3 ms·
That'd be nice, but I'd even settle for the plain pdf attached to the email.
by RulerOf 3mo ago
That'd be nice, but I'd even settle for the plain pdf attached to the email.
- saltcured 3mo agoFor things like financial records, I would not want plain PDF in the email. I think it needs encryption for confidentiality. I am geeky enough to use PGP or S/MIME if they had the option, but I can definitely see how vendors would see this as too fringe with retail customers. I would not like the typical "secure email" which is nothing more than a volatile link back into yet another website.
- wwind123 3mo agoHmm, yeah some people feel that plain emails are not secure for sensitive information. As a result, some banks provide a "secure email" box that's usually PITA to use. It'd be great if there's a unified API for all financial institutes to provide sensitive info (statements, tax forms etc.) and you just need to run a software tool to download them once in a while or when you need it.
- RulerOf 3mo agoI get that, but I don't care. I want the PDF (or CSV) emailed to me as an attachment because that's the workflow that doesn't suck. Everything else sucks in one way or another, and much of it is security theater.
- mcv 3mo agoUnencrypted sensitive data in an email is a really bad idea. I hope they never do that. Although what I would really like, and think is long overdue, is an extension to email that normalises encryption and sender verification. It's ridiculous that email can be spoofed like that. (The same is even more true for phone numbers.)
- pocksuppet 3mo agoIs it really? Who can read it today? Your email provider and theirs? Gmail won't deliver messages without TLS any more, so everyone supports it or they're effectively kicked out of email.
- floam 3mo agoTLS just encrypts the IMAP / SMTP sessions, no guarantee it’s stored encrypted, let alone end to end
- account42 3mo agoYou didn't answer this question: > Who can read it today?
- mcv 3mo agoWell, the email providers. And that could easily include Google without you even realising. It's true that email isn't quite as insecure as it used to be (it was once compared to shouting your message at someone and expecting them to shout it in the right direction until it reached the intended recipient), but there are still many things missing compared to other forms of direct messaging, and there's good reason why many people and organisations don't want it used to send sensitive information.
- pocksuppet 3mo agoHow is that different from your browser and the bank website being able to read the same PDF transmitted through the website?
- thayne 3mo agoIndeed. We really either need email to get decent, user-friendly encryption and verification, or replace email with a new, ubiquitous, decentralized, system that has first class support for encryption. I have a laundry list of other issues I'd like fixed in email, but I'd be happy just to get end to end encryption and sender verification.