5 ms·
Why are you letting perfect be the enemy of the good? Regular email doesn't preserve sender identity when forwarding, and why should that even matter for encryp
by nmilo 3y ago
Why are you letting perfect be the enemy of the good? Regular email doesn't preserve sender identity when forwarding, and why should that even matter for encrypted mail? Encrypted clients can disable including the original email in a reply, which is totally unnecessary nowadays. And it's okay if headers are unencrypted as long as the client knows it's unsecure. All I'm seeing is a strictly better system than cleartext mail which might have holes around the edges but none that can break the integrity of single-recipient encrypted mail, which is what most people use encrypted email for anyways.
- tptacek 3y agoThis is the rare case where the "perfect is the enemy of the good" logic doesn't apply. Encrypted email is secure messaging. Secure messaging is life-or-death (or at least life's fortune) for many ordinary people who rely on it. The only reason encrypted email is taken seriously by nerds is that none of their messages matter; it's LARP security, a thing done performatively as a social signal, and it doesn't matter if it's safe because getting hit with the LARP sword doesn't kill you. The right way to think about secure messaging and the compromises we should be willing to accept with it is avionics or radiotherapy software. Safety is practically the only thing that matters; if you can't provide it, there's no point in talking about how convenient, open, federated, or standardized it is.
- bombolo 3y agoHow can a computer protocol guarantee that if you tell me your secret, I won't make a video about it and put it on instagram? At the end of the day, it's not a problem with the protocol.
- deleted 3y ago[deleted]
- nmilo 3y agoI don't follow. Simple single-sender-single-receiver would still be 100% secure so use that if it's life or death. Forwarding and multiple recipients can come with a warning that it will be unsecure. Same with the headers. Anyone actually relying on it to be secure would understand the opsec necessary to maintain this, just like any other platform.
- tptacek 3y agoNo, it's not: 1. It leaves metadata unprotected, which is usually just as valuable if not more so to investigators. 2. It leaves the subject unencrypted, which isn't even metadata --- it's message content. 3. It's effectively plaintext-by-default, which is why everybody who has ever used encrypted email has seen someone reply to an encrypted email with an unencrypted response that includes a transcript of the encrypted message. 4. It's based on long-term secrets and a cumbersome secret exchange process with no forward secrecy, something no other secure messenger does, because that configuration makes it just a matter of time before someone loses their key to an investigator and compromises the entire transcript --- put differently, the configuration of cryptography in secure email encourages investigators to simply record all encrypted messages in perpetuity, since they'll eventually get the one key that unlocks all of them. These are disqualifying attributes that cryptography engineers would never accept in any modern design. The only reason they're tolerated in email is that almost everybody who uses encrypted email is doing so performatively, so that it simply doesn't matter when their counterparty replies in plaintext; it's a party foul, not the end of someone's life. Part of this is, I think, that PGP came to popularity in the 1990s, during a time where the Internet was itself kind of a toy, and if you had a threat model, it probably involved someone you'd pissed off on EFNet IRC. If your only adversaries are script kids who are going to own you up for your mail spool, PGP does a great job! The problem is, real-world adversaries, now that the Internet is as prolific and important as the telephone, don't play by IRC script kid rules. So much so that the plaintext content of a PGP'd email often doesn't even matter; they just need the source and destination email addresses and the time the mail was sent, to determine where to roll the van up to in order to beat the plaintext out of the recipient. Or, in the US case, 18 USC 1001 you into federal custody.
- woodruffw 3y agoBecause it’s not good, it’s bad. “Let the perfect not be the enemy of the good” applies to schemes like the Web PKI or phone numbers as identities in E2E chatting schemes, not to things that outright don’t work. (You’ll note that even the simplest single sender case here assumes both key distribution and stable keys for users, neither of which PGP makes easy.)
- reaperman 3y agoKey distribution is the (unsolvable?) weak point for targeted warrants/etc. But still prevents wholesale slurping of data from everyone.
- woodruffw 3y agoI don’t understand what warrants have to do with key distribution. The problem here is much simpler than that: you can’t encrypt to me if you don’t know my key. PGP doesn’t give you a sound way to get my key; every mechanism offered by the larger PGP ecosystem is either broken or disabled due to persistent abuse.
- reaperman 3y agoPGP protects against warrants if done well. But if gmail.com has a system to force-push new keys (which it basically has to do, receiver of key could get option to reject but everyone will just click "yes, accept updated public key for this contact"), then a warrant can force Gmail to utilize their existing system to push a MITM key and intercept encrypted email.
- woodruffw 3y agoWhy are we proposing schemes that are broken from the outset? As others have pointed out: Signal (among others) does not have these problems. These problems occur because email was not meant to be encrypted (or signed); efforts to do so result in these kinds of convoluted “maybe secure, maybe not” models. If we want people to be able to communicate privately, we should be encouraging them to use protocols that are meant that purpose.