Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, at some point people are going to work out that the problem isn't Johnny, it's email. Email is distinctively hostile to secure messaging. No matter what software Johnny uses, "secure" email will always be inferior to alternative options.

https://www.latacora.com/blog/2020/02/19/stop-using-encrypte...





"The most popular modern secure messaging tool is Signal"

As Mike Waltz had found out. And Snowden used gpg and I haven't heard of a single message of his having been decrypted.


Snowden also endorsed Signal, fwiw: https://x.com/Snowden/status/661313394906161152

Snowden also used Cryptocat.

Both PGP and Signal will leak if you use them incorrectly, so that comparison doesn't really hold up.

I say this as someone who uses both.


PGP email doesn't match Signal security:

* PGP doesn't encrypt email metadata, so the attacker gets a record of every senders, receiver, time, date, and subject line, for free, with PGP actually working at its best.

* Email usually isn't usable without storing it server-side (for multi-client access), and without being able to search it. That requires your email to be in clear text on the server. That's solved with an on-prem mail server, but not many people have that - very few end users can operate one.

* Email endpoints generally aren't secure, so even if you somehow secure your personal mail store, possibly nothing is secure except your draft messages. Every email is sent to or received from other people, so your messages are subject to their security practices.


One key difference is that Signal intentionally makes design choices to make it harder to use incorrectly, and PGP is comically easy to use incorrectly.

Snowden was a Sharepoint administrator with no demonstrated expertise in cryptography or in communications security.

What he does or does not endorse means nothing.


Mike Waltz is just about dumb enough to pile out his own eyes with his thumbs. At which point we will be regaled with the danger of thumbs forevermore.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: