4 ms·
Yeah, my mom would totally understand that prompt.
by cdmckay 2y ago
Yeah, my mom would totally understand that prompt.
- kazinator 2y ago1. Given that Mom doesn't understand the bulk of the prompt, should we take away the prompt and encrypt the e-mail; i.e. treat the e-mail in a way she doesn't understand? (Maybe! After all sending an e-mail over TCP/IP and SMTP, and adding various headers and whatnot also treats it in ways Mom doesn't understand, and those have to be done. Or maybe not. Encryption literally obliterates the content, making it unreadable without the key.) 2. Your mom would likely understand "If unsure, answer No", and end up sending a normal e-mail. That text should be in bold, probably. Some of the verbiage could be behind some "learn more" link, where there is space and scope for a better explanation. It is probably better if the switch is on the receiver's side, as some kind of Boolean field in the key registration record.
- PurestGuava 2y agoGiven that mom isn't going to understand any of the prompt, and presumably has no pressing care or need for encrypting an email, the sensible default would be to send email unencrypted unless she expressly asks otherwise. It is pretty interesting seeing the various different design philosophies for computer UIs compete in this thread: the typical Linux approach (ask the user a convoluted question, expect them to understand it and expect an informed response - if/when the user selects wrong, tough shit) the Windows approach (ask a convoluted question but give an out for the 99% of people who don't understand it - if the user still selects wrong, tough shit) the Apple approach (don't ask the question at all and choose a sensible default, because 99% won't care - 99% of users get the exact result they wanted to begin with)
- ComodoHacker 2y ago>the sensible default would be to send email unencrypted That's exactly what anti-encryptionists would want.
- kazinator 2y agoThat's the same sort of argument form as "everything encrypted is what the terrorists and child pornographers would want". Just sayin'.
- lxgr 2y agoOr realists that think that encryption-by-default needs to be designed very differently from PGP, and that forcing people into something brittle will not win any sympathy.
- twiss 2y agoHi! Proton crypto team lead here. Our motto is "Privacy by default". We're aiming to fulfill that mission as much as is practically possible. In this case, looking up keys on keys.openpgp.org caused an issue for this user because they didn't know they have a key there. We'll try to make that more clear in the received (encrypted) emails - and we might look into opting out somehow. However, we don't want to make it opt-in if we can avoid it, even if that's what would make sense for Linux, Windows and Apple; it's not what would make sense for Proton. You can't change the world by copying someone else :)
- kelnos 2y ago"Privacy by default" is a good motto when the mechanisms used to ensure privacy actually work most of the time. I'm sure that between ProtonMail users, it does indeed work most (if not all) of the time. But once you leave the ProtonMail ecosystem, I expect you'll find that enabling PGP automatically doesn't work most or all of the time. It likely only works occasionally or even rarely. > You can't change the world by copying someone else :) Please take this as gently as I intend it: ProtonMail is unlikely to change the world on user privacy, at least when it comes to email. Larger providers are too entrenched, and most people won't care enough about privacy to change their email address (and very few people have a custom email domain to move between providers). At any rate, it seems like you're copying Facebook: "move fast and break things". Not great when we're talking about messaging. You're breaking email for some people, and some of those people are your users. OP may not be one of your users, but OP's mom is, and you have broken her ability to send her son email with this misguided policy.
- twiss 2y agoObviously, rolling out end-to-end encryption in a federated system is difficult. We need to start somewhere, but obviously the outcome for OP was not ideal. That being said, we haven't actually had that many complaints about rolling this out. We'll still work to improve it further, obviously, and reduce failure cases like this. And, we'll take the feedback on board about moving more carefully and communicating such changes better. > most people won't care enough about privacy to change their email address Note that with this change, you don't need to change providers to get end-to-end encrypted email: you can let your email client or a browser plugin (like FlowCrypt or Mailvelope) handle OpenPGP for you, and (let it) upload your key to keys.openpgp.org, and we'll send you encrypted email. Obviously, signing up for Proton is still easier, but email is a federated system, and so I think it's important to invest in the feasibility of federated E2EE as well :)
- pard68 2y ago"Mom" implicitly signed up for encrypted email when she decided to use Proton as her mail provider. It's what they're all about.
- mcv 2y agoWhy make unencrypted the default? For https, encrypted has become the default. Users don't need to understand certificates at all, but it works. We should have the same for email. But that does require all clients to make this easy for the user.
- lxgr 2y agoHTTPS is transport-level encryption. If that's your benchmark, email is encrypted by default today – in that most SMTP connections are TLS-encrypted.
- PurestGuava 2y agoWe should have the same for email. But we don't. And while we don't, users have a reasonable expectation that they can send an email and the other person can read it.
- PKop 2y ago>the sensible default would be to send email unencrypted Why even use Proton then? What is the point?
- deleted 2y ago[deleted]
- eviks 2y agoAnyone can understand this > If unsure, choose "No".
- thedanbob 2y agoUnfortunately, when presented with a prompt they don't understand a lot of people stop reading entirely and just click "yes" to make it go away.
- baobabKoodaa 2y agoThose people will click the most brightly colored button, which in this case would be "no"