5 ms·
"Last but not least, every COI client app can offer a variety of end to end encryption options to keep your communication absolutely private." The fact I had t
by kelnage 8y ago
"Last but not least, every COI client app can offer a variety of end to end encryption options to keep your communication absolutely private."
The fact I had to read quite so far down the page to find this snippet emphasises to me how unimportant the developers of this protocol see E2E encryption to be :( And leaving it to the client seems like a terrible idea, especially if there are options, as then surely it will depend on what E2E encryption options your and your recipient's clients supports?
- Aeolun 8y agoI don’t really understand why or how this is different from your current trust model around email...?
- calgoo 8y agoIMO its comparing itself to Whatsapp and other messaging apps that do have end to end encryption. Thats why the current email trust model is not as important.
- renholder 8y agoI think that was OP's point? To tout it as an alternative, or "breaking free" of WhatsApp, is to discredit one of the pivotal reasons that people use WhatsApp, which is E2E encryption.
- adrianN 8y agoI think most people who use WhatsApp don't even know what E2E encryption is and use it only because their peers are using it.
- Freak_NL 8y agoThe pivotal reason people use WhatsApp is because it can be used without paying (with money that is), and because up to 90% of people in any country use it¹. That's it. Facebook could remove E2E today, and lose only a fraction of its WhatsApp users. Of course many little annoyances might mean that a competitor may step up, but WhatsApp is incumbent, and this is no longer about features or technology. It's all about the fact that your friends, family, and colleagues are using it. It can safely ride the network effect for years. I welcome any protocol that makes chat something that is available for everyone with a computing device again — not just on approved smartphone operating systems. 1: Varies quite a bit per country.
- eXpl0it3r 8y agoNot to forget that WhatsApp started out without E2E and didn't implement E2E for quite a while. WhatsApp simply won the race by being there early on and getting the critical mass. From there on out people are locked in, because everyone else is there.
- beagle3 8y agoI would add: WhatsApp was there, free and very well done. Even in countries that had free domestic text messages (where the “free” factor was much less important), WhatsApp nailed group messaging better than anything else available at the time. Also, by using phone numbers they skipped the entire “create account / invite friends” stage, making for a much smoother bootstrap.
- alrs 8y agoIt must vary a lot. I live in the United States and I've never encountered anyone who wanted to communicate over WhatsApp.
- Semaphor 8y agoIn South Africa WhatsApp is almost required. It's ubiquitous. In Germany I'd say it's by far the most common chat client, even my parents use it.
- pbhjpbhj 8y agoSame in UK, I installed it as almost all my (relatively non-technical) friends and family were using it. It's much more commonly used than Facebook, or email, for direct to groups communications.
- kalleboo 8y agoCertainly it varies a lot. But back in 2017 they had 1.5 billion monthly active users (20% of the world population). The US is probably an outlier here (I hear SMS is still popular in the US whereas I literally can't remember the last time I sent an SMS, it must be over 5 years ago)
- michael-ax 8y agoI agree. Fascinating, but its not exactly 'Signal' (end-to-end encryption with perfect forward secrecy) over IMAP. That would be something I'd jump on, fwiw.
- vermilingua 8y agoI don’t think that means the developers don’t consider it important; it means that the people that want E2E aren’t necessarily in their primary audience. The prime target of this protocol isn’t power users and developers; it’s the overwhelming majority of users that stick to siloed messaging because it’s convenient, and everyone has it. First and foremost, they need to be shown that this is more convenient, and has a larger and more accessible network.
- stdclass 8y agoI would argue that every user wants E2E, they just don't know (enough) about it. E2E should be the default.
- projektfu 8y agoIt can’t be default because the protocol is degradable by design. I would agree that they could advocate a method to harmonize all COI-aware IMAP servers. But it’s hard to get E2E encryption in a heterogeneous, legacy environment.
- m0dest 8y agoSupport for S/MIME encryption is pretty ubiquitous at this point, right? There are practical issues with CAs, but nothing insurmountable.
- richardwhiuk 8y agoNot even close to ubiquitous.
- qrbLPHiKpiux 8y agoI thought you can’t encrypt data at rest on an imap server? Apple even says this in their security guide... right?
- Arnt 8y agoYou can in theory. But you have to choose: Either your data is encrypted or it's searchable. So in practice you prefer searchability. Someone will probably say something about homomorphic encryption. Not deployed AFAIK, and deploying will be difficult if you want to ensure that you can search your encrypted mail but others cannot.
- devit 8y agoYou can just search on the client after decrypting.
- Arnt 8y agoOh, sure. Just download all of the messages. The problem with that is that you run into users like me, who have 25 years of archived email, a mobile phone, and who travel abroad.
- gsich 8y agoJust for a backups sake you should do it.
- Arnt 8y agoAre you suggesting that if I want to search on a particular device, then that device should hold my backup storage? If so, then I disagree and have chosen to store my backups on a device that's behind two locked doors, hard to reach, well protected from being accidentally disturbed, and which doesn't run unrelated software.
- gsich 8y ago
- ttsda 8y agoThe draft spec available in the confluence wiki says the following: >A COI-compliant client MAY support the Autocrypt standard to ease end to end encryption scenarios. >TODO: Consider using more secure lookup mechanisms for encryption keys. Also check for existing encryption keys before auto-generating a new encryption key set.