4 ms·
Its expected that you'll run JMAP over HTTPS which takes care of the wire encryption. For end-to-end encryption, there's a heap of problems that still aren't so
by robn_fastmail 12y ago
Its expected that you'll run JMAP over HTTPS which takes care of the wire encryption. For end-to-end encryption, there's a heap of problems that still aren't solved (key distribution, need for content analysis). There's no reason JMAP couldn't be extended in the future to support these via additional properties, attached encrypted payloads, etc but mandating it from the outset would quickly see the whole protocol dead before it began.
- davexunit 12y ago>key distribution GPG key servers?
- robn_fastmail 12y agoAnd how do you trust those? And if I'm a brand new user, how do I get my key in there? All the moving parts probably exist, but so far no one has pulled it together into something that a random person off the street can use. Its not the problem JMAP is trying to solve.
- uaygsfdbzf 12y agoYou don't need to trust the keyservers since you verify the fingerprints of downloaded keys against the fingerprints given to you in person. The keyserver protocol includes commands to include keys in the keyserver network. How you send keys depends on the UI of the tool you use, geeks will do this: gpg --keyserver <keyserver> --send-keys <fingerprint>
- robn_fastmail 12y agoRight. I'm a little rusty on the details. My point stands - key distribution is not a solved problem for the average user.
- uaygsfdbzf 12y agoIt is solved for some specific platforms, GNOME for example: https://mail.gnome.org/archives/gnome-announce-list/2014-November/msg00004.html https://mail.gnome.org/archives/gnome-announce-list/2014-Nov... The average user doesn't use GNOME or Linux though :(