Live data from Hacker News

Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

blog.torproject.org

21–30 of 55 posts

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#21
post #5

One of the largest holes in encrypted communication is still the fact that the vast majority of email is still neither digitally signed, nor encrypted. And even if they are, the usual schemes do not encrypt the subject line. I wish there was something like Let's encrypt but for email. Just make it trivial to sign and encrypt your mail. Also, mail clients should give a huge warning for unencrypted and/or unsigned mail…

I think Latacora's (famous?) post[1] sums the situation up here nicely: email is designed in such a way that precludes an encryption scheme that actually works for ordinary users. Even power users consistently fail to use email encryption correctly. If we care about secure communication, then we should be nudging users towards protocols that enable encryption, rather than fighting against it. For 99% of cases, that p…

Signal has no concept of trust delegation: also, the verification API is extremely hidden and sucks (i.e. my brother working at a FAANG had no idea it existed or what it did - it's also extremely confusing when you open it).

This creates two problems: (1) is that Signal functionally operates as "trust on first use", and (2) Signal has no system by which you can communicate to "conceptual entities" - i.e. companies. There's no way in Signal to talk to say, a bank or a government agency as an entity (IMO: to turn a profit, this is the business Signal actually need to be in).

Which makes it a bit of stochastic security measure: encrypt enough communications and probably when something important does come up, the window to intercept it has failed - except of course, that those verification number messages nobody knows what to do with and so they ignore them.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#22

Earlier quoted context omitted.

Lots of people, including my parents, use email as an asynchronous messaging platform. For those people, Signal is an eminently suitable replacement. As the post points out: email cannot be extended into a secure position. Attempts to do so either fail to interoperate or fail outright.

Email as a concept can evolve. We can break backward compatiblity. Call it email v2 and include some killer features. If enough major players and users get involved then it'll happen. My hope is it'll be something like Dark Mail, yet with a carve out for enterprise recipients to inject their controls and anti-malware before end-user delivery. (To combat spam and malware.)

In theory the giants that already hold the vast majority of all email communications - like Microsoft and Alphabet - are in a prime position to introduce a successor, hopefully this time with a receipt so the last argument in favour of fax dies off. At the same time, they have no proper motivation to do so.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#23
post #21

Earlier quoted context omitted.

I think Latacora's (famous?) post[1] sums the situation up here nicely: email is designed in such a way that precludes an encryption scheme that actually works for ordinary users. Even power users consistently fail to use email encryption correctly. If we care about secure communication, then we should be nudging users towards protocols that enable encryption, rather than fighting against it. For 99% of cases, that p…

Signal has no concept of trust delegation: also, the verification API is extremely hidden and sucks (i.e. my brother working at a FAANG had no idea it existed or what it did - it's also extremely confusing when you open it). This creates two problems: (1) is that Signal functionally operates as "trust on first use", and (2) Signal has no system by which you can communicate to "conceptual entities" - i.e. companies. T…

I agree that the verification UI sucks. I have similar stories about otherwise technical people not knowing about it or otherwise not understanding it.

At the same time: the relevant comparison here is email. Email isn’t even TOFU between arbitrary identities; it’s trust-on-each-message. Similarly for conceptual identities (like a bank’s catch-all address).

(I also agree with your point about this needing to be one of Signal’s businesses. WhatsApp and other chats already do this, I believe.)

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#24
post #2

But think of the children!! 'Technology companies currently use encryption positively to keep your bank transactions and online purchases safe and secure. Encryption has many other uses throughout everyday life, but some social media companies such as Meta are proposing to implement or already have implemented E2EE in private messaging spaces. E2EE overrides current controls in place that help to keep children safe a…

> E2EE overrides current controls in place There are no controls in place. This line is becoming quite a pattern in UK (Tory) government rhetoric. They forcefully state wishful thinking as if it were a fact. There are no controls because there is no possibility of controls, as a matter of mathematics. But by exploiting ignorance, the tories managed to beast parliament into an intractable "just imagine if..." clause i…

The better answer though is that it's a misdirect: they're pointing at encryption as the bad guy, the one thing which takes place solely in the digital space and is activity-agnostic - nothing which happens with encrypted bits, by itself, can do anything in the real world.

"Pedophiles and terrorists" on the other hand, have to do a lot of things in the physical world in order to actually be pedophiles and terrorists. And the vast majority of work taking them down is infiltration - which is to say, nobody breaks encryption, they break trust - which is much easier, and has side-benefits like "generating actual evidence".

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#25
post #21

Earlier quoted context omitted.

Signal has no concept of trust delegation: also, the verification API is extremely hidden and sucks (i.e. my brother working at a FAANG had no idea it existed or what it did - it's also extremely confusing when you open it). This creates two problems: (1) is that Signal functionally operates as "trust on first use", and (2) Signal has no system by which you can communicate to "conceptual entities" - i.e. companies. T…

I agree that the verification UI sucks. I have similar stories about otherwise technical people not knowing about it or otherwise not understanding it. At the same time: the relevant comparison here is email. Email isn’t even TOFU between arbitrary identities; it’s trust-on-each-message. Similarly for conceptual identities (like a bank’s catch-all address). (I also agree with your point about this needing to be one o…

Email these days is however tied to DKIM and domains. We have UI problems, but communicating to a companies email servers at their domain name can be reasonably expected to be communicating with that company.

It's just the security story on that if you never want the content disclosed isn't great, but conversely, conceptual entity communications are always going to be a bit public by nature.

There's a whole other rant I have about this problem, where we really lack domain specific trust standards - i.e. communicating with a business, what I want to know is "is this a recognized legal business entity in it's jurisdiction, and what's it's status to mine?" which is very different to "I need to make absolutely sure me and John Smith's communication is just between us" - but they're in the same space of problem.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#26
post #21

Earlier quoted context omitted.

I think Latacora's (famous?) post[1] sums the situation up here nicely: email is designed in such a way that precludes an encryption scheme that actually works for ordinary users. Even power users consistently fail to use email encryption correctly. If we care about secure communication, then we should be nudging users towards protocols that enable encryption, rather than fighting against it. For 99% of cases, that p…

Signal has no concept of trust delegation: also, the verification API is extremely hidden and sucks (i.e. my brother working at a FAANG had no idea it existed or what it did - it's also extremely confusing when you open it). This creates two problems: (1) is that Signal functionally operates as "trust on first use", and (2) Signal has no system by which you can communicate to "conceptual entities" - i.e. companies. T…

> (2) Signal has no system by which you can communicate to "conceptual entities" - i.e. companies.

This has always kind of bugged me with email as compared to physical mail: While with a physical mailbox I can write a letter "to whom it may concern" and throw it in, with email I need to find out if the special, general purpose inbox is info@, contact@, hello@, or whatever other address the company uses, assuming they use the same domain for their email as they do for their website.

On the next level, there is no first-class support for stuff like 'send this message to person X, although it is adressed to organisation Y, where X works.' Basically, acknowledging the legal and organisational reality that while (single) humans might read, process and respond to communication, it is the legal entity that is actually being adressed.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#27
post #25

Earlier quoted context omitted.

I agree that the verification UI sucks. I have similar stories about otherwise technical people not knowing about it or otherwise not understanding it. At the same time: the relevant comparison here is email. Email isn’t even TOFU between arbitrary identities; it’s trust-on-each-message. Similarly for conceptual identities (like a bank’s catch-all address). (I also agree with your point about this needing to be one o…

Email these days is however tied to DKIM and domains. We have UI problems, but communicating to a companies email servers at their domain name can be reasonably expected to be communicating with that company. It's just the security story on that if you never want the content disclosed isn't great, but conversely, conceptual entity communications are always going to be a bit public by nature. There's a whole other ran…

> There's a whole other rant I have about this problem, where we really lack domain specific trust standards - i.e. communicating with a business, what I want to know is "is this a recognized legal business entity in it's jurisdiction, and what's it's status to mine?"

I have the same pain, but this seems more like a regulatory issue than a technological one. Here in Germany, (basically all) legal entities need to publish a physical adress where they are reachable, it would be easy, in theory, to extend this to a reachable domain or email adress, thereby giving a guarantee, at least in Germany, that you are interacting with the business you are expecting. As you said, DKIM already exists.

Unless I have missed your point, then rant away.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#28
post #15

Earlier quoted context omitted.

I don't think that Signal is a proper substitute for anything that email is used for. Maybe it would be better to work on more secure successors or extensions to email.

Lots of people, including my parents, use email as an asynchronous messaging platform. For those people, Signal is an eminently suitable replacement. As the post points out: email cannot be extended into a secure position. Attempts to do so either fail to interoperate or fail outright.

Email is also an archive of communications with vendors, shops and government departments.

Signal doesn't let you migrate chat history to your desktop.

Trying to migrate between phones while retaining your Signal history is too hard for most people.

Signal is not at all a suitable replacement, and I believe that forward secrecy is an anti-feature for an email-like usecase.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#29
post #5

One of the largest holes in encrypted communication is still the fact that the vast majority of email is still neither digitally signed, nor encrypted. And even if they are, the usual schemes do not encrypt the subject line. I wish there was something like Let's encrypt but for email. Just make it trivial to sign and encrypt your mail. Also, mail clients should give a huge warning for unencrypted and/or unsigned mail…

This is actually the best example for why encryption isn't a human right. Postal mail isn't encrypted, telephone calls aren't encrypted, and the UN hasn't made a declaration about that. Why is that?

It's because encryption is a red herring. The theory that encryption is going to stop government surveillance is ridiculous. Even a perfect technology is not going to override national politics. Any government oppressive enough to require surveillance of its citizens will not be stopped by encryption. They will just block it or require a backdoor, or find yet more exploits that they won't announce in order to take advantage silently (whether it's the government directly, or one of the many 0day-for-pay players)

Either way they will enforce their will, until the citizens reform their government. You can't tech your way out of politics. You want an end to surveillance? Then go get involved in politics! Force your government to stop surveiling its citizens! Don't wait for someone else do the heavy lifting for you.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#30

Earlier quoted context omitted.

Email as a concept can evolve. We can break backward compatiblity. Call it email v2 and include some killer features. If enough major players and users get involved then it'll happen. My hope is it'll be something like Dark Mail, yet with a carve out for enterprise recipients to inject their controls and anti-malware before end-user delivery. (To combat spam and malware.)

That’s the point about interoperability. If we’re going to make “email v2” (not a terrible idea!), then the considerations that will go into securing it will ensure that it’s entirely incompatible with the thing we currently call email. In other words: without sufficient clarity, email v2 just confuses people like my parents. Who would be better served by Signal anyways.

Vendors big enough to be known by your parents are sophisticated enough to paper over the differences and make it seamless. (Where possible)
Post reply on HN