Live data from Hacker News

Google releases stats on email encryption in transit

google.com

1–10 of 53 posts

Re: Google releases stats on email encryption in transit

#5
post #3

I'm confused as to why anything isn't 100%. I guess I could maybe understand 0%, but how can it be 50%? I would imagine you either encrypt all email or you don't encrypt any email. What is the in-between?

Large installations with heterogeneous clusters, accreted during many internal reigns and rounds of partially-integrated M&A.

Re: Google releases stats on email encryption in transit

#6
post #3

I'm confused as to why anything isn't 100%. I guess I could maybe understand 0%, but how can it be 50%? I would imagine you either encrypt all email or you don't encrypt any email. What is the in-between?

Probably because it allows connections that aren't perfectly secure, such as supporting anything less than 256 bits.

Re: Google releases stats on email encryption in transit

#7
The 99.9% freak me out.

The huge problem with email encryption right now is that you can't reasonably make it mandatory (as you can see, a lots of domain do not support it) so it can be easily be stripped à la sslstrip, and there is no such a thing as HSTS. (Again, please, build pinning into everything.)

So an active attacker able to MitM can simply turn encryption off, and those 99.9% make me wonder if that happened to the 0.1%...

Re: Google releases stats on email encryption in transit

#9

This is ironic, as Gmail has never supported email encrypted (or even signed) using S/MIME and digital certificates.

This post is referring to the secure transport of plain text emails between email providers. I.e. protecting from a mitm between gmail.com and hotmail.com when somebody sends a normal email from one to the other.
Post reply on HN