4 ms·
> Therefore, in 2022 a daily email traffic of 333.2 billion emails is expected I mean, sure, but let's be honest, a big majority of that is going to be spam, t
by mkdirp 5y ago
> Therefore, in 2022 a daily email traffic of 333.2 billion emails is expected
I mean, sure, but let's be honest, a big majority of that is going to be spam, the next step down from that are silly little things like email verifications, password resets, notifications, newsletter spam, and other similar crap. As a millennial who doesn't touch emails for work or for personal reasons (because there is Slack, Signal or some other alternative to those two), I could very well be out of touch, but I'd be surprised if actual legitimate emails (both business and consumer) are more than 5% of that number.
I suppose 5% is still a big number, putting it at a comfortable ~16 billion emails.
Anyway, yes, we should be using encryption by default wherever possible, but honestly, encryption isn't easy for the common folk, which is going to be the majority of those 333 billion. Heck, I migrated away from PM and I struggled with a lot of it. As someone who mostly lives in the CLI, GnuPG is not easy to use. Something like MailVelope makes it easier, but still not that easy.
Then there is the matter of administration. Your sysadmin, especially of the bigger orgs, do not want encryption on your emails. Especially when the business you're in is regulated. Imagine being able to casually leak something without anyone knowing what's in the content? I know regulation is usually not a good answer for why not, but within a business, yes, it totally is. As a customer of Big Bank Corp, I do not want employees to be able to mess with my data, money, or worse, the money of the bank so that it can fail and for my money (or the tax payer's in case of govt protections) to be gone because everyone's emails were encrypted.
The only viable solution here is something like ProtonMail, which actually makes it easier to use, at $/£/€ 5 per month, not many are able to afford to part with that. And no, their free tier is really not that great. But regardless, even PM doesn't really help if a non PM user sends you an email.
- nonrandomstring 5y ago> Your sysadmin, especially of the bigger orgs, do not want encryption on your emails. This is the nub of it. People don't know what they want from technology. Or rather, they are conflicted. Our collective illusion that rational technical concerns drive technology hides the reality that all digital technology is a set of power relations that help or hinder different spheres of interest - often within the same group or individuals. Many people want to do bad things and we have even created laws that insist people do bad things (as piss poor solutionism to the original bad things). Hole, spade, keep digging. The problem of email can be seen two ways: 1. Bad protocols. 2. Bad actors. Naturally, as techies we attack (1). Just encrypt it all. Zero trust. Train everybody to use encryption. Enforce it. Let's call that the "Rule of Tech". By contrast, let's call (2) the "Rule of Law". There are already more than enough laws that deal with the fundamental immorality of reading someone else's private correspondence. However we have carved out so many exceptions, including those in the interests of our own profits, that we now just assume (2) is an intractable feature of the world. It isn't. Email has shown us time and time again that the solutionism of getting people to use encryption is nigh-on impossible. Even the US government have pretty much said PGP is a dead approach. So let's ask the question nobody wants to hear; Would it be economically wiser to enter into more layers of solutions, securing email at the technical and policy level (1), or to take a GDPR-like approach of bolstering the rule of law? Let's be clear - this would mean taking NSA, GCHQ, Google, Microsoft etc to court, fining and if necessary dismantling the assets of those who interfere with private communication. It would mean stripping ISPs of listening taps, and auditing server rooms. It would mean something approcimating to a civic cyber police force acting IN THE INTERESTS of the public, rather than against us. I realise how naive that sounds in this cynical epoch. But I think the ultimate cost of 'zero-trust' society may greatly outweigh the political cost of using the Rule of Law to re-establish 'trusted' networks. Can't we give the law a chance?
- mkdirp 5y ago> Can't we give the law a chance? No because law makers have at every turn attempted to undermine encryption. What makes you think they'll suddenly fine and/or dismantle the assets of the NSA/GCHQ? These are the agencies that have been central to both countries' security in times of war. Times of war that seemingly has never ended.
- nonrandomstring 5y agoI think one should not confuse support for the Rule of Law with exasperation at the parochial "lawmakers" who are poorly educated, motivated by power and money, and thus essentially traitors to the principle. That would be cynicism.
- upofadown 5y ago>Even the US government have pretty much said PGP is a dead approach. I would be very interested in a reference to that...
- nonrandomstring 5y agoSo would I , but I can't find it so you'll have to do your own digging. It was posted here on HN about 3 weeks ago. It was a report by a major TLA announcing a significant revision of cybersecurity "best practices", one of which was to stop pushing email encryption as it's deemed more trouble than it's worth.
- nonrandomstring 5y agoFound it at last. It's back on the front page of HN https://news.ycombinator.com/item?id=30530592 https://news.ycombinator.com/item?id=30530592 It's the Whitehouse.
- Karrot_Kream 5y agoYou're starting down a very interesting/sanguine line of questioning, but you're leaving out another complication of "bad actors". The number of sysadmins and netops out there is very large. While some certainly are malicious or are motivated by privacy-violating desires (whether organizational or personal), many of them are just overworked, underpaid, or underqualified. When it comes to email, a single unencrypted link is all it takes to break the trusted chain of Email. Given the sheer multiplicity of the problem, IMO a GDPR-like approach would meet too much pushback from organizations who already don't want to hire a sysadmin. In this case the reason why I think it's worth focusing on the protocol is that, when an E2E encrypted protocol is designed properly, it removes an entire attack surface and significantly decreases the amount of possible human error. I think encrypted L7 overlay networks are a good solution to step aside these problems at the cost of a bit of overhead (wrapping packets, etc)
- charcircuit 5y agoThe only people who send me messages on email are recruiters. I'd honestly prefer if they'd just discord me so we could have synchronous communication instead of having to wait 24+ hours for a response.
- jigarjain 5y ago> their free tier is really not that great. Why do you think that their free tier is not great? AFAIK, it works like any other free tier email service but with encryption. Though it does have a limited storage space (which has increased recently). Anyone who would need more than that & has chosen to use PM probably also understands the cost of free products available & will be willing to get paid service Disclaimer - I am a paid PM user (converted from free tier after using it for few years)
- _wldu 5y agoOrganizations may use ADK (additional decryption key) when they want to access what users are emailing to each other (for compliance/security reasons). It can be done with vendor provided software or manually. Here is a short description of how it works: https://www.go350.com/posts/age-file-encryption/#additional-decryption-key-adk https://www.go350.com/posts/age-file-encryption/#additional-...
- hkt 5y agoDelta is also viable. I use it for IM and it is TOFU based PGP encryption. It works OK for general email too, though that's not the focus. See: https://delta.chat/en/ https://delta.chat/en/