Google releases stats on email encryption in transit
1–10 of 53 posts
Re: Google releases stats on email encryption in transit
#2Re: Google releases stats on email encryption in transit
#3Re: Google releases stats on email encryption in transit
#4Why is hotmail between 50% and 90%?
Re: Google releases stats on email encryption in transit
#5I'm confused as to why anything isn't 100%. I guess I could maybe understand 0%, but how can it be 50%? I would imagine you either encrypt all email or you don't encrypt any email. What is the in-between?
Re: Google releases stats on email encryption in transit
#6I'm confused as to why anything isn't 100%. I guess I could maybe understand 0%, but how can it be 50%? I would imagine you either encrypt all email or you don't encrypt any email. What is the in-between?
Re: Google releases stats on email encryption in transit
#7The huge problem with email encryption right now is that you can't reasonably make it mandatory (as you can see, a lots of domain do not support it) so it can be easily be stripped à la sslstrip, and there is no such a thing as HSTS. (Again, please, build pinning into everything.)
So an active attacker able to MitM can simply turn encryption off, and those 99.9% make me wonder if that happened to the 0.1%...
Re: Google releases stats on email encryption in transit
#8Re: Google releases stats on email encryption in transit
#9This is ironic, as Gmail has never supported email encrypted (or even signed) using S/MIME and digital certificates.