5 ms·
I find it hard to judge how much, if at all, this will help, but I'm all for email being more secure, to the point that organizations (banks, governments, insur
by sverhagen 4mo ago
I find it hard to judge how much, if at all, this will help, but I'm all for email being more secure, to the point that organizations (banks, governments, insurance companies) stop creating walled-email alternatives: please log in to our secure message center, where you can only see our messages poorly formatted, and for a short time, until we permanently delete them. I like that my Inbox is a somewhat-searchable, historical record of my life, and these alternatives break that.
- iLoveOncall 4mo ago> I'm all for email being more secure, to the point that organizations (banks, governments, insurance companies) stop creating walled-email alternatives This will literally never happen. Email doesn't support the features that those messaging platforms need to have, such as recalling messages. The security layers are also only on the sender part, not on the receiver part, which banks care a lot more about.
- superice 4mo agoI know this is only tangentially related, but recalling messages is horrible. I hate that so many services will allow people to send me a message, give me a notification with a preview, but then the message gets edited or deleted. If you drop a letter in a physical mailbox, or slide a paper underneath the door, you cannot get it back either. This whole philosophy of 'we allow destruction of messages in a shared chat' needs to stop. The moment things are being sent, both sides are co-owner of that message. Not being able to recall messages is a good thing. I'll settle for a brief edit (not retraction!) window after sending though, say 5 minutes tops. Edit (I realize the irony): banks of course won't give a hoot about the receiver, the power dynamic is inherently not equal.
- nosioptar 4mo agoWith banks, I've found that offering to bring the matter up with the FDIC and/or fed regulators moves the balance of power to a less unfair level. "We have to use secure messages" turned into a willingness to use email in less than 6 hours last time I had an issue.
- Hizonner 4mo ago> Email doesn't support the features that those messaging platforms need to have, such as recalling messages. "Need".
- LoganDark 4mo agoI love hearing that I received a "secure message", with no further detail. Straight to trash -- I don't read "secure messages". My inbox is probably more secure.
- Symbiote 4mo agoI get secure messages from public authorities and companies in Denmark, which go to my secure 'mailbox' for this purpose. Of course, contracted out to some private company, and they'll probably change the contract again in 5 years. The messages are usually PDFs, which isn't great for accessibility, e.g. using a translation tool.
- jasode 4mo agoThe gp isn't talking about spam using "secure message" as bait to open unwanted email. Instead, legitimate companies like banks, healthcare, etc tell users to click on a url link to their "Secure Message Center" to read or submit some critical information. It's often the only way to get the info the users need. E.g. if I open a payment dispute with the bank, the workflow they use is the Secure Message area. I can't just use my normal email client and upload some pdf attachments. Instead, I have to log into my bank website, navigate to their Secure Message area, and then upload the docs there to submit the claim. They also don't send followup status or final resolution in an email. Instead, you log back into the Secure Message area to read the case resolution. Similar for insurance claims. Similar situation for asking a medical imaging center for some mammograms. They will not send those as PDF or JPG attachments directly to your email address. Instead, you log into a secure message area on a healthcare website and download it from there.
- LoganDark 4mo ago> The gp isn't talking about spam using "secure message" as bait to open unwanted email. No, this includes all messages from my doctor/healthcare. It's not mass spam. Theoretically I could want to know what's in the message, but not enough to visit a website I've been logged out of again, perform multi-factor authentication, navigate to the message center and find the message and then back it up manually.
- thefounder 4mo agoTo have secure email I think html /css should be dropped from email support and the inbox should work on an invite only basis. Basically you should pre-authorize the senders just like you add someone as friend on a social network.
- Angostura 4mo agoSo... not e-mail then
- fc417fc802 4mo agoThe necessary bits to facilitate that could be added on top of the existing protocol in a manner that doesn't break existing clients. Essentially it amounts to an out of band registration of the expected sender with your own server, likely by means of a short proxy code or phrase. Couple with key exchange to facilitate an E2EE extension at the same time, while also dodging the logistical issue that would otherwise arise when a sender has multiple addresses or the sending address changes.
- coldtea 4mo agoYeah, because email as a family of protocols never developed different capabilities /s
- thefounder 4mo agoYou can call it Secure-Email or RFC-99999
- jen729w 4mo ago> Basically you should pre-authorize the senders This is kinda what 'masked email' services like Fastmail's – of which I am a delighted customer – do. Until you've known the comfort of creating an address; giving it to a service; deciding that you want to end your relationship with them; just deleting that address, without changing your mailbox or infrastructure or archives or anything else … it's kinda life changing. I recommend everyone try it. Also, the chances of a phisher trying to get my BigBank details by sending mail to lonely.chicken6382@spuriously-named-and-unused-other-than-for-email-domain.com are … well, it seems unlikely. I've never felt more secure. For real.
- the_bear 4mo agoThose "message centers" aren't just about security, they're also about compliance. For example, insurance companies need to be HIPAA-compliant which requires that they can only send health-related info to other HIPAA-compliant systems, which means signing a BAA (a contract) with those other systems. There's no way to do that with email (your insurance company can't sign a contract with every potential email host in the world, and they don't even know where the email will ultimately end up after they send it) so practically speaking, they're not legally allowed to send any health info via email. It's extremely difficult to accurately identify which emails have health info and which ones don't (even something like a person's name or IP address could count depending on the context) so they just default to sending everything through their message center. No amount of email security could change that.
- prepend 4mo agoSomehow they mail letters with info. Encrypted email wouldn’t require a BAA.
- b112 4mo agoDollar bills are essentially untracked, good everywhere, secure, work no matter what. Same goes for normal mail, and it's a federal offense to tamper with it. Nothing electronic will ever be secure, unless it is never, ever networked. Networking changes "touch physical thing" into "everyone on the planet plus their bots" can touch it. Even if you pass harsh laws, you need to geogate network connections to only within that legal jurisdiction. Otherwise, it's pointless. The real, true problem is anonymousness. I used to advocate for, now I'm done. The problems anonymity solve, are a gnat compared to the ones it creates. I'm all for ipv8, but with a unique ID in the packet identifying the person directly. I can't drive a car, own a gun, drive a boat, buy explosives, ply many trades, and 100 other things without a license. Maybe unrestricted internet access is in that category, and bad behaviour means it is revoked. The Internet was a toy for a long time. Now it's the backbone of all commerce, industry, personal communication, with life threatening implications at times. Play time is over.
- 4mo ago
- nosioptar 4mo agoThose secure messaging platforms make it damned near impossible to make a backup. I've seen medical clinics delete messages that would have bad for them in court. As such, I tell anyone who sends me one to fuck off and send a real email.
- marysol5 4mo agoMy bank does a PUSH notification that is "Please log into the app to read an important message", which is usually just my monthly statement or whatever. And then also sends an e-mail, which sometimes I confuse and think is ANOTHER message, and log in again.... It has a "Download this message as a PDF" button, which just takes you to a web-browser wrapper....
- WhyNotHugo 4mo agoI called my bank for some info recently. They can't email it to me, but they _can_ send it through postal mail. Should be arriving any time next week. I'm sure there's a sum of compliance reasons why this is not allowed, but it doesn't make any sense at all.