Live data from Hacker News

Email encryption on Android and iOS becomes easy with the open source app Tutanota

tutanota.de

11–20 of 27 posts

Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota

#11

Slightly OT, but what's the likelihood of Apple/Google integrating PGP natively into the OS? I know iPhone has S/MINE - but is PGP too much to ask?

For PGP you can try:

https://whiteout.io/

https://lavaboom.com/

Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota

#12

The NSA Planned to Hijack Google App Store to Hack Smartphones [1] Given that software updates are automatic (unless you manually turn them off etc), how can you trust an app if you can't trust the platform? 1. https://firstlook.org/theintercept/2015/05/21/nsa-five-eyes-...

Two things.

Firstly, Android checks app signatures and as far as I know the market app doesn't have any ability to override that. It can do a few privileged things like skip showing the permissions screen, but I think the OS still wants to see correct signatures. So even if the app store was hacked the phone itself might reject a bogus upgrade.

Secondly, that slide is more like some junior GCHQ guy noodling around, I think. It is old and dates from a time before Google used SSL for everything. I doubt it's possible to do via purely technical attacks now.

Thirdly, it'd almost certainly be easier to attack the developer laptop/workstation to steal the signing keys directly than attack Android head on. I plan to do some research this summer into splitting the RSA signing keys used by Android apps to allow for threshold signed online updates for Android and maybe iOS.

Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota

#13
post #10

I have to be honest, I have given up on pgp. From what I know there is no way to have encrypted communications between more than two people. So why even bother pursuing the dream of everyone using it if there is such a roadblock in the way of common communication habits.

I believe PGP does support multiple recipients. The symmetric key is encrypted and included for every recipient.

Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota

#15

The NSA Planned to Hijack Google App Store to Hack Smartphones [1] Given that software updates are automatic (unless you manually turn them off etc), how can you trust an app if you can't trust the platform? 1. https://firstlook.org/theintercept/2015/05/21/nsa-five-eyes-...

Two things. Firstly, Android checks app signatures and as far as I know the market app doesn't have any ability to override that. It can do a few privileged things like skip showing the permissions screen, but I think the OS still wants to see correct signatures. So even if the app store was hacked the phone itself might reject a bogus upgrade. Secondly, that slide is more like some junior GCHQ guy noodling around, I…

> It is old and dates from a time before Google used SSL for everything

Their budget is $52.6 billion and (as you say, the slides are old) they have lead time too. Let that sit for a moment.

Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota

#16
post #10

I have to be honest, I have given up on pgp. From what I know there is no way to have encrypted communications between more than two people. So why even bother pursuing the dream of everyone using it if there is such a roadblock in the way of common communication habits.

PGP absolutely supports multiple recipients. As the other reply says, the (small) symmetric key is encrypted separately with the public key of every recipient.

Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota

#18

Slightly OT, but what's the likelihood of Apple/Google integrating PGP natively into the OS? I know iPhone has S/MINE - but is PGP too much to ask?

I don't know about Apple, but I doubt Google will because of the features they've been putting out lately (i.e.: Now cards for flights, etc based on emails).

Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota

#19

The NSA Planned to Hijack Google App Store to Hack Smartphones [1] Given that software updates are automatic (unless you manually turn them off etc), how can you trust an app if you can't trust the platform? 1. https://firstlook.org/theintercept/2015/05/21/nsa-five-eyes-...

Two things. Firstly, Android checks app signatures and as far as I know the market app doesn't have any ability to override that. It can do a few privileged things like skip showing the permissions screen, but I think the OS still wants to see correct signatures. So even if the app store was hacked the phone itself might reject a bogus upgrade. Secondly, that slide is more like some junior GCHQ guy noodling around, I…

The only way to change the signing key for an app (on an unrooted phone at least) is by completely uninstalling it (which deletes the main data directory) and then installing a new version. In fact, Google lost the key for their OTP authenticator app at one point, requiring all users to install the new app manually before they would receive updates again.

Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota

#20
post #13
post #10

I have to be honest, I have given up on pgp. From what I know there is no way to have encrypted communications between more than two people. So why even bother pursuing the dream of everyone using it if there is such a roadblock in the way of common communication habits.

I believe PGP does support multiple recipients. The symmetric key is encrypted and included for every recipient.

Ouch, I did not expect that. Nice!
Post reply on HN