TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

It is unlikely that built-in email encryption will ever be available in Gmail

196 点作者 wil_I_am_27大约 6 年前

16 条评论

tkfu大约 6 年前
&gt; While it is possible to encrypt certain emails in Gmail with GPG, Google can still read all email meta-data such as email addresses and subject lines. Better use a Gmail alternative that encrypts your entire mailbox and contacts automatically.<p>This is nonsense. Any email service will be able to see the recipients (and senders) of your messages, because that&#x27;s how email works. Subject lines too, again, because that&#x27;s how email works.<p>E2E encryption of email is a good thing, GPG is hard. These things have be true forever.
评论 #19440874 未加载
评论 #19440747 未加载
评论 #19440784 未加载
评论 #19440634 未加载
yuz大约 6 年前
This is a promotion article for an end-to-end encrypted mail service called tutanota. They claim that google abandonment of the mail encryption project impiles that gmail encryption will necessarily never be available for gmail users.
politelemon大约 6 年前
It was dead the moment they put it on Github. Their blog post[1] claimed:<p>&gt; E2EMail is not a Google product, it’s now a fully community-driven open source project, to which passionate security engineers from across the industry have already contributed.<p>But looking at the commit history[2] makes it clear that was not the case at all.<p>Although this post is by Tutanota (and I can&#x27;t tell if Tutanota supports PGP), Protonmail does support PGP emails.<p>1: <a href="https:&#x2F;&#x2F;security.googleblog.com&#x2F;2017&#x2F;02&#x2F;e2email-research-project-has-left-nest_24.html" rel="nofollow">https:&#x2F;&#x2F;security.googleblog.com&#x2F;2017&#x2F;02&#x2F;e2email-research-pro...</a><p>2: <a href="https:&#x2F;&#x2F;github.com&#x2F;e2email-org&#x2F;e2email&#x2F;commits&#x2F;master" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;e2email-org&#x2F;e2email&#x2F;commits&#x2F;master</a>
评论 #19440973 未加载
评论 #19440729 未加载
hannob大约 6 年前
I know it&#x27;s a bit old, but since I read this I cannot possibly take Tutanota seriously on anything crypto:<p><a href="https:&#x2F;&#x2F;tutanota.uservoice.com&#x2F;forums&#x2F;237921-general&#x2F;suggestions&#x2F;7858974-tutanota-is-using-unauthenticated-aes-cbc-encrypti" rel="nofollow">https:&#x2F;&#x2F;tutanota.uservoice.com&#x2F;forums&#x2F;237921-general&#x2F;suggest...</a> <a href="https:&#x2F;&#x2F;seclists.org&#x2F;fulldisclosure&#x2F;2015&#x2F;Jun&#x2F;58" rel="nofollow">https:&#x2F;&#x2F;seclists.org&#x2F;fulldisclosure&#x2F;2015&#x2F;Jun&#x2F;58</a>
Leace大约 6 年前
The article has a point but do know that Tutanota is using their own custom encryption scheme. I can understand they don&#x27;t want to support PGP if they have something better but judging from their FAQ [0] they just replicated what PGP already can do [1] [2] effectively reinventing square wheel.<p>As for browser encryption Mailvelope [3] works and can even use local GnuPG (through NativeMessaging). FlowCrypt [4] is a little bit more tightly integrated with Gmail (through their API).<p>[0]: <a href="https:&#x2F;&#x2F;tutanota.com&#x2F;faq&#x2F;#pgp" rel="nofollow">https:&#x2F;&#x2F;tutanota.com&#x2F;faq&#x2F;#pgp</a><p>[1]: &quot;That&#x27;s why we have developed a solution that is also based on recognized algorithms (RSA and AES) and that automatically encrypts the subject, the content and the attachments.&quot;<p>[2]: <a href="https:&#x2F;&#x2F;github.com&#x2F;autocrypt&#x2F;memoryhole#memory-hole-protected-e-mail-headers" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;autocrypt&#x2F;memoryhole#memory-hole-protecte...</a><p>[3]: <a href="https:&#x2F;&#x2F;www.mailvelope.com&#x2F;en" rel="nofollow">https:&#x2F;&#x2F;www.mailvelope.com&#x2F;en</a><p>[4]: <a href="https:&#x2F;&#x2F;flowcrypt.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;flowcrypt.com&#x2F;</a>
评论 #19441570 未加载
mikekchar大约 6 年前
In the meantime I&#x27;m using mutt on the desktop on K9 on Android. I have to say that K9 is brilliant (mutt less so, but I like it ;-)). It&#x27;s the closest &quot;it just works&quot; E2E mail client I&#x27;ve ever used. Unfortunately the reality of PGP is that it&#x27;s hard for a normal person to use, although I&#x27;ve got my Dad using it for all of our email.
snvzz大约 6 年前
We need the Dark Mail Alliance more than ever.<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Dark_Mail_Alliance" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Dark_Mail_Alliance</a><p><a href="https:&#x2F;&#x2F;darkmail.info&#x2F;downloads&#x2F;dark-internet-mail-environment-june-2018.pdf" rel="nofollow">https:&#x2F;&#x2F;darkmail.info&#x2F;downloads&#x2F;dark-internet-mail-environme...</a><p><a href="https:&#x2F;&#x2F;github.com&#x2F;lavabit&#x2F;" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;lavabit&#x2F;</a>
LinuxBender大约 6 年前
GPG is hard for some, but 7-zip is easy for most. Not perfect, but perfect is enemy of good. Just put your email, files, whatever in a 7-zip encrypted and compressed file and email that.<p>Tell your friend the password over voice chat, or some other chat that is in no way related to your mail provider. Even a weak password is better than trusting the mail provider to handle this job. Here is a 7-zip file with a very simple password. [1] Please reply with the contents of the text file in the 7z.<p>[1] - <a href="https:&#x2F;&#x2F;tinyvpn.org&#x2F;5&#x2F;e&#x2F;f&#x2F;5efed61e6efe235d965547999292279e.7z" rel="nofollow">https:&#x2F;&#x2F;tinyvpn.org&#x2F;5&#x2F;e&#x2F;f&#x2F;5efed61e6efe235d965547999292279e.7...</a>
stirfrykitty大约 6 年前
If all one wants to do is communicate securely with another person and what your typing is private but not &quot;illegal&quot;, then why even send email. Simply use the Drafts in GMail. Compose an email and leave it in Drafts. Each person amends the draft and they can agree on times to check and update. This has been done with great success before if you want nothing &quot;going across the wire&quot; so to speak.
nukeop大约 6 年前
Advertisement for tutanota. Just use GPG like everybody who knows what they&#x27;re doing.
kjar大约 6 年前
Mass surveillance is kinda Google’s model
jimnutt大约 6 年前
So, I&#x27;m sure this idea has holes all over it, but how about a very simple service that you log into with your PGP public key, then would allow you to post encrypted messages to other PGP public keys and retrieve messages posted to your public key. It could be fully anonymous, depending on your choice of keys. It would be very similar to the mixmaster remailers, except it wouldn&#x27;t actual mail anything as it wouldn&#x27;t have any identifiable information other than the public key.
评论 #19448123 未加载
vlastik大约 6 年前
Why not something like Let&#x27;s Encrypt, but for S&#x2F;MIME?
评论 #19440933 未加载
Causality1大约 6 年前
&quot;shows where Google&#x27;s real interests are: Not in protecting their users&#x27; private data, but in harvesting it for their own benefit.&quot;<p>Well, Duh. That&#x27;s the deal. &quot;in exchange for this service we will scrape your data in order to serve ads&quot;. If you don&#x27;t like it go somewhere else. Google doesn&#x27;t owe you a free email service.
hguhghuff大约 6 年前
The problem with Email is that it’s routed, store and forward, whereas there’s no reason why it shouldnt be point to point.<p>If you wanted to revolutionize email then you’d create a point to point email service.
评论 #19442129 未加载
评论 #19441134 未加载
评论 #19440845 未加载
chiefalchemist大约 6 年前
I&#x27;m not a fan of email, and not only because of security &#x2F; privacy. Yes, it&#x27;s ubiquitous and convenient; and great for quick simple messages.<p>But it&#x27;s not (in a biz &#x2F; life context) a project management tool. So aside from &quot;where do you want to go for lunch?&quot; the appropriateness of email breaks down pretty quick. Unfortunately, the habit and convenience not so much so.<p>Ideally, we&#x27;re nudging towards a tipping point where email gets replaced by more appropriate (planning and proj management) tools - even at the personal level.
评论 #19441937 未加载