But Google likes to read your email so they can target ads. Even they don't want you to encrypt on the client.
Leading the way looks a lot better than dragging your feet on something that is going to happen whether they want it to or not. At least they can say "hey we lead the way on this, even if it was 3 decades too late"
> that is going to happen whether they want it to or not
I highly doubt this. This sounds like wishful thinking.
Leading the way looks a lot better than dragging your feet on something that is going to happen whether they want it to or not. At least they can say "hey we lead the way on this, even if it was 3 decades too late"
> that is going to happen whether they want it to or not I highly doubt this. This sounds like wishful thinking.
Pessimism, just as illogical as optimism.
As in, care to explain why you so highly doubt it? I have little more than anecdotal trends as evidence.
A fun experiment for someone who isn't afraid of having their ISP, colocation provider, or VM provider terminate their account and/or sue them because ZOMG LOTS OF OUTBOUND TCP/25 CONNECTIONS MEANS A SPAMMER IS YOU: • Take Google's list of mail domains they see (they offer a CSV file for download) and look up all of the mail exchangers for all of the domains. • Remove duplicates from the list of MX hostnames. • Write…
The 99.9% freak me out. The huge problem with email encryption right now is that you can't reasonably make it mandatory (as you can see, a lots of domain do not support it) so it can be easily be stripped à la sslstrip, and there is no such a thing as HSTS. (Again, please, build pinning into everything.) So an active attacker able to MitM can simply turn encryption off, and those 99.9% make me wonder if that happened…
That problem is quite common on the internet in general. Just think how common ftp still is! We constantly use public networks and then have to mitigate the fact that the packets are public. It would be better to treat encryption like a peering arrangement. When there is sufficient traffic between two large networks all packets should be routed via an encrypted tunnel.
While I generally agree with the concept, encryption isn't free, and will break pretty much every routing protocol used. It's easy enough to get a tunnel through transit when you control both ends, but neither the hardware nor the software that actually runs the peers supports it in any way. You'd have to set the link, then encrypt on top of that, costing a ton of cpu cycles, bandwidth overhead, and requiring something that can handle encrypting everything in real time and then pass it off to the actual edge connection. "Large" networks do 100Gbit plus, and I can't think of any way this is currently feasible to do.
A fun experiment for someone who isn't afraid of having their ISP, colocation provider, or VM provider terminate their account and/or sue them because ZOMG LOTS OF OUTBOUND TCP/25 CONNECTIONS MEANS A SPAMMER IS YOU: • Take Google's list of mail domains they see (they offer a CSV file for download) and look up all of the mail exchangers for all of the domains. • Remove duplicates from the list of MX hostnames. • Write…
I'm lost. Where is the "profit" step ?
If it makes major providers start bothering with proper SSL configuration with a not-self-signed cert for their mail services maybe that would be a profit: things become slightly more secure for some people.
So how do I manually check that my host supports this? I checked the list of domains and although I know I have sent mail to gmail address my host does not appear.
> The huge problem with email encryption right now is that you can't reasonably make it mandatory Sure you can, see pgp. Really, its nice to see they are encrypting coms between each other but I don't really see how this affects me. If I want something secure I will use pgp. Email encryption, has and, always will be a client side problem. There is nothing the middle men and women can do for you that you can reasonabl…
But Google likes to read your email so they can target ads. Even they don't want you to encrypt on the client.
Maybe they don't care about your email(they have plenty of data) as long nobody else can use it for ads ?
Given the number and state of the certificate barons and their document-as-stolen marbles, SSL is not really encryption though, is it?
I thought this was going to be GPG stats. I bet Google do keep them... and I bet they have an uncanny correlation with people downloading their Gmail and leaving the service, or being well placed within the IT industry and vocal opponents of many of Google's recent policies.