Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
twiss
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
twiss
2y ago
Not really, grandparent is asking about what we call "zero access encryption" [1]: encryption at rest of received and sent emails, without the provider having access to the keys (unlike typical "encryption at rest", whic
62.
▲
by
twiss
2y ago
It's possible that some software did it on their behalf; I believe GPGTools submits keys to keys.openpgp.org, for example. (However, I don't know what the UI flow looks like, it's possible that it could be made clearer what.)
63.
▲
by
twiss
2y ago
Unfortunately, we can't easily offer direct IMAP access, because no external email client offers support for everything we need and use in OpenPGP (such as for automatic forwarding, which is currently just a draft [1], but we hope will
64.
▲
by
twiss
2y ago
Here's some background on what Proton Bridge does and why: https://news.ycombinator.com/item?id=36643124 . The recommended way to send signed emails is to let Bridge do it for you; you can enable this with a setting in
65.
▲
by
twiss
2y ago
All of this is public information, so it shouldn't leak anything. So indeed we'll look into whether we can make this information show up in an interoperable way.
66.
▲
by
twiss
2y ago
Well - note that OP uploaded a key to keys.openpgp.org, and then seemingly forgot about it and lost the private key (or at least they couldn't decrypt encrypted emails, and their email client - not Proton's - showed them as being
67.
▲
by
twiss
2y ago
Part of the difficulty is that email is a federated system, unlike WhatsApp. Adding end-to-end encryption to a federated system, if it wasn't there before, is a lot more difficult than adding it to an ecosystem that you control in its
68.
▲
by
twiss
2y ago
Our goal is to make email encryption more usable and less niche, and not only for "situations with a specific need for extra security" - because people shouldn't have to think about which of their emails are and aren't s
69.
▲
by
twiss
2y ago
Obviously, rolling out end-to-end encryption in a federated system is difficult. We need to start somewhere, but obviously the outcome for OP was not ideal. That being said, we haven't actually had that many complaints about rolling th
70.
▲
by
twiss
2y ago
We implement OpenPGP client-side, on the user's devices. Their central complaint of > If it’s running in the browser with code downloaded from our servers, then if we get compromised, we can serve up a version of the PGP code which
71.
▲
by
twiss
2y ago
Indeed, our mission is to make it as convenient as possible to send and receive secure emails. Of course, this outcome (unexpectedly receiving blank emails) was not intended, and we'll see if we can improve the experience. Rolling out
72.
▲
by
twiss
2y ago
Email addresses are typically stored in the User ID in OpenPGP keys, so as long as the OpenPGP key is on keys.openpgp.org, the email address will be there as well. They can be deleted by the owner whenever, of course.
73.
▲
by
twiss
2y ago
Yeah, we'll work to improve the documentation on this. Though.. note that WhatsApp doesn't have any documentation on their key discovery either, because WhatsApp is not a federated system. Achieving automatic end-to-end encryption
74.
▲
by
twiss
2y ago
Just to check, are you looking at a translated (non-English) version of the page? It seems like those are outdated, unfortunately. The English version does specify a log retention period of 30 days. (The version you're served depends d
75.
▲
by
twiss
2y ago
Hi! Proton crypto team lead here. Our motto is "Privacy by default". We're aiming to fulfill that mission as much as is practically possible. In this case, looking up keys on keys.openpgp.org caused an issue for this user bec
76.
▲
by
twiss
3y ago
> the number of people who increasingly choose to die is startling. I expected this sentence to be followed by some statistics, but the article didn't give any. The review committee does publish yearly reports: https://ww
77.
▲
by
twiss
3y ago
I believe Svelte does figure it out at build time. Which does make me question the mention of Svelte in the proposal, and makes me wonder what the Svelte developers think of it - because IIUC they indeed don't need this (at runtime), i
78.
▲
by
twiss
3y ago
It wouldn't even need to be an event on the input, it could be any key or mouse event on the document, including mousemove. That being said, I think it would be better if browsers would implement this; that would make it more efficient
79.
▲
by
twiss
3y ago
I think the last part of the conclusion is relatively representative: > people are starting to take geoengineering seriously It could be made more objective by prepending "Some" :) Though the author does give a bunch of referen
80.
▲
by
twiss
3y ago
Nobody is asking you, specifically, to do anything. But your original point was that checks aren't a problem for you. My point is just that as the article describes, for those without a bank account it does pose problems, and so assumi
81.
▲
by
twiss
3y ago
Oh, right, I agree. I guess my further point is that I'd prefer that after you close the sale and finish the transaction, you're sure you have the money. Cash and some electronic transfers give you that, while checks don't.
82.
▲
by
twiss
3y ago
The word "need" does not appear in the quote :') I think the author is just describing how it typically works rather than how it needs to work.
83.
▲
by
twiss
3y ago
I may be missing your point but it seems to me that cash and paper checks are at opposite ends of the spectrum wrt who has most control over the outcome in case of disputes: with cash, the payer has to go to court to get their money back; w
84.
▲
by
twiss
3y ago
As the article describes, it may be convenient for you, but for many people it's inconvenient and costly to cash a check. Also, saying that those people messed up in their financial management is sort of blaming their poverty on them,
85.
▲
by
twiss
3y ago
This'll be obvious to anyone who's ever used any other payment system, but it'd be better if more of the risk of payment was borne by the payer rather than the payee. For example, re. this line from the article: > In the c
86.
▲
by
twiss
3y ago
If you're willing, you could try to look for a buyer, in case someone else (thinks they) can make the business work. There are marketplaces for small businesses online. Also, hope you can find help with the alcoholism!
87.
▲
by
twiss
3y ago
Since the sequence goes into the past, you'd rather expect there to have been a post 16 years ago, though that would've required a time machine :) From the sequence of difference I'd rather expect the next post in 2025 or 202
88.
▲
by
twiss
3y ago
Fair enough, that's also an important aspect (perhaps more important ^.^). It's just that I immediately started thinking about what other phrases could've been said, and which might be the best one for a "properly aligne
89.
▲
by
twiss
3y ago
I'm not sure. But, my impression is that the boundary of what we consider sentient life has been shifting for a while. For example, people used to think that fish don't feel pain, and so it's fine to catch and eat them. Now t
90.
▲
by
twiss
3y ago
No, I personally don't, and I'm actually a vegetarian. Though, I think it might've been justifiable in the past when/if it was impossible to replace (though I'm neither a historian nor a dietitian, so that's mo
More ›