3 ms·
Is Signal supposed to be more secure than point to point TLS? That doesn’t sound correct to me, and makes me wonder what the complaint about email is. TLS enc
by miscPerson 7y ago
Is Signal supposed to be more secure than point to point TLS?
That doesn’t sound correct to me, and makes me wonder what the complaint about email is.
TLS encryption over a relay network seems like state of the art security, and something I’d trust much more than Signal to hide my metadata — which is how you’ll actually get killed in a “life or death” situation.
- cyphar 7y agoEmail-over-TLS provides encryption to your mail server, not to end-to-end encryption to the recipient of your email. That's what this entire discussion is about (and "encrypted email" in the article refers to PGP encryption, not TLS.)
- miscPerson 7y ago> Basically, he argues you can't trust encrypted email for any content you would not also be fine to send over an TLS secured wire. I was responding to the person above me. If PGP encrypted email is as safe as TLS encrypted lines, which are used every day by major corporations, what’s the complaint? A form POST over TLS through a relay network sounds like it would hide my metadata better than Signal, which is tied to my phone number; and metadata leakage is what actually gets you caught, in the real world. So does depending on a single point of failure for implementation, where it’s easy to coerce a backdoor. He wants to talk about LARPing security — well, tying your secrecy to one of the most monitored and tracked systems in the world, the phone network, sounds exactly like that. I’m genuinely asking what the threat model is, because this sounds like advice that’s going to get people tortured or killed.