3 ms·
What is the alternative to PGP for the specific use case of secure email? That doesn't mandate dealing with the X509 certificate bureaucracy?
by benchloftbrunch 9mo ago
What is the alternative to PGP for the specific use case of secure email? That doesn't mandate dealing with the X509 certificate bureaucracy?
- tptacek 9mo agoDon't encrypt email. https://www.latacora.com/blog/2020/02/19/stop-using-encrypted-email/ https://www.latacora.com/blog/2020/02/19/stop-using-encrypte...
- teddyh 9mo agoThe only alternative suggested by the linked article is giving up email completely in favor of centralized solutions like Signal. My short answer is “no”. My long answer is: <https://news.ycombinator.com/item?id=45390332 https://news.ycombinator.com/item?id=45390332>
- tptacek 9mo agoI wrote the linked article. I don't care what secure messenger you use. But if you choose encrypted email over Signal because "centralization", you're LARPing. The first criteria for a secure messenger has to be that it is plausibly secure, and email isn't. You'd use encrypted email (for "decentralization") because you understand the cost of losing the plaintext of your message is nil. If you tell strangers to do that, without certainty that their messages are also valueless, you're committing malpractice.
- Natanael_L 9mo agoWhat's your usecase here? Internal or external messaging?
- pseudohadamard 9mo agoUse case? We're crypto LARPing dammit, we don't need a use case!
- pseudohadamard 9mo agoSomething that doesn't require securing email. Both S/MIME and PGP were solutions for 1980s problems (TFA is slightly off about PGP's start date, the PGP design dates from 1987 and MSDOS, not the 1990s, and S/MIME via PEM is from 1986). They're pretty much irrelevant today because almost all email is encrypted anyway via StartTLS and if you need full end-to-end encryption you use Signal or something similar.