4 ms·
> Email can be secured and authenticated with GPG and perhaps more people should consider doing this. Doesn't work unless you teach people about security, whic
by Animus7 14y ago
> Email can be secured and authenticated with GPG and perhaps more people should consider doing this.
Doesn't work unless you teach people about security, which is difficult. We have padlocks next to URLs but it's amazing how many people are still willing to send CC info over HTTP.
> SPAM is often in the eye of the beholder.
There's a lot of grey area, but when a particular string has a 99% unread/deleted rate, you can make statistical inferences. An enormous percentage of email falls into this category, and it's why "spam filters" exist and generally do a good job.
- SagelyGuru 14y agoYes, spam filters work OK, so what is the problem? Do we really need some governmental/corporate agency deleting our emails, with all its attendant dangers of abuse? Because that is what you will get. I would rather have spam. GPG has email clients and key management clients (e.g. seahorse) which make it increasingly user friendly.
- kelnos 14y ago>> Email can be secured and authenticated with GPG and perhaps more people should consider doing this. > Doesn't work unless you teach people about security, which is difficult. Simple, transparent security is hard. But this is again a UI problem, not a failing of email. Think about this for a second: let's say Google decided that it was going to transparently PGP-sign all GMail users' emails. Now GMail knows that any message with a from address that ends in @gmail.com but without a valid PGP signature is fraudulent. Now let's say Yahoo wants to adopt this too. So we add some syntax to SPF that advertises, "any mail coming from this domain must be PGP signed." And another field that points to a public key server. So then all other SMTP servers (or even end-user mail clients, if they want), can auto-reject mail based on this criterion. Sure, this leaves out some details, like people sending mail from an @gmail.com address using their own SMTP server via a thick mail client that doesn't support PGP (or requires complicated setup to do it properly, like most do). But it's a (hopefully) interesting idea that might work with some modifications. This has nothing to do with email per se, nothing about its successes or failings. It's just building an easier-to-use distributed authentication system that mail recipients can use.
- SagelyGuru 14y agoGmail etc. could have provided encryption and authentication if they wanted to. Unfortunately they don't want to because their business model(s) rely on reading our emails.
- alexchamberlain 14y agoThis comment is rather silly. Gmail is a hosted service, and tgerefore, their servers would decrypt incoming email on your behalf. Therefore, they could still read your email.
- kelnos 14y agoNot at all relevant to my point. I'm talking about signing messages, not encrypting them. Authenticating messages is completely orthogonal to encryption and whether or not Google can read your mail.
- SagelyGuru 14y agoTrue, they could at least allow signing, good point.
- cflee 14y agoTake a look at DMARC. [1] The webpage is horribly ugly, but essentially, it allows a domain to declare that all their outgoing mail are DKIM-signed and SPF-passed. Paypal and eBay do this. Gmail filters out any DKIM-fail or SPF-fail mails purporting to be from @paypal.com and sends it to spam, with 100% accuracy. Gmail also puts the little 'key' icon next to the sender name, but that's not really important, the point is that any and all fraudulent emails are filtered out with unerring accuracy. Thus, we don't need to use PGP or whatever, which needs to be handled at the client level. DKIM + DMARC is already here and working at the server level. You don't need to wait for your favourite email client to adopt DMARC. Yes, if people send emails without going through that SMTP server etc etc.. that's a problem, but also solvable/solved. [1] http://dmarc.org/ http://dmarc.org/
- 14y ago