Live data from Hacker News

Advocating for privacy in Australia

fastmail.blog

61–70 of 112 posts

Re: Advocating for privacy in Australia

#61

Earlier quoted context omitted.

I'm not sure what's more unrealistic, that you can recover from a punch or that it's viable to have per-user judge blacklists... https://www.smh.com.au/national/teenager-daniel-christie-die... I guess it's the punch then.

Ok how does having access to sucker puncher's phone help me here ? I will still die.

I think we're talking past each other here. I was pointing out an example of how there's no absolute guarantees that another human being won't mess up your life, not that you need to look at punchers' phones.

Re: Advocating for privacy in Australia

#62

Earlier quoted context omitted.

Ok how does having access to sucker puncher's phone help me here ? I will still die.

I think we're talking past each other here. I was pointing out an example of how there's no absolute guarantees that another human being won't mess up your life, not that you need to look at punchers' phones.

The problem: I am asked to give up privacy. What I am getting in return, I can get more cheapely.

I can avoid sucker punchers. No need to give up privacy. I can avoid going outside a walled garden. No need to give up privacy.

You seem to be saying that its fair trade. I disagree.

Re: Advocating for privacy in Australia

#63

Earlier quoted context omitted.

I wonder why no one has ever made PGP user-friendly. Some might argue whatsapp or signal or Telegram E2E is exactly that. I talk about the email.

ProtonMail say that they've made PGP user-friendly, and I'm inclined to agree with them: https://protonmail.com/support/knowledge-base/how-to-use-pgp... "This means that with ProtonMail, anybody can use PGP, regardless of their technical knowledge." Something like this would make things even more transparent to end users: https://autocrypt.org/

Imo ProtoMail is snake oil:

When you’re communicating with email addresses outside of ProtonMail, their servers will see your emails. Your emails might then be encrypted “at rest”, but they’ve passed through their servers unencrypted anyway.

To workaround it, for sending to email addresses without a ProtonMail account, AFAIK they also give the possibility to send a link to a ProtonMail interface for decryption.

And also web interfaces are inherently insecure for E2E encryption, which ProtonMail encourages.

This is not how email is supposed to work.

Speaking of email ProtonMail also doesn’t work via standard IMAP and SMTP. You need an adapter to use classic mail clients and that only works on the desktop.

In other words ProtonMail is anti-standards.

And for me standards are more important than promises of privacy that an email service can’t really meet.

Unless you’re doing PGP or similar, independent of the email service being used, then email is incompatible with encryption.

Re: Advocating for privacy in Australia

#64
post #2

Fastmail should relocate to Canada. Just throwing suggestions out there.

Damn, I just lost $100. Thanks. We had a bet on how long it would take for somebody to say "just relocate your entire company and all your staff's lives to another jurisdiction".

It's the best solution. Given how mindbogglingly expensive your product is, you could try your best at least.

Re: Advocating for privacy in Australia

#65

Earlier quoted context omitted.

We never offered, and never claimed to offer, a safe haven for people who have broken the law in both Australia and their own country to hide from the police. We don't place ourselves above law enforcement. We don't have data trading agreements with anybody, and we don't sell or provide backdoor channels - we only provide data in response to lawful warrants. That's the right amount of privacy and the right tradeoff w…

> We don't place ourselves above law enforcement. Of course this is reasonable, but I'm curious what you think of companies who do put themselves above law enforcement when it's the right thing to do. i.e. lawmakers do not always make laws that are right and law enforcement does not always do the right thing when interpreting and enforcing laws. A case to cite might be Apple vs. FBI in 2016. The company placed itself…

> I'm curious what you think of companies who do put themselves above law enforcement when it's the right thing to do ... A case to cite might be Apple vs. FBI in 2016. The company placed itself above law enforcement.

Apple did no such thing. They asserted their legal rights. They used the exact mechanism -- the law -- that you are saying they ignored or held themselves above.

Re: Advocating for privacy in Australia

#66

Earlier quoted context omitted.

The problem is simply that you expect the impossible. Either you give the factual power to access your emails to some party, then whoever you give that power to can as a matter of fact access your emails, and in particular that means that they can be coerced into accessing your emails, or you don't give them the power, then they can't. You are demanding that they offer a product where they have the power to access yo…

Not sure what you are getting at exactly, but you can provide browser based email where the browser using J.S. decrypts the email. Obviously need to figure a way to make that AA proof.

You now trust the provider’s JS not to be hijacked. I know of no good infrastructure at present for managing this risk; at the very least, you’ll need an independent browser extension for auditing all the code and ensuring that no unaudited code is permitted, and you’ll need the provider to support it in some measure as well, so that the service doesn’t break when new, not-yet-audited versions of the code are rolled out.

Re: Advocating for privacy in Australia

#67
post #15

Their "Actions we are taking" section is almost entirely composed of a political lobbying strategy. Given the outcome of the vote, 44 votes for and only 12 against, their plan doesn't exude much confidence. I would have expected plans to move data and key technologists out of Australia at the very least. The company I work for uses Fastmail but our CEO has already decided to switch mail providers sometime in 2019. I…

> The company I work for uses Fastmail but our CEO has already decided to switch mail providers sometime in 2019. I don't know what other service they'll choose.

If the reason for switching is because of such laws, your company could look at providers outside the:

* Five Eyes (Australia, Canada, New Zealand, the United Kingdom and the United States)

* Nine Eyes (Five Eyes plus Denmark, France, the Netherlands and Norway)

* and Fourteen Eyes (Nine Eyes plus Belgium, Germany, Italy, Spain and Sweden).

There are very few well known and good providers outside these jurisdictions, in my knowledge.

Re: Advocating for privacy in Australia

#68

Earlier quoted context omitted.

ProtonMail say that they've made PGP user-friendly, and I'm inclined to agree with them: https://protonmail.com/support/knowledge-base/how-to-use-pgp... "This means that with ProtonMail, anybody can use PGP, regardless of their technical knowledge." Something like this would make things even more transparent to end users: https://autocrypt.org/

Imo ProtoMail is snake oil: When you’re communicating with email addresses outside of ProtonMail, their servers will see your emails. Your emails might then be encrypted “at rest”, but they’ve passed through their servers unencrypted anyway. To workaround it, for sending to email addresses without a ProtonMail account, AFAIK they also give the possibility to send a link to a ProtonMail interface for decryption. And a…

That's no longer the case, you can set PM to send PGP encrypted mail directly, in which case the mail won't be in cleartext on their servers.

Sending a link with a symmetrically encrypted mail is still possible for users without PGP but those aren't in cleartext on the server either (they are encryped and decrypted) in the client.

(in theory, PM could swap code in the webclients but you can use the Bridge or Android/iOS app to circumvent that hole easily)

Re: Advocating for privacy in Australia

#69

Earlier quoted context omitted.

ProtonMail say that they've made PGP user-friendly, and I'm inclined to agree with them: https://protonmail.com/support/knowledge-base/how-to-use-pgp... "This means that with ProtonMail, anybody can use PGP, regardless of their technical knowledge." Something like this would make things even more transparent to end users: https://autocrypt.org/

Imo ProtoMail is snake oil: When you’re communicating with email addresses outside of ProtonMail, their servers will see your emails. Your emails might then be encrypted “at rest”, but they’ve passed through their servers unencrypted anyway. To workaround it, for sending to email addresses without a ProtonMail account, AFAIK they also give the possibility to send a link to a ProtonMail interface for decryption. And a…

> When you’re communicating with email addresses outside of ProtonMail, their servers will see your emails. Your emails might then be encrypted “at rest”, but they’ve passed through their servers unencrypted anyway.

Decryption is done in the browsers so it's not passing through the servers unencrypted. (ProtonMail is one of the biggest contributors to Openpgpjs).

> To workaround it, for sending to email addresses without a ProtonMail account, AFAIK they also give the possibility to send a link to a ProtonMail interface for decryption.

And you can add the recipient PGP key in ProtonMail settings so it's pure PGP. (I've heard that they're working on Web Key Directory support for automatic contact key retrieval)

> And also web interfaces are inherently insecure for E2E encryption, which ProtonMail encourages.

Not strictly true. The problem is web interface hosted on a foreign host. For a secure web interface see e.g. Mailpile.

There are also other ways of minimizing risk like using Mailvelope that communicates with GnuPG through Native Messaging.

> In other words ProtonMail is anti-standards.

Not for all standards for example ProtonMail is very active in OpenPGP mailing list.

For the record I'm not using ProtonMail but I like that they're promoting PGP by showing that it can be made relatively easy. Too much people think that the UI complexity in PGP is intrinsic.

Re: Advocating for privacy in Australia

#70
post #5

Earlier quoted context omitted.

I didn't think Canada was doing much better than us (Australia) with these kind of crazy, over-reaching laws. You'd probably have to find somewhere in Europe.

Switzerland might be better as not part of five eyes.

Not part of any "X eyes" arrangement, but at least some parties within Switzerland are strongly engaged in partnering with foreign secret services, apparently without any consequences by the Swiss state: https://en.wikipedia.org/wiki/Crypto_AG#Compromised_machines
Post reply on HN