Gmail E2E is as terrible as expected
11–20 of 70 posts
Re: Gmail E2E is as terrible as expected
#12By whom? It looks like E2E to me. It’s just that both ends are controlled by the same entity.
Re: Gmail E2E is as terrible as expected
#13Then there were a whole plethora of products were build around Lotus Notes Domino that provided a central place for securing outgoing E-mail using either S/MIME or GPG keys. All of this on premises. Then came the Cloud and obliterated these products. And for what?
edit: typos
Re: Gmail E2E is as terrible as expected
#14Re: Gmail E2E is as terrible as expected
#15This is how all HIPAA "secure email" works. Outlook, Zoho, clinic comms, BECAUSE it lets you revoke email access. If you want an opportunity in this space, it isn't actually encrypted emails, but possibly standardizing and streamlining such "message pointers" and address endpoint verification.
That's pretty funny.
Re: Gmail E2E is as terrible as expected
#16Re: Gmail E2E is as terrible as expected
#17Re: Gmail E2E is as terrible as expected
#18What happens if the sender's Google account ceases to exist for whatever reason? What if Google ceases to exist? I know that there are a lot of HIPAA "secure email" solutions that also do this, but I don't want this to become more common practice then it already is...
Re: Gmail E2E is as terrible as expected
#19What happens if the sender's Google account ceases to exist for whatever reason? What if Google ceases to exist? I know that there are a lot of HIPAA "secure email" solutions that also do this, but I don't want this to become more common practice then it already is...
Long term archival is a different use case altogether, especially of encrypted materials. It's questionable whether any provider or medium can survive over the long term, so it's better to use an encryption system where you hold the keys and the encrypted data can be migrated to any sort of storage or provider over the years.
Re: Gmail E2E is as terrible as expected
#20Earlier quoted context omitted.
Can’t expect a civilian to manage pgp keys or go to key signing parties
The anti-establishment fervor of open source crypto developers is the reason this is a problem though. Most people, for most things, don't need to verify trust outside of normal government channels. i.e. any business I correspond with, trust is via the government that they are a business bound by the relevant legal system I live in. Same story with communicating with basically anyone: if their GPG key was signed by t…
Trusting the government as a peer makes sense for government sites, but for anything else, it just makes censorship way too easy.
Even among businesses, we normally trust the middleman (the credit card issuer, and their protections and chargebacks) over the government. If a business screws over a regular consumer, the government isn't really going to do anything.
Maybe you have a more civilized society and functional government where you live. We don't.