4 ms·
I think that's because email, fundamentally just isn't very secure. Lots of email servers support fallback to non-encrypted, plaintext transmission, which can
by laurentMiguel 8y ago
I think that's because email, fundamentally just isn't very secure.
Lots of email servers support fallback to non-encrypted, plaintext transmission, which can expose entire chains of replies to MITM attacks with a single message being routed questionably. [0,1,2] End-to-end encryption, via user-defined keys is actively discouraged by those who might assuredly know better, and be in a position to change minds. Usually, the cop out comes in the form of "too complicated for non-technical/less-technical users, and thus potentially harmful to profits."
As if to say, we've been espousing the use of an insecure method of communication for decades, so, to suddenly reverse our position, and encourage bring-your-own-encryption might provoke discussions of liability, or something. Nevermind, the premise of ad tech and scanning user messages, to sell data.
But you know, running your own server, and hiring people who can't be bothered to go deeper than using word art in MS PowerPoint slides, well, hey. Bring a horse to water... know what I'm saying?
PGP is easy to use. At this point, I'd like to think people are fatigued enough by the bottomless pit of nightmares we've fallen into, that they'd step up and tell people: yes, people are using SSH keys and SSL keys billions of times a day. It's okay to use PGP on your email. Go ahead, start doing it.
Or, you know, whatever. Lose another election. Right?
[0] https://en.wikipedia.org/wiki/Email_encryption https://en.wikipedia.org/wiki/Email_encryption
[1] https://blog.filippo.io/the-sad-state-of-smtp-encryption/ https://blog.filippo.io/the-sad-state-of-smtp-encryption/
[2] https://security.stackexchange.com/questions/51552/how-insecure-is-pop-imap-smtp https://security.stackexchange.com/questions/51552/how-insec...
- nerdponx 8y agoYou don't need to MITM anything if your campaign manager uses the password "joealison10231997" for every website.
- laurentMiguel 8y agoYeah, there's no accounting for glaring cluelessness. Leaving S3 buckets open to the world, and totally unencrypted, for example. Downloading and running *.exe email attachments, destroying systems with ransomware, and so on. Encryption can be its own foot gun. It can aid attackers, by totally destroying evidence that might exonerate you from being framed for other crimes. It can cost people dearly, in terms of lost data. Consider how many people have lost old bitcoin wallets, containing small fortunes, and similar tails of woe. But look at how that plays out. A dropped bitcoin wallet, gone forever. The failure mode of something like that is often a better look than things going the other way. Imagine that same bitcoin wallet getting stolen, and seeing the thief profit from it. Sort of like watching elections get stolen, no? So, think about that, the next time you warn someone against forcing you to exchange PGP keys, in order to communicate more securely.
- tptacek 8y agoU2F keys were invented in part because the glaringly clueless employees at Google were routinely shown to be phishable. People who dismiss phishing as a threat vector betray a lack of understanding of how difficult it is to mitigate reliably.
- ISL 8y agoPGP is so easy to use that the first day I attempted to configure it, I accidentally emailed my friends my private, rather than public, key. I await the day that a great PGP client for everyone might emerge, but I'm not sure that it is possible, nor am I certain that people will want it. There is substantial utility involved in letting Google read all of my email for spam/malware filtering and more.
- laurentMiguel 8y agoThe strong will survive. On some level you have to make peace with the way evolution really works. Or, you know, wind up extinct.
- tptacek 8y agoPGP addresses literally none of the operational security problems congressional campaigns have. No matter how you protect individual emails, for most users (and probably every single congressional campaign staffer) your email account is still the most important account you have, the key to every other account you control. And PGP doesn't do a thing about incoming emails with malicious attachments. People think PGP is important for campaigns because they want it to be important, not because there's any empirical evidence that it is important.
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- arcliteIndira 8y agoWow, so, you really believe that asking people to lock up their important messages to you, using a public key that you've provided through a verified, alternate non-email channel really won't work? PGP actually does do something about incoming email attachments. It offers the opportunity to programmatically reject anything that is non-encrypted ASCII text, and renders malicious files as non-executable ASCII text, when such policies are properly enforced. At this point, the promiscuous user is protected from delving deeper into emails. The server can effectively isolate attachments entirely, by proxying mail delivery, and refusing to decrypt attachments automatically. This would further defend against account compromise, through practices that require special handling of attachments. Email then becomes a medium of communication, rather than file transfer, and file transfer is pushed to other protocols and applications. Sort of like a point-and-call policy. Forcing a user to cognitively jump through hoops to discover the contents of an attachment, when they should really be using email for the exchange of messages with humans, or automated control messages, such as multi-factor auth. Doing something like this limits email to character data only, rather than interpretable instructions. You know, much in the way we don't execute JavaScript from an email context. Example: -----BEGIN PGP PUBLIC KEY BLOCK----- mQENBFuPKDYBCAC6xIbamQ3hTFCp8qcu8fLiz8XrSMXod/Xo5/iV/7FbqN8pE6uB 9EFyrWX1gy6ZNP+EGXrQ017sNcGHL7LquV74m+Z4/CRZlKpHMR2U9WEIhjgfL46c vtQP/l9MB39P/VK3xsPXHTWSBiVdDdhWQTTZ5Tl88Zwo5n81ToOMFDLSXqZThlBl CjUNOmHt1nLpkUzyn5h8c9/x2gNe/ArD2nY6DewHZCALLSDAEKLqrru+v2N6ABRh Ad7GTVaHrD7aM84nlDMYiJmWSbx+IX2i4sxOeescjFPCmgjIuLLfIv94Oc7a6cV/ O7JzaX5Vyr+wBiHqhG2Xrwo+/V6+hRLv3Aj7ABEBAAG0H2xhdXJlbnQgbWlndWVs IDxsbUBleGFtcGxlLmNvbT6JAVQEEwEIAD4WIQRrmP8aKYfcI7jMLtoYF2U5ECzk nQUCW48oNgIbAwUJA8JnAAULCQgHAgYVCgkICwIEFgIDAQIeAQIXgAAKCRAYF2U5 ECzkneaeCACVHmasl2V+gz2dDKJr3ELuCM82ZGltq44kSj2Wod5KyvAulb8XB4Ox d5LXw8rdLuHiGl8vFrPljRO1do+8ahQyPy6Sk5UNb73zi8ujubhLHm/jpSdO5lUO ryb/TN4lnBnGSDeYkUtKn2FUr0+i4EgnqAi2L2svQoDwzzyyeWrkXBgqqm1NT0bw hbBhQfozdafqvFF3gBfaBqrFpD/KAgHzmTe3YejrD9tJTVJamTsEvmMXNMhaXF3s FVqlWGoGr0/17Ft75SyuKj+ssJ7oxeblxhocUum8XvtmVlu8Ee/wxqugApeDLN0x 6cqEH837QIU6vQgx3mGK7Vv035uRru1yuQENBFuPKDYBCADC1Hea+6AMj7gwNnfX tOIJ8X/rKeqw6u3Up1vt7DC3IOrml0AQHk08bklLbXokO/GlW0uUwX/tqKeIz35y l+uzqBooR62H99CQc36trN96GD6zxeVYlbMpWdTzPqgxSVmEx9EvfCPhsgCueTz1 oTJw5SW4dUOHuL3k8R/cEFraJJpigp8PceXJWsxinUTOVSKH1VhWsZaActRRicf4 Y9GOcEJhgFhNlvVgFW+x/+hYL3vLXeUNTb6UCH6O9X0I+zv03VbLO/GdZFGA3Vps MYzzk8y/n93DkAIAD6vCPZAvcOLGMXaEv5GER2Scpv/sgINefh67+ExH/Vc8ZrUl C421ABEBAAGJATwEGAEIACYWIQRrmP8aKYfcI7jMLtoYF2U5ECzknQUCW48oNgIb DAUJA8JnAAAKCRAYF2U5ECzknTEMB/0ZcvUYZq5IlqsBNYdZjCaXY5KQqWqKnQlW jISSM7RmjCQwDqjTgyOVfl19PeVpj63h/tAPTXcsJ31LlpyHUklBVAeQmXuvMRry WMfLeHa5nAQmS3VgZNyahFyps+mGFiDChy7Zz14v/bpfUAeqBIY4txVHwT4fLWEM M1ZRbu8DcgwUErXt5xe5kOJZRWd8Q/xnspn9Tg+QvdWF67xi4CZ7RTl2+aL8MshT 051atXtkskDomQD/kNhP757cUuvDBkC4FydP8rztMdNLUiiC0L1R6V4bxhr4Yhsh dbf+w0XrcuUaSnaka5TAeh+NCK//CoUsnVF/fun2bJ8bRikMPwxy =/JKx -----END PGP PUBLIC KEY BLOCK-----