5 ms·
It's kinda cool that they're doing this, if not for anything else than to raise awareness about PGP. That being said, I'm trying my best, and coming up short,
by markild 11y ago
It's kinda cool that they're doing this, if not for anything else than to raise awareness about PGP.
That being said, I'm trying my best, and coming up short, in figuring out what problem this would solve...
- jpp 11y agoI would guess that it will help (eventually) with email deliverability: phishing emails claiming to be from Facebook wouldn't have valid signatures. Yes, DKIM and other stuff already partly does this, but signed emails are much harder to forge!
- markild 11y agoYes, but they could just start signing the mail. There's no reason to encrypt the content if proof of origin is what they want to provide.
- Piskvorrr 11y agoSigned (and unencrypted) mails are vulnerable to known-plaintext attacks; in other words, it is possible (although not always feasible) to alter their content yet retain a valid signature.
- rakoo 11y agoThe cynic in me believes that both this and the official onion sites are baits to lure in those who typically care about privacy and thus don't want to use Facebook. By doing this Facebook allows them to gradually extend their medium of communication to FB, and thus gather more information on them.
- CWood1 11y agoPeople who care about privacy enough to stay away from Facebook in the past are going to know enough about privacy, I hope, that they'll continue to stay away in the future. If this truly is Facebook's intention, I somehow doubt it'll be very successful. I'd like to think it'll encourage more people to start encrypting and signing their emails, although somehow I doubt that as well.
- __z 11y agoFacebook basically got pwned when firesheep came out. I think that ordeal basically made them more security minded.
- jakobegger 11y agoThis solves the problem of your email provider reading your Facebook notification emails.
- cpach 11y agoYep. This is good overall and certainly for password reset e-mails.
- bigiain 11y agoEmail provider, overbearing parents, abusive spouse, scriptkiddie who's just phished your email password... It's only a small "win" for privacy - given that Zuckerberg is on the other unencrypted end of anything "private" this might send, but I can see it as an important win for a few people... Of course, perhaps this is part of a cooperative or NSLed collaboration with the NSA, "Hey Zuckerberg! We need you to tell us which of your users knows how to use PGP, then give us their entire social graph, the social graph of everybody who's ever uploaded a photo with them in it, the locations of those photos, and any Facebook-javascript-bugged webpages they've ever visited. Thanks."
- patzerhacker 11y agoBut it does nothing to hide that it is a facebook notification or that it is from facebook because the envelope information is still unencrypted. So the 'From' address and subject are still in the clear, which doesn't prevent overbearing parents and abusive spouses from knowing you received a notification - only from reading the contents of that notification.
- stevejones 11y agoGiven that if you turn on all notifications you'll have about a bajillion of them it's a pretty good smokescreen.
- tomjen3 11y agoYeah but there is a hell of a difference between seeing that you have received a friend request and seeing that you have received a friend request from an agency that helps victims of domestic abuse. The first is pretty innocent, the other could get you killed.
- tagawa 11y agoOne existing problem is that email encryption is so unusual it stands out and can arouse suspicion to some people. I'd just like to encrypt to protect my privacy but "why encrypt if you've nothing to hide?" The more mundane email traffic like this is encrypted, the less encryption will be equated with suspicious activity.