inject their controls and anti-malware before end-user delivery. (To combat spam and malware.)

That’s the point about interoperability. If we’re going to make “email v2” (not a terrible idea!), then the considerations that will go into securing it will ensure that it’s entirely incompatible with the thing we currently call email.

In other words: without sufficient clarity, email v2 just confuses people like my parents. Who would be better served by Signal anyways.

Post reply on HN