3 ms·
What we need next is a widely adopted standard of end-to-end opportunistic encryption, similar to Signal. PKI and PGP are too complex for end users. The proble
by bumholio 8y ago
What we need next is a widely adopted standard of end-to-end opportunistic encryption, similar to Signal. PKI and PGP are too complex for end users.
The problem that prevents such a standard from ever taking off is that, unlike TLS, there is zero interest from major providers to push end-to-end encyption, because they absolutely need access to the plain text for commercial reasons. So they advertise STARTTLS as "email encryption". By that token, CDMA and GSM are "email encryption" as well, it's not like they push the plain text naked over radio.
- bjpbakker 8y ago> PKI and PGP are too complex for end users They are also the only possibilities to provide proper end-to-end encryption. The last thing we need is another proprietary “standard” (remember how those same companies pushed for drm in the w3c spec). Yet the only real change can come when end users understand the implications of using the free email providers. I think this is harder for most than using a pgp email client plugin.
- rakoo 8y agoIt's not a standard, but it's there: autocrypt (https://autocrypt.org https://autocrypt.org) aims to make end to end encryption as easy as possible. It's using PGP underneath but the whole idea is to hide key management (the real pain point) from the user. It's a long term initiative, divided in multiple levels of "compliance" that gradually break compatibility with existing systems more and more. Level 1 is there already, with some implementations.