2 ms·
> Alice's email needs to be sent as plaintext Thanks for your explanation! Though in your hypothetical Carla uses Gmail, and Google supports SMTP TLS. So the e
by declan 11y ago
> Alice's email needs to be sent as plaintext
Thanks for your explanation! Though in your hypothetical Carla uses Gmail, and Google supports SMTP TLS. So the email would be encrypted in transit to Google's servers.
The problem, which the previous poster may be alluding to, is when a lavaboom user emails a non-PGP user with an account at an email provider that fails to support SMTP TLS. When I wrote about this for CNET two years ago, Hotmail, Yahoo, and AOL did not support it:
http://www.cnet.com/news/how-web-mail-providers-leave-door-open-for-nsa-surveillance/ http://www.cnet.com/news/how-web-mail-providers-leave-door-o...
Now it looks like all three of those companies do, so the question is: Which providers still fail to, two years post-Snowden disclosures?
- simi_ 11y agoTLS transport is nice to have, but some people can work around it. [0] That's why I only considered PGP, but you're right, SMTP TLS is important. We've also been toying with SMTorP. [1] 0: http://en.wikipedia.org/wiki/PRISM_%28surveillance_program%29 http://en.wikipedia.org/wiki/PRISM_%28surveillance_program%2... 1: https://github.com/mailpile/Mailpile/wiki/SMTorP https://github.com/mailpile/Mailpile/wiki/SMTorP