Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

151–160 of 450 posts

Re: Encrypted email is still a pain

#151
post #22

Earlier quoted context omitted.

WhatsApp has over a billion users. There are big places where its market share exceeds that of SMS --- another big centralized service that has a userbase comparable to that of email. My conclusion is that the people who care about "decentralized" systems are a rounding error. I care about non-technologists managing to send asynchronous messages to each other that are well-encrypted by default. That's a solved proble…

How does WhatsApp compare to email? I mean, how easy is it for me to contact MS CEO via email vs WhatsApp? Or my doctor. Or my mom. Or my friend I've not seen in a while. Or????

It's not that easy to compare the two. With WhatsApp, if you know the phone number of the person you want to contact, then you can send them a message or call them via WhatsApp. Both users need to have WhatsApp installed, but this is not a big problem in most countries outside of the US, since the install base is over 1 billion.

Re: Encrypted email is still a pain

#152
post #63
post #61

Earlier quoted context omitted.

Forgive my ignorance, but what caused XMPP to fail? Simply the lack of uptake or is there some other reason?

I've been running my email server for a decade without serious glitches. Setting up my own federated XMPP instance is much more problematic and people are already complaining about how hard email is. I'd love to see an up-to-date tutorial that opposes my statement, eg. setting up prosody (or something lightweight) on debian (or similar) with multiple domains for multiple accounts, sending and receiving test messages…

This one's a bit minimal since it's designed to fit on a flyer, but it does contain what you need to know; install server of choice, get a TLS cert from somewhere, set DNS records if you want them, done. https://xmpp.org/images/promo/xmpp_server_guide_2017.pdf

Re: Encrypted email is still a pain

#153
post #26

Do any of these keyservers perform email verification? It would go a good way towards some kind of verification that a user's GPG key corresponds to their email. Otherwise, anyone can generate a key with any email address and push it up to the servers. The standard way of verifying it (key-signing parties) is somewhat difficult.

Only https://keyserver.pgp.com performs email verification, the others don't. See: https://lkml.org/lkml/2016/8/15/445

It seems that keyserver.pgp.com won't accept keys with revoked subkeys

Re: Encrypted email is still a pain

#155
I used to encrypt my email with GnuPG, but it was a huge hassle for me, and an even bigger pain for the family and friends I wanted to communicate with. In the end, I realized that the things I tend to say over email just aren't that important anyway, so I stopped doing it. If someone wants to spy on my dad's fart jokes, more power to them.

Nowadays, I hardly ever check my email. There are other ways to communicate with the people who matter to me, which are automatically encrypted and aren't as easily exploited by marketers and spammers. Email just isn't something I really need or use much anymore.

Re: Encrypted email is still a pain

#157

Isis? I guess we have to trust her after all the ioerror affair, right? Considering he's currently on trial for all her allegations. /sarcasm moxie HAS to agree with his protocol. thegrugq? Wasn't he selling exploits to the highest bidder? http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-th... I can't argue about their qualifications, I argue about their morality. .edit added link.

Are you seriously suggesting that a large portion of the crypto/security community is so inherently biased that you can't trust their expert opinion on the field that they're expert in? Who do you trust?

Re: Encrypted email is still a pain

#158
post #108

I'm not sure I buy this. Protonmail has a very polished UI that's dead simple enough for technical people and non-technical people alike: https://protonmail.com

does this only work if both parties have @protonmail.com ?

It works seamlessly/automatically between protonmail users and you can also send encrypted mail to non-protonmail users - they receive a link via email that they need a password to access.

You can also export your PGP public key and receive encrypted email from anyone else too.

Re: Encrypted email is still a pain

#159

Isis? I guess we have to trust her after all the ioerror affair, right? Considering he's currently on trial for all her allegations. /sarcasm moxie HAS to agree with his protocol. thegrugq? Wasn't he selling exploits to the highest bidder? http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-th... I can't argue about their qualifications, I argue about their morality. .edit added link.

[deleted]

Re: Encrypted email is still a pain

#160
post #70
post #61

Earlier quoted context omitted.

Forgive my ignorance, but what caused XMPP to fail? Simply the lack of uptake or is there some other reason?

Google's embrace-extend-extinguish destroyed XMPP. They made their chat system XMPP compatible for a short time which caused many people to swap to their solution. When they ended support, most users simply stopped using XMPP.

Even worse, Google never federated with encryption, then Hangouts killed group chats which were XMPP compatible. A few friends and I resisted with several XMPP accounts until they moved to Hangouts. Not to mention all the JEPs that solved the same problems as Hangouts that Google plain ignored for years.
Post reply on HN