4 ms·
He is referencing end to end encryption. Google can see Your to/from/subject/metadata headers even if you bother to use gpg
by Ninn 7y ago
He is referencing end to end encryption. Google can see Your to/from/subject/metadata headers even if you bother to use gpg
- Glosster 7y agoThen that's a problem with us using a centralized system (Google) for emails, right? So email is not really decentralized.
- cyphar 7y agoReplace "Google" with "your email provider". Even if there were many diverse email providers with significant adoption, the problem would remain. Unless you're using PGP (and -- critically -- the other people know how to use it as well), then your email is stored as plaintext on your email provider's email server (and the email provider of anyone you send the email to, as well as any forwarding agents that passed the email along).
- ekianjo 7y agoNothing prevents you from not using Gmail.
- cyphar 7y agoIf any of the people you are communicating with are using an email provider that they don't personally host, then the problem is exactly the same. In fact, arguably a better comparison to E2EE is that they have to host an email server on each of their devices (which precisely zero people do).
- ekianjo 7y agoNot at all. As long as your keys to decrypt messages are on your device only, the body of the message will be gibberish for your email host. You could argue that metadata is in jeopardy since the email recipient is not obfuscated but that is the same thing with Signal where you rely on a central server with phone numbers connecting people to each other's.
- cyphar 7y ago> As long as your keys to decrypt messages are on your device only, the body of the message will be gibberish for your email host. The original comment didn't imply usage of PGP. They asked whether messages being encrypted between mail hosts counted as E2EE -- and remember that the number of email users who also use PGP is close to 0%. But with PGP, sure -- though PGP has many other problems which make it a questionable choice unless you are forced to use email for some other reason: * Most email clients don't know how to use it and will often allow you to accidentally reply to an encrypted email with clear-text. This comes back to "every single one of the recipients of your email needs to actively know how to use it correctly". * PGP doesn't have perfect forward secrecy (instead depending on long-lived keys) which means your entire conversation history is threatened if your keys ever become compromised. * Most PGP implementations are not using properly-authenticated cryptography (yeah, there's the MDC but Efail showed that there were serious bugs in its design -- and backwards compatibility made it bypassable). OpenPGP still hasn't standardised AEAD.
- waldfee91 7y agoYou could encrypt subject, from field and most metadata (some mail servers don't accept garbled from fields though). To field can not be encrypted, but that's the same on Signal (the server needs to know where to deliver the message to).
- rakoo 7y agoPGP alone is no longer sufficient to talk about encryption in emails. The real step up is autocrypt (https://autocrypt.org/ https://autocrypt.org/) that encrypts almost everything. Unfortunately the way email works it is still possible to know who is talking to who.