TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Skiff: Various Privacy Failures

60 pointsby uselpaover 1 year ago

4 comments

cedwsover 1 year ago
I see Skiff also advertises itself as &quot;end-to-end&quot; encrypted. This is the same misleading advertising as ProtonMail is guilty of. Traditional email <i>cannot</i> be E2E encrypted because of protocol limitations. You <i>can</i> technically achieve E2E encryption if using PGP, but if the private keys are not in your control then it is effectively pointless.<p>ProtonMail can only guarantee E2E encryption without PGP if you are sending email to another ProtonMail user. I don&#x27;t know if Skiff also offers this special kind of encryption. Either way, they should be more upfront about the level of privacy they can offer.<p>I had a read of Skiff&#x27;s page on E2EE. It is very carefully worded and, from a skim read, is not upfront about the fact that un-PGP&#x27;d email sent and received through Skiff can be read by Skiff.<p><a href="https:&#x2F;&#x2F;skiff.com&#x2F;blog&#x2F;end-to-end-encryption-email" rel="nofollow">https:&#x2F;&#x2F;skiff.com&#x2F;blog&#x2F;end-to-end-encryption-email</a><p>Oh, one more thing. Skiff&#x27;s SMTP server (inbound-smtp.skiff.com) is running on AWS in the United States which means it will be beholden to US warrants. Skiff does not have a warrant canary. Getting big Crypto AG vibes from this.
评论 #38995210 未加载
评论 #39012616 未加载
lcofover 1 year ago
Great read, I have seen this myself in the last 4-5 years with services surfing on the privacy wave - I mean, not just email, but also cloud drive. My conclusion, even regarding established privacy-focused email providers, is that it’s not worth the hassle, really. I use trusted and reliable email providers (according to me), and I just don’t use email for anything sensitive. That’s just right for me.<p>I know some people do need more privacy and&#x2F;or security. But a lot of people think they need the same but really, they don’t.
forwardemailover 1 year ago
Forward Email team here (<a href="https:&#x2F;&#x2F;forwardemail.net" rel="nofollow">https:&#x2F;&#x2F;forwardemail.net</a>), we have a write-up and comparison @ <a href="https:&#x2F;&#x2F;forwardemail.net&#x2F;en&#x2F;blog&#x2F;docs&#x2F;best-quantum-safe-encrypted-email-service" rel="nofollow">https:&#x2F;&#x2F;forwardemail.net&#x2F;en&#x2F;blog&#x2F;docs&#x2F;best-quantum-safe-encr...</a><p>We&#x27;ve considered adding a E2EE comparison column as well (with the issues such as Proton rewriting your emails @ <a href="http:&#x2F;&#x2F;jfloren.net&#x2F;b&#x2F;2023&#x2F;7&#x2F;7&#x2F;0" rel="nofollow">http:&#x2F;&#x2F;jfloren.net&#x2F;b&#x2F;2023&#x2F;7&#x2F;7&#x2F;0</a> highlighted).<p>Privacy Guides Discussion @ <a href="https:&#x2F;&#x2F;discuss.privacyguides.net&#x2F;t&#x2F;forward-email-email-provider&#x2F;13370" rel="nofollow">https:&#x2F;&#x2F;discuss.privacyguides.net&#x2F;t&#x2F;forward-email-email-prov...</a><p>Unlike Skiff, Proton, and Tuta... we&#x27;re _actually_ 100% open-source. Those providers that advertise as open-source really only open-source the front-end, when the back-end is the most sensitive part of an email service.
评论 #38994858 未加载
评论 #38996273 未加载
评论 #38995802 未加载
评论 #38995206 未加载
crimblesover 1 year ago
Interesting read. I will point out that having seen <i>&quot;security audits&quot;</i> done by top tier well known security companies, they aren&#x27;t worth the paper they are written on. They are selling you a pen test script run, the output of which is farted into a document for the least amount of time they can expend on it.<p>If you want security, you have to do it in house with competent people who understand your business domain. So when I see people with regular pen tests I know they don&#x27;t really give a shit because they are doing minimal ass coverage.
评论 #38994350 未加载
评论 #38994425 未加载