4 ms·
The parent statement is very misleading. Here are some significant differentiators between email providers: * Encryption in transmission emails sent and receiv
by hackuser 10y ago
The parent statement is very misleading. Here are some significant differentiators between email providers:
* Encryption in transmission emails sent and received, using SSL/TLS
* Encryption in transmission of webmail sessions, using HTTPS
* Authentication security: Do they use 2 factor or other tech?
* Logging and retention of logs
* Reading your mail to build marketing profiles and social graphs
* Access by employees to your data
* Retaining and sharing your personal data with other businesses
* Security of your account information; can they easily be persuaded to surrender it
* Security of the email provider's systems
* Responsiveness to 3rd party requests for your information, whether private parties in lawsuits or legal authorities with/without warrants
* Cooperation with government surveillance dragnets
Security always is a matter of degree. Email will never be perfectly secure but there are some big differences between providers.
- maxt 10y ago> Authentication security: Do they use 2 factor or other tech? Sorry for sniping this specific one, but 2FA is (more often than not), security theater. It gives the illusion of security like how TSA baggage check is a big dance of scanning, pat-downs, and key ceremonies. For context, consider Yahoo Mail, where emails are read by intelligence agencies before the user even gets them. Does my 2FA help here? Probably not. I can understand that 2FA does have its uses, but frequently I'm seeing it being used like those 'Secured by Comodo SSL' with a picture of a shield to make a would-be shopper feel like the transaction is more secure. It can be theater.
- hackuser 10y ago2FA is generally effective but not enough to guarantee security by itself.
- Xorlev 10y agoIt doesn't help a system-level adversary, but it does help prevent trivial takeovers by malicious actors attempting to get access to your email as a vector to compromise other services. To summarize, 2FA does not prevent email reading if the provider doesn't, however it does help prevent run of the mill takeovers, especially if you've reused a password somewhere. Security is all about defense in depth, it's worth keeping in mind that 2FA is an important step there, but by no means the only one. If you aren't encrypting+signing a message, you've already decided that security requirements of that particular message is minimal.
- acdha 10y agoThat's like arguing that an airbag is safety theater because it doesn't prevent drowning if you drive off of a bridge. MFA is used to prevent a third-party who has access to your credentials from being able to login as you and, in the case of U2F, to prevent a successful phishing attempt from compromising your account. MFA offers no, and never has been billed as, protection against a subverted server or an attacker who can decrypt or tamper with traffic on the wire. Security is a large, complicated problem. There will never be a single measure which protects against every threat.
- threatofrain 10y agoIt seems like you're just ignoring HackUser's argument that security is a degree. Securing against low-level hackers and intrusions increases security, even if it doesn't stop the NSA. It also doesn't stop the CIA from physically spying on you. Securing yourself against low-level hackers and intrusions is not security theater. For most people, these are the most frequent and direct threats. I would also argue that over-securing yourself is security theater. It's the same as overselling insurance products to people whose risk profile doesn't match the product. If you're not making security decisions based on the profile of risks you encounter, then you're engaging in theater to make yourself feel better.
- urda 10y ago> Sorry for sniping this specific one, but 2FA is (more often than not), security theater. This is a completely wrong statement. It helps prevents compromise from non-system-level attackers. Telling a user that 2FA is "security theater" is doing far more harm than good.