Live data from Hacker News

Gmail E2E is as terrible as expected

michal.sapka.pl

11–20 of 70 posts

Re: Gmail E2E is as terrible as expected

#13
The E2E problem has already been solved long time ago. We used to have Thunderbird with an OpenPGP extension and GPG keys.

Then there were a whole plethora of products were build around Lotus Notes Domino that provided a central place for securing outgoing E-mail using either S/MIME or GPG keys. All of this on premises. Then came the Cloud and obliterated these products. And for what?

edit: typos

Re: Gmail E2E is as terrible as expected

#15

This is how all HIPAA "secure email" works. Outlook, Zoho, clinic comms, BECAUSE it lets you revoke email access. If you want an opportunity in this space, it isn't actually encrypted emails, but possibly standardizing and streamlining such "message pointers" and address endpoint verification.

> lets you revoke (...) access

That's pretty funny.

Re: Gmail E2E is as terrible as expected

#18
post #10

What happens if the sender's Google account ceases to exist for whatever reason? What if Google ceases to exist? I know that there are a lot of HIPAA "secure email" solutions that also do this, but I don't want this to become more common practice then it already is...

Keep HARs from the browser if you need your own record of the messages. Next step would be to determine how to extract the messages from a history of HARs and inject into your own mailbox or other storage system for archiving and search. Perhaps a browser extension to automate this automated logging of message retrieval.

Re: Gmail E2E is as terrible as expected

#19
post #10

What happens if the sender's Google account ceases to exist for whatever reason? What if Google ceases to exist? I know that there are a lot of HIPAA "secure email" solutions that also do this, but I don't want this to become more common practice then it already is...

IMO those are different use cases. If that sender or Google itself were to disappear, hopefully the messages would just disappear too. It's better that they become inaccessible rather than public.

Long term archival is a different use case altogether, especially of encrypted materials. It's questionable whether any provider or medium can survive over the long term, so it's better to use an encryption system where you hold the keys and the encrypted data can be migrated to any sort of storage or provider over the years.

Re: Gmail E2E is as terrible as expected

#20
post #9
post #6

Earlier quoted context omitted.

Can’t expect a civilian to manage pgp keys or go to key signing parties

The anti-establishment fervor of open source crypto developers is the reason this is a problem though. Most people, for most things, don't need to verify trust outside of normal government channels. i.e. any business I correspond with, trust is via the government that they are a business bound by the relevant legal system I live in. Same story with communicating with basically anyone: if their GPG key was signed by t…

It depends a lot on the government in question too. In the US very few people would trust the government to handle something like this. The certificate authority system is run by big tech companies and nonprofits, for example, not the government.

Trusting the government as a peer makes sense for government sites, but for anything else, it just makes censorship way too easy.

Even among businesses, we normally trust the middleman (the credit card issuer, and their protections and chargebacks) over the government. If a business screws over a regular consumer, the government isn't really going to do anything.

Maybe you have a more civilized society and functional government where you live. We don't.

Post reply on HN