3 ms·
I don't think it is? Fact is, if you use SMTP, you can only see if the content is encrypted or not once you receive part of it. The techniques I mentioned are t
by cryptarch 10y ago
I don't think it is? Fact is, if you use SMTP, you can only see if the content is encrypted or not once you receive part of it. The techniques I mentioned are to reduce the risk of these (partial) plaintexts being captured, but should be paired with a refusal to deliver.
There's no way to stop a user's contacts sending plaintext emails for all the ISP's/intelligence agencies to see, but you can make sure you touch them as little as possible when they do arrive (see GP) and discourage those contacts from doing it again by not delivering/returning error codes.
Unless you drop SMTP altogether. I think Riot with E2E is looking pretty good, but it's not been hardened at all.
- ryanlol 10y ago>Fact is, if you use SMTP, you can only see if the content is encrypted or not once you receive part of it. Then don't put your users at risk by using SMTP. >The techniques I mentioned are to reduce the risk of these (partial) plaintexts being captured, but should be paired with a refusal to deliver. Techniques you mentioned are nothing more than pointless showmanship, which you'll cease as soon as the government asks you to. >There's no way to stop a user's contacts sending plaintext emails for all the ISP's/intelligence agencies to see Which is why you shouldn't put them in a situation where they will inevitably do so. >Unless you drop SMTP altogether. If you're going to launch a service that advertises secure communications, you have to. Otherwise you're just endangering your users, just like lavabit did. We're not talking hypotheticals here. Lavabit already fucked over their users trying to pull silliness like this.