22 ms·
Why can't my mom email me?
- kevincox 2y agokeys.openpgp.org seems to claim that keys aren't searchable by email until the email is verified. Did you ever verify the email with them? If not something is going wrong. Maybe there is a problem in the service or maybe Proton Mail is working off of a dump and ignoring the "is verified" bit. https://keys.openpgp.org/about/usage#gnupg-upload https://keys.openpgp.org/about/usage#gnupg-upload
- lxgr 2y agoEven publishing a key as “searchable by email” should absolutely not be taken as an invitation by any client to encrypt by default, given the somewhat lacking ergonomics of GnuPG. I have a key published, but if somebody emails me encrypting to it, it would take me days to figure out where my smart card storing the private key is, how to use it on my current OS etc.
- brewdad 2y agoI'd probably be more sunk. When I was first learning and playing around with PGP, I published a key. Later, I changed the key for some reason or other but no longer had a way to revoke the old one. I'm pretty any of them out there are expired by now but for a few years it absolutely was possible to send me unreadable mail.
- lxgr 2y agoI think they are only using the “email address verified keys” that these “new-style key servers” use, so you’d be able to at least revoke that binding as long as you can receive unencrypted emails to that address.
- Valodim 2y agokeys.openpgp.org operator here. It's definitely not a bug, we do not publish email addresses without verification. From our perspective, op verified their email and made the key discoverable.
- PaulDavisThe1st 2y agoSo that implies that either the OP has forgotten that they did this (because they are quite clear that they did not), or that there is a way to do this without being the owner of the email address. Both worrying, but one is a lot more worrying than the other.
- Valodim 2y agoI don't think they are clear they did not? In fact, they are clear that they did publish their key, because they mention depublishing it to test their hypothesis. The part they say they didn't opt into was that Proton (or any specific email client) would use the key by default.
- PaulDavisThe1st 2y agoIndeed, you are correct, and I was wrong.
- smoyer 2y agoI actually like this behavior ... If you have a key, use it!
- kiwijamo 2y agoThe OP doesn't recall generating one. Genuine question: do you also like it when someone else generates a key for you without telling you? Personally I would rather know about it.
- int_19h 2y agoThe OP did generate one and placed it in a public registry. What they didn't do was indicate that this key should be used to encrypt email sent to them to them.
- abofh 2y agoThey published it with an precise link to their email address - what were people supposed to conclude from them publishing it - "never use this pgp key unless you've spoken to me in person?" - that... kinda defeats the whole point of publishing a key _and_ the handle by which it's looked up in the same database. If you didn't want that, you'd associate it with something else that wouldn't expect encrypted email - like a name or a GUID and point people there when they need it. They wrote in the book "me@foo.com: use key" - and then people did. If he wanted different behaviour, he could have published "someoneelse@foo.com" and then they wouldn't use it to email _him_.
- PeterisP 2y agoIn the current world an "email address" is not solely (or sometimes even primarily) for delivering email, but rather an identity or username for various systems, such as for signing git commits. So a key linked to an identity (email address) does not imply in any way that this key is also used or usable for encrypted communication.
- kelnos 2y ago
- roenxi 2y agoThe Fastmail article linked my Mr Duggan [0] is also worth a read, they provide a sober and reasonable overview of why they don't offer PGP. Of course, Australia has a quietly privacy-phobic regulatory regime so we can guarantee [1] that Five Eyes countries and possibly others are reading emails sent through Fastmail. Cost of doing business really, I use Fastmail. Fact is that there isn't a way to use a convenient 3rd party email provider if you want secure emails. Only local clients can provide that feature - which means both sides of the message have to be using trusted local clients, and at some point one side of the conversation will forget their secret and lose access to their email history. It is a tough problem. [0] https://www.fastmail.com/blog/why-we-dont-offer-pgp/ https://www.fastmail.com/blog/why-we-dont-offer-pgp/ [1] https://www.bbc.com/news/world-australia-46463029 https://www.bbc.com/news/world-australia-46463029
- mulmen 2y agoI also use Fastmail and I am a happy customer. My eyes are open. I make no assumption that my mail is private. I think the email analogy is actually very accurate. It’s as secure as postal mail. Maybe slightly more secure than a post card. I’m happy to be supporting a slightly smaller provider. I don’t have to admin anything and I still feel like I’m contributing to an open ecosystem. Plus I own my domain so I can always change providers. I have made peace with the compromise.
- greyface- 2y agoI'm in essentially the same place. I do wish their marketing pages didn't make such strong claims of privacy - it's an impossible promise. https://www.fastmail.com/fast-private-email/ https://www.fastmail.com/fast-private-email/
- mulmen 2y ago“We’re more private than Gmail” doesn’t have the same ring even if it’s true.
- 2y ago
- rvnx 2y agoIn summary (quoting OP): "the act of uploading a OpenPGP-compatible key seems to trigger Protonmail service to send end-to-end encrypted message"
- totetsu 2y agoIf there is one thing I absolutely want to keep out of the big techs and governments surveillance data lakes its conversations with my mother. What will become of the world if we can’t even talk with our mothers without it being taken as a chance by some extrafamilial power to exert some behavioral modification.
- skybrian 2y agoI was very fortunate to have set up Mom with video chat just before the pandemic. Maybe try that?
- inetknght 2y agoVideo chat... in an age where algorithms exist to transpose faces and voices in real time. I admire the idea but I doubt it solves the problem: trusting that the communication is both private and authentic.
- skybrian 2y agoIt's commonly claimed to be end-to-end encrypted. Maybe you can find software you trust more than mainstream providers, though?
- lxgr 2y agoWhat does one have to do with the other? Algorithms to generate and imitate email text exist as well. If you want to be able to trust the content, you need to encrypt and authenticate that, no matter the channel. And many VoIP/video conferencing systems these days are end-to-end encrypted! It’s arguably easier than email, since communication is synchronous and there isn’t any expectation of being able to view past conversations, both of which are not true for email.
- jrflowers 2y agoThis is a good point. While faces and voices can be faked, text cannot
- softgrow 2y agoI have a web form on my website which is used mainly by spammers and my Dad. So when he can't seem to email me, there is always a backup that works. Parents demand highly redundant systems of their techno offspring.
- felixfbecker 2y agoI personally think S/MIME is better than PGP. The "key exchange problem" is solved more pragmatically and user-friendly (send an unencrypted but signed email once, your/their client will automatically remember keys for encryption afterwards). And most pre-installed email clients support S/MIME natively (e.g. Apple Mail, Outlook, even the web email apps). The only annoyance is that it's too difficult to acquire a certificate as an individual, but e.g. Actalis [1] will issue one for free. [1] https://www.actalis.com/s-mime-certificates.aspx https://www.actalis.com/s-mime-certificates.aspx
- Avamander 2y agoApple Mail's implementation was broken for years, it silently failed to encrypt messages (CVE-2023-40440). It also still can't properly sign letters with attachments. None of these implementations also handle RSA-PSS signatures and the standards basically forbid double-signing that would allow gradual migration to better algorithms. (This issue also exists with PGP/GPG) Actalis is nice for testing but they unfortunately generate your private key for you instead of accepting your CSR. (Protonmail has the same issue with PGP.) But it is better in a bunch of other aspects, including tooling, yes.
- jms703 2y agoUse signal.
- NooneAtAll3 2y agoas soon as it stops requiring phone number as identifier
- spaceguillotine 2y agothey did that already. you can sign up with just an account name now, i ditched my phone number from my account after it rolled out around a month ago.
- gnyman 2y agoI'm quite sure you still need a phone number to sign up? Afrer that you can hide it but not get rid of it. Still the fact that you can use it without disclosing your phone number to anyone except signal is indeed useful and a improvement from before. https://support.signal.org/hc/en-us/articles/6712070553754-Phone-Number-Privacy-and-Usernames https://support.signal.org/hc/en-us/articles/6712070553754-P...
- em500 2y agoSerious question: what should they, or some idealized privacy-first messaging service, use for as a account-id + authentication? I will need some reasonably cost-effective defense against mass abuse.
- lxgr 2y agoThey could offer usernames tied to a one-time minimum donation, for example, let existing users vouch for new ones etc. Yes, all more difficult than using phone numbers and outsourcing the proof-of-humanity problem to telcos all over the world, but in my opinion it would be worth it.
- upofadown 2y agoLast I checked, Signal doesn't support email...
- Valodim 2y agokeys.openpgp.org operator here. He uploaded his key and verified his address, it's discoverable, and people use it to send encrypted email. As far as we're concerned, that's not a bug, that's a feature. Now, it is debatable whether the ecosystem is ready to be doing this at (some) scale by default. I agree it's not, dealing with e2e encrypted email is a less convenient experience than plaintext for most users. But not all - case on point, with Proton it's fine. It's a valid question how opt in our out should work, with lots of implications and stakeholders involved. For better or worse, the status quo is that there is no signaling mechanism in openpgp (or keys.openpgp.org) at the moment to specify how a key should be used, so publishing a key is just a yes or no situation. If op wants to offer encrypted email as a possible means of communication, but explicitly on an opt in basis, I would recommend a separate email address (or a tag, e.g. +encrypt) for that purpose.
- akerl_ 2y ago> For better or worse, the status quo is that there is no signaling mechanism in openpgp (or keys.openpgp.org) at the moment to specify how a key should be used, so publishing a key is just a yes or no situation. Given that, why would it make sense for a service to assume that publishing a key signals that they should use it by default for a given communication channel?
- nulbyte 2y ago> Given that, why would it make sense for a service to assume that publishing a key signals that they should use it by default for a given communication channel? Why else would one publish a key and make it discoverable, if not that it be used?
- UberFly 2y agoI think the point is that it isn't an opt-in process as it should be. The default shouldn't be "if it exists use it".
- 2y ago
- throwaway984393 2y ago[dead]
- eduction 2y agoIf I didn’t want people to encrypt mail to my pgp key I would simply not upload it to a public pgp key directory. Honestly, what is the complaint here? If you don’t want people to use certain contact info don’t put it on the open internet. To get your key in that key server not only do you have to submit it you have to verify it via email. It’s literally… to spread it widely… to anyone who wants it… so they can send you encrypted mail. That’s the entire purpose of the thing. Like if i put my phone number on a billboard I have no right to complain when I get calls. Take responsibility for your actions. “ However long we postpone it, we eventually lie down alone in that notoriously un- comfortable bed, the one we make ourselves. Whether or not we sleep in it depends, of course, on whether or not we respect ourselves.” Joan Didion https://www.vogue.com/article/joan-didion-self-respect-essay-1961 https://www.vogue.com/article/joan-didion-self-respect-essay...
- worddepress 2y agoMore charitable is that the user thought it would do X and it ended up doing Y. They may have even been happy with X even, if they knew that was going to happen, because the whole thing would have been less confusing. > I'm at a little bit of a loss here. I totally understand sending me encrypted emails if I've gone through the steps to set the CNAME that indicates that I want to do that, but it doesn't seem like that's how the service works. As far as I can tell, the act of uploading a OpenPGP-compatible key seems to trigger their service to send it as an end-to-end encrypted message. A similar example is how Windows changed their OS to require a PIN, which can be a password if you figure how to. It then asks you for this when doing completely unrelated to your OS online stuff sometimes, like some of the weird flows to do with using Teams or whatever, and I am not expecting it was asking me for my PC pin because it before that just asked me for my Online username. It is a UX issue.
- jrockway 2y agoI don't know... I thought encrypted emails were cool in like 2002, so I probably have a key on a keyserver. I probably lost the ability to revoke that key, and simply stopped caring after not receiving a single encrypted email in 25 years. So I would be very surprised if someone sent me an encrypted email today. (I actually do know where my key material is. It's on a smartcard that nothing that exists today can read. Back in the day laptops had smartcard ports! Crazy.)
- gnyman 2y agoOn a related topic, I wish someone would implement "user-encrypted-at-rest" to protect me from the provider getting breached. I don't care so much for the transit, but I'm a bit worried about the fact that I have many years of emails stored in "plaintext" (citation makes because they probably use FDE and maybe other encryptions but they can still read everything) on the providers server. I'm not worried about a malicious provider, but worries they might at some point make a mistake which allows them to be hacked. If anyone knows any solutions for this that works in iOS/Mac I'd love to hear. The only thing I've found on this is some research a few years ago with ideas how to do this; but I haven't seen any implementations of it. I've linked to it here: https://www.cs.columbia.edu/~koh/papers/koh-eurosys19-e3_easy_email_encryption-final.pdf https://www.cs.columbia.edu/~koh/papers/koh-eurosys19-e3_eas...
- bartbutler 2y agoProton does this.
- upofadown 2y agoThat's actually the Protonmail feature that is causing the problem.
- twiss 2y agoNot really, grandparent is asking about what we call "zero access encryption" [1]: encryption at rest of received and sent emails, without the provider having access to the keys (unlike typical "encryption at rest", which doesn't give you much). Instead, OP is talking about outgoing end-to-end encryption using public keys from keys.openpgp.org. [1]: https://proton.me/blog/zero-access-encryption https://proton.me/blog/zero-access-encryption
- kjhcvkek77 2y agoDownload all the emails from the server. Create a backup dump file from your email client. Encrypt that with any program you like. Upload to eg Google drive. Verify the backup and then delete all the server-side copies of your emails.
- beefnugs 2y agoHate to badmouth them: but they are definitely broken recently (one full month at least). I get long term contacts fine from things like AWS, but multiple new people i have not contacted before just do not get anything, complete silent failure (with @proton.me) with no indication that my contact received nothing. I created an alias using @protonmail.com and that worked to new people
- protonmail 2y agoThat doesn't sound right. Have you opened a support ticket with us so that we can look into what's happening? You can do it here: https://proton.me/support/troubleshooting?product=mail https://proton.me/support/troubleshooting?product=mail
- DeepSeaTortoise 2y agoSilent failures are about as bad as it gets, but it's probably related to overlooked edge-cases during the simplelogin integration. If you file a bug report, there should be a probably highly stressed, overworked and slightly paniced team ready to get a fix out by yesterday.
- ulrischa 2y agoOlder generations tend to use Messengers like whatsapp. E-Mail has some Henry barriers often to high for them. Would be great to have an email app as simple as whatsapp
- aborsy 2y agoThe current email protocols can’t be easily encrypted. There are multiple providers and clients that are not compatible, you often have to put people in copy that don’t have public keys, or get replies in plaintext, you may want the content accessible to different people for documentation or legal purposes, some functionality will be broken or become hard to use, it’s asynchronous, and there is simply little demand for privacy from the providers. The use cases are currently niche, in places like dark web.
- soraminazuki 2y agoIn short, “if you have nothing to hide, you have nothing to fear.” I disagree. Privacy is a fundamental human right essential to a functioning democracy.
- plopilop 2y agoRelated research: * Why Johnny can't encrypt (1995): https://people.eecs.berkeley.edu/~tygar/papers/Why_Johnny_Cant_Encrypt/OReilly.pdf https://people.eecs.berkeley.edu/~tygar/papers/Why_Johnny_Ca... * Why Johnny still can't encrypt (2006): https://cups.cs.cmu.edu/soups/2006/posters/sheng-poster_abstract.pdf https://cups.cs.cmu.edu/soups/2006/posters/sheng-poster_abst... * Why Johnny still, still can't encrypt (2016): https://arxiv.org/pdf/1510.08555.pdf https://arxiv.org/pdf/1510.08555.pdf At this point I really wonder if e-mail is the best solution for encrypted asynchronous communication. E2E systems like Signal or Whatsapp offer a very functional, intuitive way to protect your texts.
- outime 2y agoThe only issue with WhatsApp (I have no idea about Signal) is that, while it offers seamless encryption, it doesn't allow you to use an alternative client. Therefore, all trust has to be placed in the client and its distribution to ensure it doesn't mess up (intentionally or not). For the average Joe however I totally agree with you and it's a good baseline.
- izacus 2y agoSecurity folks, especially on HN, are very actively hostile to alternative implementations and clients because in their mind it breaks security. Just see any Apple or Signal topic. The walled garden lockin in by design for you to be safe.
- upofadown 2y agoThat's only if Signal and Whatsapp actually took any good lessons from WJCE. Both handle the difficult identity issue with the comparison of huge numbers just like with PGP. Usability studies have shown that this has worked out about as well as one might expect[1]. Worse, both cheerfully allow the use of unauthenticated correspondents without any particular warning to the user. WHCE identified the root issue as a failure to create and impart the required concepts to use the system. Signal/Whatsapp completely fail at this, instead the user is provide with a sense of security that is not warranted. The PGP using community as least recognised that there was a problem. When has anyone ever organized a Signal/Whatsapp key comparison party? [1] https://www.ndss-symposium.org/wp-content/uploads/2018/03/09-when-signal-hits-the-fan-on-the-usability-and-security-of-state-of-the-art-secure-mobile-messaging.pdf https://www.ndss-symposium.org/wp-content/uploads/2018/03/09...
- paulnpace 2y ago> It outlines an enrollment process by which I would signal to a WKD service that I have a key that I want to enroll into the process. The only problem is I never did that, or at least certainly can't remember doing that. I'm certainly not hosting a page with any key verification stuff. The post includes the above statement that this person never took the steps required for following the standard Proton states they are following. This communicates to me that Proton is not following any standard. This is something publicly visible and on a grander level fairly simple to discover compared to other issues related to E2E encryption. I don't trust Proton or really any organization to manage E2E for email, and among the biggest issues is that email just seems like the wrong tool for the job. Another issue I have with encrypted email is what to do about spam. If the server can't inspect the contents of the message, the probability of a "success" on the part of the spammer is significantly higher. Public keys can be published for addresses that have very high limitations (e.g., 1KB size limit, strict mail policy standards enforcement, whitelists, etc.). How Proton plans to deal with this an average person, I have no idea, but I imagine a lot of people will be scammed in their discovery process.
- rakoo 2y agoSo if I understand correctly: - Proton uses WKD for keys outside its own domain - OP didn't activate WKD for their own key (there is no CNAME) - But Proton still assumed that it was activated, that their key was on keys.openpgp.org and that it was valid It is hard for me to see how this is not a fault with Proton and Proton only. If the user didn't opt-in, don't opt-in for them !
- Avamander 2y agoDon't upload your key to a public keyserver with an email address you have to verify you don't want to receive encrypted things with. That is the opt-in! Usually the problem is the exact opposite, it's really annoying to find someone's public key even if they have given you the key ID or mentioned they can receive such mail.
- rakoo 2y agoThat a key exist on a random keyserver means nothing. There is a spec that explicitely says "if you want to use my key here it is" and Proton doesn't respect it. what does it mean that you found the key on some third-party domain ? There are 0 safeguards, I don't know what they're going to do with it, there is no obligation from any side. A key in keys.openpgp.org means nothing.
- Avamander 2y agoIt means someone uploaded it there and verified the address in the identity (or subidentity). A keyserver is exactly for "here's my key, use it". Don't publish your keys if you don't want them used. It's not that difficult.
- ziddoap 2y ago>It is hard for me to see how this is not a fault with Proton and Proton only. If the user didn't opt-in, don't opt-in for them ! The counter argument is that they opted-in by publishing an encryption key to a public key server.
- uconnectlol 2y agothese kinds of stories are such a joke, why can i not just give someone my public key and that should be enough to communicate with him forever? how is that not user friendly? because he can lose the key? you just give it again. you just use some decentralized protocol with a DHT or something and the only step the user ever has to do is get the public key of the person he wants to add. net result is far better off than nonsense like email, dns, and x509. and i had this exact same rant 15-20 years ago too, it's amazing how everyone is still chasing the same carrot.
- deleted 2y ago[deleted]