3 ms·
I understand that sending email in plaintext is a design issue for email. And that PGP is outdated. However, I think it’s possible to have a system completely
by leshokunin 7y ago
I understand that sending email in plaintext is a design issue for email. And that PGP is outdated.
However, I think it’s possible to have a system completely in the open and still be secure. Bitcoin comes to mind. I don’t think the problem is with email, but with the lax encryption models and the lack of support by email clients and servers alike. Wouldn’t you agree?
- lvh 7y ago"Completely open" is not the only useful property to discuss about a system. Email itself is still fundamentally terrible for secure messaging. Your argument seems to boil down to: "bitcoin is open", "bitcoin can $X", "email is like bitcoin", therefore "email can $X". There are a few flaws in that argument. Firstly, Bitcoin is pseudonymous, it makes no attempt to hide transaction details, which obviously message security would need. Secondly, even if the properties of bitcoin were relevant to messaging, at best you've made the argument that "a system with public transaction records can still do what you need for safe messaging", but not "email specifically can do what you need". There are two ways I could see your argument working out and both are pathological examples. We can do secure comms over TCP, so just design a secure comms system and then all the way at the end choose a blockchain or email as your transport. That sounds true, but also doesn't seem like a useful thought tool that results in improving anyone's communication security tomorrow.
- leshokunin 7y agoI'm not sure why you feel like calling my arguments pathological, or a false equivalence. I'll disregard this. I did not introduce any equivalence about valuation in my argument. I used Bitcoin as an example of a well known open database, where everyone can see the data (arguably an analog to plaintext exchanges) and yet it's secure. Additionally, your point about Bitcoin being pseudonymous also applies to email. You may create your own address, on any number of servers. At a high level, it feels like the pseudonimity is essentially the same. Are you proposing people stop using email and switch to a more secure messaging system, like Signal? Or maybe to make an email app on top of tech similar to Signal (kind of like Protomail?), or to improve email by baking in modern security standards?
- lvh 7y agoI did not call your arguments pathological, I called my own examples pathological to clarify that I am not trying to strawman you: I appreciate that my own examples are almost certainly not what people have in mind when they talk about email security. The pseudonymity is precisely one of the reasons e-mail does not work well. One of the features of secure messaging as it is commonly understood is participant privacy: hiding who participates and ideally when. This is the metadata leakage problem described in the post. You're restating your argument of "bitcoin is public and yet it is secure and so it is possible to have secure systems that are public". I understand that, but you don't appear to have engaged with my counterargument: "secure" is not a universal term, and things that are fine bitcoin transactions are not necessarily fine for secure messaging. Protonmail does not seem like "tech similar to Signal" to me at all. I'm all for implementing stuff like MTA-STS, and I appreciate e-mail isn't going to die any time soon. I think that trying to add E2E-style encryption to e-mail is fundamentally doomed, signing for e-mail is mostly doomed, and yes, private conversations belong on something like Signal.
- leshokunin 7y agoI appreciate the clarification, thanks. It’s interesting that you feel email has a lot of traction and is broken, but you see that as an argument for moving away from it. I would think it’s an opportunity to fix that system, since users are unlikely to switch. I’ve thought quite a bit about what making email like Signal would look like, but I’m curious what’s your take on the overall problem.
- lvh 7y agoI do not think it is meaningfully possible to fix that system (I say meaningfully, because I'm excepting the pathological senses I mentioned above). If you want it to look, feel like email and be compatible, you can't secure it. MTA-STS works because it does not require end users to do anything. If you need end users to change their workflow, you could try to do that with e-mail (which fundamentally can't do all the things you need it, per the post and the PGP post), or you can just make them use a non-broken protocol.