this post was submitted on 17 Feb 2024
184 points (100.0% liked)

Technology

69156 readers
2724 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 3 points 1 year ago (6 children)

Can we get away from email?

It's not a secure form of communication anyway. I want my messages to be e2e encrypted so I know I am the only one that can read them

[–] [email protected] 32 points 1 year ago (1 children)

Congrats, you just invented ProtonMail

[–] [email protected] 7 points 1 year ago (1 children)

Its not encrypted when 99% of your contacts aren't on Proton.

[–] [email protected] 13 points 1 year ago (1 children)

You can encrypt it for non-Proton users very easily.

[–] [email protected] 2 points 1 year ago (1 children)

oh? i have friends that use protonmail and i've asked them to do it. no one has succeeded yet

[–] [email protected] 6 points 1 year ago (1 children)

Yep, it just has you set a password, confirm it, and even set a hint if you want. Works on web or mobile.

[–] [email protected] 2 points 1 year ago (1 children)

you're talking about sending a link to a password protected message?

[–] [email protected] 5 points 1 year ago (1 children)

Yes, there's no other implementation I know of for provider-to-provider encrypted email. O365 is very similar. Recipients can then reply back too and the Proton user receives it directly.

[–] [email protected] 2 points 1 year ago (1 children)
[–] [email protected] 1 points 1 year ago* (last edited 1 year ago) (1 children)

Ah yes, forgot about PGP. Haven't used it in a long time myself, but Proton automatically creates a PGP signature for you. You can just attach your public key that's already on your account and it'll encrypt your mail. It natively supports PGP/MIME.

[–] [email protected] 1 points 1 year ago (1 children)

you say it like it's simple, but i don't have any friends who have accomplished it

[–] [email protected] 1 points 1 year ago* (last edited 1 year ago)

It was pretty easy when I tested it just a few min ago, yes. Maybe they step the missed was adding your public key to the contact entry for you. As soon as you do that "encrypt" is enabled by default for you.

[–] [email protected] 15 points 1 year ago

Then use Proton Mail

[–] [email protected] 11 points 1 year ago* (last edited 1 year ago) (3 children)

What a stupid thing to say.

Whatever your favorite (and probably shitty) proprietary or open source messaging service - not everybody uses it. But hey, everyone has email, so let's kill that.

BTW since you said encryption is important to you: your walled-garden messaging service has a much easier time profiling you and your friends than they would in a heterogenous environment like email. They don't need the content anyway, just metadata.

[–] [email protected] 2 points 1 year ago* (last edited 1 year ago)

They don't need the content anyway, just metadata.

ProtonMail uses PGP encryption to encrypt emails, which means your meta data, including subject line is vulnerable to data collection. Also there is no forward secrecy with current PGP standard. See quotes from below:

We have built Proton Mail with PGP fully integrated, ... All messages between Proton Mail users are automatically end-to-end encrypted.

https://proton.me/support/how-to-use-pgp

Subject lines and recipient/sender email addresses are encrypted but not end-to-end encrypted.

https://proton.me/support/proton-mail-encryption-explained

PGP (especially for email) exposes much more info to outside party than any good communication protocol, like the signal protocol or OMEMO used by XMPP.

[–] [email protected] 1 points 1 year ago (1 children)

Oh no, profiling. Google can read your emails directly

[–] [email protected] 1 points 1 year ago (1 children)

No, they can't since I don't have a Google mail address. Even if I had, they'd have a harder time building a social graph when I communicate with others outside of Gmail.

[–] [email protected] 1 points 1 year ago

Okay, but unless all of your communication is e2e encrypted, your provider can read all of your messages. They can even show you ads based on the contents. Oh, you bought vitamins on Amazon? How about some minerals?

If I send messages with matrix, the matrix server admin cannot read them. If I cared about them seeing who I'm talking to, I would run my own server

[–] [email protected] 1 points 1 year ago

IDK, I think that's kind of flawed logic. E.g. "we should stop using gasoline for cars and switch to electric" - would you say "what a stupid thing to say. everyone uses gas so we shouldn't try to stop"?

And are you not aware of Signal? It's open source, and the default server is not, but it doesn't matter since it is E2E encrypted, just like Proton. The difference is that ProtonMail allows you to communicate unencrypted with non-ProtonMail accounts.

I think all they're saying is that, similar to gas users, there are many people who will not stop using it or just don't care unless we sunset gas cars / email for them.

I do agree with that, and in both cases it isn't something which can happen overnight, but it is a serious long term problem which IMO we should be pushing to solve.

[–] [email protected] 4 points 1 year ago (2 children)

you can e2e encrypt emails though?

[–] [email protected] 2 points 1 year ago

And then just go PGP if you want even more security.

[–] [email protected] 1 points 1 year ago

Yet everyone sends me one time passwords in plain text

[–] [email protected] 3 points 1 year ago

autocrypt has been around a while. get your contacts to use it.

[–] [email protected] 1 points 1 year ago* (last edited 1 year ago)

That's what s/mime does. If it were as easy to get personal certs as it is to get server certs through letsencrypt, everyone could easily sign and encrypt mail.

I can certainly do it anyway, but you'd have to trust my self signed cert.

That said, it's pretty rare to find relays these days that are not using tls for transport, so there's that.