5 ms·
I'm still surprised Apple hasn't had a stab at making the PGP process seamless. I always imagined they'd generate keys on the device, sync via iCloud and publis
by willhackett 3y ago
I'm still surprised Apple hasn't had a stab at making the PGP process seamless. I always imagined they'd generate keys on the device, sync via iCloud and publish public keys.
I was hoping their big song and dance over privacy would lead the likes of Gmail, Outlook, etc to adopt native PGP too.
Wishful thinking. :')
- SquareWheel 3y agoThey do offer client-side encryption for enterprise, but it uses S/MIME rather than PGP. https://support.google.com/a/answer/10741897 https://support.google.com/a/answer/10741897 https://security.googleblog.com/2023/06/gmail-client-side-encryption-deep-dive.html https://security.googleblog.com/2023/06/gmail-client-side-en...
- willhackett 3y agoThey have the opportunity to make PGP completely seamless.
- teddyh 3y agoExcept for the fact that if your e-mails are encrypted, you can’t search them in Apple Mail.
- paulryanrogers 3y agoThis seems more like a problem in Apple Mail than SMIME
- reaperman 3y agoIndeed. The client could maintain a vector search table that contains "unencrypted" data from emails, but the table itself could be separately encrypted on-device to the same level of security as the rest of the iPhone/MacBook/etc (T2/TPM/HSM chip). Definitely a client problem.
- teddyh 3y agoOh, yes. I never claimed otherwise. But if you’re a user of Apple Mail and are looking for a solution for encrypted mails today, you should be aware of this.
- nashashmi 3y agoThey would invent an entirely new mail protocol to make encrypted mail work. It would probably go like this: 1. User writes recipient address. 2. Server checks the address and asks mail host for encryption key. 3. Mail host sends encryption key 4. User continues writing email. Similar to how UDP https works.
- crossroadsguy 3y ago5. Only works on M2 Apple hardware (ps. major functionalities only supported from M3 Pro devices)
- bunga-bunga 3y ago> an entirely new mail protocol I'd call it Wave
- AceJohnny2 3y agoThere are many, many use-case problems with PGP and email, to the point that most serious security people just don't bother with PGP. It's relegated to niche and die-hard users. The problems are so many that it's better to use an alternative messaging platform that is built from the ground-up with encryption in mind, like Signal. For example... 1. what happens when you send an encrypted email, and the recipient forwards it? 2. What happens when the recipient replies? Will your original email be included encrypted, or decrypted? Most likely the latter, meaning the same cleartext is now present in two messages. 3. What happens when you email more than one person? What entity handles the encryption for each recipient? 3.a. what if only some of your recipients support encryption? What's the point of encrypting if you're sending some in the clear anyhow? 4. What happens when you email a mailing list, with unknown participants?... 5. What should be canonically encrypted? Just the message body? What about the subject, which is a header of the email? What about any other headers? 5.a. Oh you just want it signed? Again, what is canonically getting signed? How does that survive the many transformations the text receives in a conversation?
- AceJohnny2 3y agoI'd say the problem of PGP and email is that it suffers from a "90% of features is good enough" mindset that is prevalent in open-source (which otherwise isn't a bad thing!) But when it comes to true security, 90%, or even 99%, is so far from "good enough" as to be pointless.
- rovr138 3y agoDo you have examples? Not sure if you mean security or ergonomics.
- colordrops 3y agoThese big companies could have extended or replaced the current mail protocol to support these cases if they wished.
- deleted 3y ago[deleted]
- woodruffw 3y agoApple is actually somewhat serious about privacy and security; PGP is much closer to the “performative” end of the privacy and security spectrum than to the “serious” end.
- tptacek 3y agoI don't think anybody is ever going to do this, because encrypted email doesn't work. https://latacora.micro.blog/2020/02/19/stop-using-encrypted.html https://latacora.micro.blog/2020/02/19/stop-using-encrypted....
- upofadown 3y agoApple is already in hot water over law enforcement access. Just imagine the political kerfuffle if they started supporting a messaging technology that even the NSA couldn't break[1]... [1] https://www.spiegel.de/international/germany/inside-the-nsa-s-war-on-internet-security-a-1010361.html https://www.spiegel.de/international/germany/inside-the-nsa-...
- andrewaylett 3y agoYou're assuming that using PGP for all email is a good thing. I'm unconvinced that's the case. Email is already encrypted in transit in most cases, and modern TLS has benefits over PGP. A big one is forward secrecy -- if you leak a TLS key, you haven't leaked all your past messages. But if you leak a key for an encryption scheme that doesn't support forward secrecy, you leak everything, as WikiLeaks found to their cost[0]. Mitigating this issue -- especially in the context of email -- is hard. Also, PGP encrypts message data but not message metadata. Transport encryption still protects the per-message metadata, but adding PGP doesn't help. Lastly, for this note at least, adding PGP into email in a way that is seamless will almost inevitably still involve some level of trust in your email provider. I'm all in favour of end-to-end encryption, but not at any cost. New protocols can have new capabilities, but for email my judgement is that your personal security boundary should include your email server. TLS for encryption in transit, DKIM for attestation of authenticity, and trust that the person you're communicating with has similar levels of trust with their mail host[1]. [0] https://www.spiegel.de/international/world/leak-at-wikileaks-a-dispatch-disaster-in-six-acts-a-783778.html https://www.spiegel.de/international/world/leak-at-wikileaks... - not that they necessarily used PGP, but the problem is the same. [1] I recently sent emails with bank data in them to my solicitors, something that just seemed wrong on so many levels. But my mail server will[2] decline to send mail to their server without validated TLS, and however I give them the information it's going to end up in their O365 environment because that's how the company works. Submitting it over SMTP over TLS is no less secure than over HTTP over TLS. [2] Because I have an advantage over many people who want email security, in that I run my own mail server and can configure it to require TLS for domains that I know support it. I'm not quite at the point of changing the default and only supporting plain text transport for explicitly-allowed domains, I need trust on first use and better observability of failures before I dare risk that -- and I'd use TLSA except that DNSSEC is annoying and so no-one else uses it.