TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Encrypted e-mail: How much annoyance will you tolerate to keep the NSA away?

72 pointsby greenburgeralmost 12 years ago

17 comments

arochalmost 12 years ago
Nowadays is GPG&#x2F;PGP-ing your emails really that hard? Thunderbird supports GPG on all platforms, Apple&#x27;s default Mail works with PGP&#x2F;GPG, I&#x27;m sure there are plenty of windows clients that do the same. In additional, online providers like Hush are bringing PGP to the masses without them having to know what in fucks name it is.<p>Even if you don&#x27;t encrypt every mail you send, signing is a good idea. Is it unnecessary in many circumstances? Yes, but at least I find it nice to be able to verify authenticity. I don&#x27;t understand why my bank (Wells Fargo) can&#x27;t figure out how to sign all their emails [1].<p>______<p>1: <a href="https:&#x2F;&#x2F;www.wellsfargo.com&#x2F;downloads&#x2F;pdf&#x2F;com&#x2F;cps&#x2F;Secure_Email_User_Guide.pdf" rel="nofollow">https:&#x2F;&#x2F;www.wellsfargo.com&#x2F;downloads&#x2F;pdf&#x2F;com&#x2F;cps&#x2F;Secure_Emai...</a><p>Yes, they can sign some emails...but it requires someone inside WF &quot;sponsor&quot; you to be added to their PKI and it still won&#x27;t lead to signed or even encrypted emails for online banking. WF is also particularly egregious in not offering <i>real</i> 2FA...they count a username AND a password as &quot;two factor authentication&quot;. <i>sigh</i>
评论 #5880264 未加载
评论 #5880219 未加载
评论 #5880792 未加载
评论 #5880403 未加载
snarfyalmost 12 years ago
I can&#x27;t support arstechnica anymore after the hatchet job done by joe mullin against snowden.<p><a href="http:&#x2F;&#x2F;arstechnica.com&#x2F;author&#x2F;joe-mullin-2&#x2F;" rel="nofollow">http:&#x2F;&#x2F;arstechnica.com&#x2F;author&#x2F;joe-mullin-2&#x2F;</a><p>How would you feel if your hacker news posts over the years were trolled into a very personal post about you on hacker news, done by a hacker news employee? The whole thing is creepy.
评论 #5880484 未加载
评论 #5880467 未加载
评论 #5880503 未加载
IBCNUalmost 12 years ago
I&#x27;m surprised more people haven&#x27;t read between the lines: the NSA is in possession of quantum computers and interference based decryption is probably already in standard use. Insiders also have dropped hints the Tor networks is, in fact, a trojan horse. We basically have two * extreme * options: 1) a trusted courier with a sealed envelope (don&#x27;t underestimate this Game of Thrones like scenario as the US Military defeated itself in the largest wargame in the gulf by using courier, sealed envelopes, and motorbikes) and 2) quantum cryptographic communication. The latter is still only the realm of university labs and down at LANL but I read a paper which stated it&#x27;s physically possible to pass keys along ethernet cable, but all parties need a device which acts as a gate. This in turn opens up Alice and Bob to traditional decryption methods if they&#x27;re not air gapped from the web.
评论 #5880433 未加载
评论 #5880943 未加载
评论 #5880474 未加载
评论 #5880845 未加载
评论 #5880505 未加载
评论 #5882931 未加载
评论 #5880404 未加载
xradionutalmost 12 years ago
Meta Comment: Considering that Ars is mining their forum database and pissing off members&#x2F;subscribers to post tabloid-style shaming articles about the NSA whistleblower, I believe the first step in privacy is to avoid visiting their web site ever again.
评论 #5880650 未加载
评论 #5880688 未加载
评论 #5880590 未加载
peter487almost 12 years ago
I am not sure if such system existed in the past or if I read about it in some sci-fi book, but it worked as follows:<p>You generated your key pair. In (almost) every country in almost every city there were “key signers” (basically trusted members of the PGP community). You met with them and they verified your identity and signed your public key. You needed to visit couple of them to get enough signatures to obtain certain level of trust in the PGP community. Once your level of trust was high enough you could start signing keys of other people. Too good to be true I guess…..
评论 #5880598 未加载
gesmanalmost 12 years ago
Encrypting email would only make sense if both sides are equally encrypting it. If you&#x27;re using the most paranoidal encryption, but your email buddy does not - than it&#x27;s all just plain silly.<p>But even then if Joe and Bill suddenly got smarty-pants and started encrypting their communication - NSA would get suspicious and <i>will</i> find out what you guys are up to via other channels.<p>&quot;The best way to hide information - is to convince others that it does not exists&quot; --Me
评论 #5880375 未加载
评论 #5880493 未加载
评论 #5880231 未加载
评论 #5880374 未加载
juntoalmost 12 years ago
Are there any heavily supported projects that seek to replace email as we know it with a &#x27;secure by default&#x27; implementation?<p>I.e. One that keeps the decentralized simplicity of email as it is today, whilst both securing it and removing the negatives, such as spam?<p>If Microsoft, Yahoo and Google got together they could flesh this out, and as long as the specifications were open and license free, then other third parties would start to develop SecMail servers.
评论 #5881546 未加载
评论 #5880858 未加载
评论 #5880869 未加载
评论 #5881042 未加载
zeidrichalmost 12 years ago
I wonder how much the use of methods to avoid detection by the NSA triggers warning flags that puts you under more individual scrutiny.<p>Sure, you can encrypt most things, but then maybe you look suspicious so you get special attention. Can you encrypt everything? Of course not.
评论 #5880940 未加载
pandogalmost 12 years ago
They appear to take a SHA1 Checksum from an unencrypted (non-HTTPS) website to verify the integrity of the download.<p>Surely if you&#x27;re worried about the integrity of the file you should also be worried about the integrity of the source website also?
评论 #5880744 未加载
annon2003almost 12 years ago
We are now using S&#x2F;mime and in today&#x27;s Apple+Thunderbird products it&#x27;s completely built-in and pain-free. Set it up once and after that all emails get encrypted automatically, you don&#x27;t even need to press a button. Provided of course that You were able to convince your colleagues to invest those 10 minutes to set it up as well. PGP Was painful because every Mail.app update broke it, not sure about the current state-of-the-art there. But the whole point should be: it is not much of an annoyance anymore! Zero annoyance after installation, Works even on your iPhone etc.
评论 #5880485 未加载
lazyjonesalmost 12 years ago
First things first.<p>PGP is useful, but pointless on a system that may be compromised&#x2F;backdoored at any time (e.g. Windows, iOS, Android ... ). So the first - and possibly most annoying - step would be to install a secure OS.
评论 #5880779 未加载
评论 #5880791 未加载
druiidalmost 12 years ago
I think it not outside the realm of realistic to imagine that the NSA has the ability to break all&#x2F;nearly all encrypted data with ease. I mean, I have had quite a few friends with PhD level mathematics degrees hired by the NSA. Haven&#x27;t heard from them in a while, but I can guess at the reasons behind hiring people like them.<p>Basically I would say the question isn&#x27;t if we should encrypt e-mail (I think we should in general, regardless of NSA spying), but instead what encryption methods (if any) exist that would be beyond the capabilities of the NSA to easily break.
评论 #5880504 未加载
petilonalmost 12 years ago
Why do you even want to keep the NSA away? I am more worried about companies such as Intelius than the NSA.<p>Private companies such as Intelius are posting my personal information on the internet.<p>Anyone who knows my real name can search the internet and find out where I work, my home address, my spouse&#x27;s name, my home phone number and my age. I didn&#x27;t put any of this information on the internet, in fact I don&#x27;t even have a facebook account. Private companies collected and aggregated this information and put it on the internet. Some of the information came from public records (for example, home address from property ownership records), but some was very private (such as my home phone number, which is not even in my name and rarely given out). This is a huge violation of privacy and I have no way of stopping it. Anyone that wants to harm me can find out where I live with a few clicks of the mouse.<p>I am not worried about the government spying on me. I am very worried about these for-profit businesses spying on me and outing my information on the internet. Why isn&#x27;t arstechnica writing stories about that instead?
评论 #5880799 未加载
cheynealmost 12 years ago
I&#x27;m just using <a href="https:&#x2F;&#x2F;www.noteshred.com" rel="nofollow">https:&#x2F;&#x2F;www.noteshred.com</a> to send private messages. I can&#x27;t be bothered with encrypted email software
znqalmost 12 years ago
What about Android and iOS? Any recommendations on email clients with a somewhat good user interface and experience?
tokenizerrralmost 12 years ago
Anyone know why it is that banks and the likes are not signing their emails? Seems like the perfect use-case.
评论 #5881235 未加载
评论 #5880884 未加载
chiphalmost 12 years ago
Hmm. Need to add my public key to my About page. Thanks for the reminder.<p>I wonder if I can add it to my LinkedIn profile?