4 ms·
To say nothing of the fact that most people are not running their own email servers so that messaging is going to reside in places they don't own and the fact t
by drpossum 2y ago
To say nothing of the fact that most people are not running their own email servers so that messaging is going to reside in places they don't own and the fact that relays get to read about everything exacerbating that problem, so you cannot really expect forward secrecy:
Does this solve all the other problems with encrypted email, which is not widely used for a reason?
Here's a discussion
https://www.latacora.com/blog/2020/02/19/stop-using-encrypted/ https://www.latacora.com/blog/2020/02/19/stop-using-encrypte...
- lxgr 2y ago> most people are not running their own email servers I honestly don't care about what the people I communicate with do, as long as I have the capability to at least own my persistent identifier (i.e. my TLD). Just having that capability exerts just the right type of pressure on large service providers to maintain a baseline quality of service, regardless of whether the majority actually makes use of it or not, just like phone number portability has done in that domain.
- em-bee 2y agomessaging is going to reside in places they don't own but that is the case with every messenger that stores messages on your behalf. telegram, whatsapp, signal... with those ALL people are not running their own servers. whatsapp and signal store encrypted copies of the messages, and so does deltachat. beyond that each client also stores a copy of each message locally. as does deltachat. in difference to all others at least with deltachat i have a choice to use a different server that i trust. with whatsapp and signal i don't have that choice.
- em-bee 2y agoDoes this solve all the other problems with encrypted email it doesn't solve all of them but a few at least. i don't believe using pgp itself is a problem. if it was deltachat could replace it with another better encryption. metadata is a problem. that could be solved by removing messages from the email server and storing them elsewhere. (or storing them back on the server with the metadata removed). that doesn't prevent intermediate mail forwarders from keeping a copy though. i think that is the real problem. deltachat doesn't control the communication channel and can't prevent leaking. i don't know how matrix or jabber compare here. if they use intermediate servers to forward messages the problem would remain. message content leaking is not a problem because messages won't ever be decrypted on the server. long term secret leaking is a problem tied to the current implementation of pgp. deltachat could change that (and maybe it does?)