Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Great. When that is done, then do email with is frankly a far more retractable problem in general (and a field where there is almost zero innovation or improvement, thanks to Microsoft (Exchange/Outlook/Outlook.com), Apple (Mail), and Google (Gmail)).


What's wrong with email? It's a 40 year old standard that still works great.


I believe he's referring to the fact that a lot of email communication is still plaintext: https://www.google.com/transparencyreport/saferemail/

Of the communication that's nominally protected by TLS, a lot of it can probably be trivially broken by an active MITM attack that either (1) prevents a connection from being upgraded to TLS, in which case it typically remains plaintext (see STARTTLS), or (2) establishes the connection under a self-signed certificate, which will suffice since many email systems do not perform certificate path validation.


Mm you mean RFC 822 - well thats the down side of internet standards x.400 had a lot of nice security features but the cheap and cheerful SMTP email standards won that war a long time ago.

I used to do X.400 and x.500 for a Large Telco back in the Day.

It's a trade off between ease of use and cost - and is a tech example of Gresham's Law


It is insecure in so many ways...


One thing that amazes me is that I get a huge volume of spam emails that claim to be from financial institutions. I use gmail for two reasons: (i) deliverability to mailing lists I need to be on and (2) other mail programs don't filter that junk out.

In 2015 it should be impossible to send a fake email from chase.com


If chase.com uses dkim and spf records and if your mail server is properly configured then it is indeed impossible.


and, of course, DMARC -- so rejection policies can be set.

PGP FTW!

Now if only STEED would be implemented... http://g10code.com/docs/steed-usable-e2ee.pdf

But, unfortunately, even mail from a properly configured mail server on properly protected domain will still end up in gmail users' spam boxes by default. Domain and server rep systems are a bear to work with.


In what ways? Mail servers can be configured to require only encrypted connections. You can also use GPG to encrypt your messages.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: