Zum Inhalt der Seite gehen


I was wondering ... as #email encryption via PGP/GnuPG is not suitable for true and ongoing end-to-end confidentiality. But what about authenticity of mails? I dislike S/MIME for its corporate nature, and #PGP via PGP/MIME is well enough supported by many (free) mail clients.

What's the #cryptography or #security community's view on PGP for signing emails? Or what would a suitable alternative be? I haven't come across any, though.

1/2

Dieser Beitrag wurde bearbeitet. (4 Tage her)
Als Antwort auf Guy

Off the top of my head I can think of one alternative if metadata confidentiality or anonymity matter:

Bitmessage: github.com/Bitmessage/PyBitmes…

Bitmessage hides non-content metadata and uses a flood mixnet to unlink sender and receiver from eavesdropper view.

There is no alternative for email. Email clients support PGP and that's it. PGP does guarantee authenticity of a message due to digital signatures. PGP does not hide metadata about sender and receiver.

If you want truly confidential communication you have to set up a private pipeline. If you are using a public paid or free email service, you have zero confidentiality. Even if your message is encrypted, the email operators know who you are talking to.

#PGP #Email #Encryption #Privacy

Unbekannter Ursprungsbeitrag

OCTADE
Unbekannter Ursprungsbeitrag

Guy

@wiktor
@octade
I *really* appreciate your input here. The purpose of this thread is to venture into opportunities to improve traditional email in a way that doesn't suck (as @soatok also states in depth in his blog post that #email for socially working end-to-end confidentiality sucks). It is also not about other tools (like Signal, Bitmessage, Briar, ...).

This is about potential #cryptography for #authenticity or mon-repudiation use cases of email. PGP flavours, S/MIME or something else?

Diese Webseite verwendet Cookies. Durch die weitere Benutzung der Webseite stimmst du dieser Verwendung zu. https://inne.city/tos