Salta al contenuto
0
  • Home
  • Piero Bosio
  • Blog
  • Mondo
  • Fediverso
  • News
  • Categorie
  • Recenti
  • Popolare
  • Tag
  • Utenti
  • Home
  • Piero Bosio
  • Blog
  • Mondo
  • Fediverso
  • News
  • Categorie
  • Recenti
  • Popolare
  • Tag
  • Utenti
Skin
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Predefinito (Nessuna skin)
  • Nessuna skin
Collassa

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone
  1. Home
  2. Categorie
  3. Senza categoria
  4. 🔐 Every unencrypted email is readable by 10+ entities and stored forever.

🔐 Every unencrypted email is readable by 10+ entities and stored forever.

Pianificato Fissato Bloccato Spostato Senza categoria
webkeydirectorywkdemailencryptionprivacyinfoseccryptographyopenpgp
46 Post 12 Autori 0 Visualizzazioni
  • Da Vecchi a Nuovi
  • Da Nuovi a Vecchi
  • Più Voti
Rispondi
  • Topic risposta
Effettua l'accesso per rispondere
Questa discussione è stata eliminata. Solo gli utenti con diritti di gestione possono vederla.
  • Nicola Fabianoundefined Nicola Fabiano

    @grant_h 2/2 - Think of it like HTTPS adoption:

    - WKD = certificate infrastructure (like Let's Encrypt)
    - Autocrypt/client logic = protocol negotiation
    - Warnings = mixed content alerts

    So yes, the ecosystem supports "encrypt when possible" — WKD makes finding keys automatic. The clients handle the graceful degradation you're looking for.

    Grant_Hundefined Questo utente è esterno a questo forum
    Grant_Hundefined Questo utente è esterno a questo forum
    Grant_H
    scritto su ultima modifica di
    #37

    @nicfab My use case is a school. Teachers and students. Particularly the counselling staff. It has to be easy and seamless, and resetable by our admins.
    Unfortunately, the big companies have no incentive to make our email private, and every incentive to make it easy to join. The precise opposite of so many FOSS projects. We will persevere!

    Nicola Fabianoundefined 1 Risposta Ultima Risposta
    • Grant_Hundefined Grant_H

      @nicfab My use case is a school. Teachers and students. Particularly the counselling staff. It has to be easy and seamless, and resetable by our admins.
      Unfortunately, the big companies have no incentive to make our email private, and every incentive to make it easy to join. The precise opposite of so many FOSS projects. We will persevere!

      Nicola Fabianoundefined Questo utente è esterno a questo forum
      Nicola Fabianoundefined Questo utente è esterno a questo forum
      Nicola Fabiano
      scritto su ultima modifica di
      #38

      @grant_h Go ahead!

      1 Risposta Ultima Risposta
      • Nicola Fabianoundefined Nicola Fabiano

        🔐 Every unencrypted email is readable by 10+ entities and stored forever.

        Web Key Directory (WKD) changes this: automatic encryption using your domain name. No manual keys. No central servers. Just cryptographic certainty.

        WKD makes encrypted email as simple as HTTPS made web browsing secure.

        https://www.nicfab.eu/en/posts/wkd2/

        #WebKeyDirectory #WKD #EmailEncryption #Privacy #InfoSec #Cryptography #OpenPGP

        Sebastian Schinzelundefined Questo utente è esterno a questo forum
        Sebastian Schinzelundefined Questo utente è esterno a questo forum
        Sebastian Schinzel
        scritto su ultima modifica di
        #39

        @nicfab @Fr333k Just an observation: that's a long blog post, with a lot of words and with a lot of computer commands and that somewhat contradicts the sentence "WKD makes encrypted email as simple as HTTPS made web browsing secure."

        Nothing is simple with OpenPGP and email and that's broadly documented in academia and annecdotes. WKD does not change that.

        If you absolutely positively must use email for sending sensitive info, use S/MIME.

        Nicola Fabianoundefined 1 Risposta Ultima Risposta
        • Sebastian Schinzelundefined Sebastian Schinzel

          @nicfab @Fr333k Just an observation: that's a long blog post, with a lot of words and with a lot of computer commands and that somewhat contradicts the sentence "WKD makes encrypted email as simple as HTTPS made web browsing secure."

          Nothing is simple with OpenPGP and email and that's broadly documented in academia and annecdotes. WKD does not change that.

          If you absolutely positively must use email for sending sensitive info, use S/MIME.

          Nicola Fabianoundefined Questo utente è esterno a questo forum
          Nicola Fabianoundefined Questo utente è esterno a questo forum
          Nicola Fabiano
          scritto su ultima modifica di
          #40

          @seecurity @Fr333k You’re right that nothing in email crypto is ever “simple” — WKD doesn’t change the complexity of OpenPGP itself. However, it does solve a particular problem that has long blocked adoption: key discovery.

          That doesn’t contradict the analogy with HTTPS — it’s about lowering friction, not erasing complexity.
          And yes, S/MIME can be smoother in some contexts, but WKD gives domains a way to make OpenPGP more usable in practice.

          Sebastian Schinzelundefined 1 Risposta Ultima Risposta
          • Nicola Fabianoundefined Nicola Fabiano

            @seecurity @Fr333k You’re right that nothing in email crypto is ever “simple” — WKD doesn’t change the complexity of OpenPGP itself. However, it does solve a particular problem that has long blocked adoption: key discovery.

            That doesn’t contradict the analogy with HTTPS — it’s about lowering friction, not erasing complexity.
            And yes, S/MIME can be smoother in some contexts, but WKD gives domains a way to make OpenPGP more usable in practice.

            Sebastian Schinzelundefined Questo utente è esterno a questo forum
            Sebastian Schinzelundefined Questo utente è esterno a questo forum
            Sebastian Schinzel
            scritto su ultima modifica di
            #41

            @nicfab @Fr333k Email crypto is extremely complex and because of this, has plenty of attack surface. We published close to 10 papers in the last seven years attacking email and email encryption with OpenPGP and S/MIME.

            I am at the point where I find recommending email encryption to be actively harmful. Metadata leaks all over the place, crypto from the '90s, plaintext fallbacks everywhere, user hate it, in particular the gnupg devs are very toxic, mail client developers lack time and (too often) expertise to implement it properly.

            Just use Signal. If you got budget, build an app on top of Signal. Heck, just use WhatsApp. Just don't even try to send sensitive information with email encryption.

            Nicola Fabianoundefined 1 Risposta Ultima Risposta
            • Sebastian Schinzelundefined Sebastian Schinzel

              @nicfab @Fr333k Email crypto is extremely complex and because of this, has plenty of attack surface. We published close to 10 papers in the last seven years attacking email and email encryption with OpenPGP and S/MIME.

              I am at the point where I find recommending email encryption to be actively harmful. Metadata leaks all over the place, crypto from the '90s, plaintext fallbacks everywhere, user hate it, in particular the gnupg devs are very toxic, mail client developers lack time and (too often) expertise to implement it properly.

              Just use Signal. If you got budget, build an app on top of Signal. Heck, just use WhatsApp. Just don't even try to send sensitive information with email encryption.

              Nicola Fabianoundefined Questo utente è esterno a questo forum
              Nicola Fabianoundefined Questo utente è esterno a questo forum
              Nicola Fabiano
              scritto su ultima modifica di
              #42

              @seecurity @Fr333k

              It’s true: email crypto has flaws and decades of technical debt. But saying “just use Signal or WhatsApp” trades one problem for another — centralized silos controlled by single entities, which is even worse for long-term resilience, governance, and privacy.

              WKD won’t magically fix email, but it removes real barriers and raises the baseline. Abandoning open, federated protocols entirely in favor of walled gardens is not a sustainable path.

              1 Risposta Ultima Risposta
              • Nicola Fabianoundefined Nicola Fabiano

                🔐 Every unencrypted email is readable by 10+ entities and stored forever.

                Web Key Directory (WKD) changes this: automatic encryption using your domain name. No manual keys. No central servers. Just cryptographic certainty.

                WKD makes encrypted email as simple as HTTPS made web browsing secure.

                https://www.nicfab.eu/en/posts/wkd2/

                #WebKeyDirectory #WKD #EmailEncryption #Privacy #InfoSec #Cryptography #OpenPGP

                ⁉️undefined Questo utente è esterno a questo forum
                ⁉️undefined Questo utente è esterno a questo forum
                ⁉️
                scritto su ultima modifica di
                #43

                @nicfab I already have a webserver for my website using my own domain name, do I need a second one or is it possible to combine this somehow?

                Really interesting, first I hear of it. Thanks for sharing it!

                Nicola Fabianoundefined 1 Risposta Ultima Risposta
                • ⁉️undefined ⁉️

                  @nicfab I already have a webserver for my website using my own domain name, do I need a second one or is it possible to combine this somehow?

                  Really interesting, first I hear of it. Thanks for sharing it!

                  Nicola Fabianoundefined Questo utente è esterno a questo forum
                  Nicola Fabianoundefined Questo utente è esterno a questo forum
                  Nicola Fabiano
                  scritto su ultima modifica di
                  #44

                  @chiefbongo WKD is for a single domain name only. They cannot be combined, but you can have multiple WKD configurations for numerous domain names on the server.

                  1 Risposta Ultima Risposta
                  • Nicola Fabianoundefined Nicola Fabiano

                    @thedarktangent @yawnbox I share your concern — past attempts (PGP in DNS, DANE, SMILE, etc.) struggled with adoption. WKD isn’t a complete solution, but it’s worth setting up: it removes a key barrier and makes encrypted mail more usable, even if challenges like local search and subject-line leaks remain.

                    Jeff Mossundefined Questo utente è esterno a questo forum
                    Jeff Mossundefined Questo utente è esterno a questo forum
                    Jeff Moss
                    scritto su ultima modifica di
                    #45

                    @nicfab @yawnbox I was checking out the defaults on Thunderbird and it looks like this feature is off by default unfortunately. They must not want to delay sending by doing the extra lookups?

                    Nicola Fabianoundefined 1 Risposta Ultima Risposta
                    • Jeff Mossundefined Jeff Moss

                      @nicfab @yawnbox I was checking out the defaults on Thunderbird and it looks like this feature is off by default unfortunately. They must not want to delay sending by doing the extra lookups?

                      Nicola Fabianoundefined Questo utente è esterno a questo forum
                      Nicola Fabianoundefined Questo utente è esterno a questo forum
                      Nicola Fabiano
                      scritto ultima modifica di
                      #46

                      @thedarktangent @yawnbox I don't know.

                      1 Risposta Ultima Risposta
                      Rispondi
                      • Topic risposta
                      Effettua l'accesso per rispondere
                      • Da Vecchi a Nuovi
                      • Da Nuovi a Vecchi
                      • Più Voti


                      • 1
                      • 2
                      • 3
                      Feed RSS
                      🔐 Every unencrypted email is readable by 10+ entities and stored forever.

                      Gli ultimi otto messaggi ricevuti dalla Federazione
                      • stefania mauriziundefined
                        stefania maurizi

                        At the #ItalianTechWeek, John Elkann will be joined by the Lord of #Amazon in person, Jeff Bezos, and Lords of #Arms companies such as #Leonardo. We will bring #Resistance:
                        technology for the 99%, NOT for the 1%, for #Peace.

                        per saperne di più

                      • Maronno Winchester :antifa:undefined
                        Maronno Winchester :antifa:

                        Trump e Netanyahu: la pace come rapina | Left

                        https://left.it/2025/09/30/trump-e-netanyahu-la-pace-come-rapina/

                        > Altro che pace: siamo di fronte all’ennesima colonizzazione mascherata

                        per saperne di più

                      • adriananselmoundefined
                        adriananselmo

                        Comunque la mattinata sta passando in modo molto confuso.

                        per saperne di più

                      • adriananselmoundefined
                        adriananselmo

                        Rimango sempre molto basita da certi comportamenti umani. Nonostante l'età su alcune cose rimango ingenua. Non capisco se è un bene o un male.

                        per saperne di più

                      • stefania mauriziundefined
                        stefania maurizi

                        Buongiorno,
                        John Elkann &Co porteranno a Torino #ItalianTechWeek: la tecnologia che sta rivoluzionando il mondo secondo piani e interessi dei signori della #Guerra,#Sorveglianza,#Capitalismo.
                        Noi porteremo la #Resistenza, grazie #SerenaDoe per #ItalianTechResistance

                        per saperne di più

                      • marcoboccaccioundefined
                        marcoboccaccio

                        Osservatorio Nazionale di Bologna morti sul lavoro: Report morti sul lavoro dall'inzio dell'anno al 30 settembre

                        https://cadutisullavoro.blogspot.com/2025/09/report-morti-sul-lavoro-dallinzio.html?m=1

                        per saperne di più

                      • Flippin' 'eck, Tucker!undefined
                        Flippin' 'eck, Tucker!

                        #NIST have issued updated #password guidelines for businesses. Interestingly they now say that requiring special characters is no longer a recommendation, but longer passwords / passphrases (using spaces) is a better idea.

                        I say "interesting" because that's something I've been doing for many years, long before I discovered password managers to remember things for me.

                        https://proton.me/blog/nist-password-guidelines

                        #infosec

                        per saperne di più

                      • marcoboccaccioundefined
                        marcoboccaccio

                        @bbacc @ModestinoSycamore @filobus @materialgirl succede sempre più spesso, devono essere le scie chimiche e il 5g 🤣

                        per saperne di più
                      @pierobosio@soc.bosio.info
                      Avvio NodeBB v4.5.2 Contributors
                      Post suggeriti
                      • Redhotcyberundefined

                        🔥 SONO UFFICIALMENTE APERTE LE ISCRIZIONI!

                        Seguito Ignorato Pianificato Fissato Bloccato Spostato Senza categoria redhotcyber formazione cybersecurity darkweb cyberthreatintelligenc ethicalhacking infosec intelligence
                        1
                        1
                        0 Votazioni
                        1 Post
                        0 Visualizzazioni
                        Nessuno ha risposto
                      • Linux Easyundefined

                        Murena lancia HIROH, lo smartphone che protegge davvero la tua privacy.

                        Seguito Ignorato Pianificato Fissato Bloccato Spostato Senza categoria murena hiroh privacy linuxmobile eos
                        1
                        0 Votazioni
                        1 Post
                        3 Visualizzazioni
                        Nessuno ha risposto
                      • Em :official_verified:undefined

                        Step 1: Assemble a great team 🙌Step 2: Privacy accessible to everyone 🔒Step 3: Non-profit 💚Privacy Guides needs your help to keep fighting for your privacy rights

                        Seguito Ignorato Pianificato Fissato Bloccato Spostato Senza categoria privacyguides privacy nonprofit donation support charity
                        1
                        0 Votazioni
                        1 Post
                        3 Visualizzazioni
                        Nessuno ha risposto
                      • Fabrizio :archlinux: :tardis:undefined

                        È successo di nuovo, anche Linkedin come Facebook e Instagram utilizzano i dati degli utenti per addestrare i modelli IA senza chiedere il consenso esplicito

                        Seguito Ignorato Pianificato Fissato Bloccato Spostato Senza categoria privacy fuckai
                        1
                        2
                        0 Votazioni
                        1 Post
                        2 Visualizzazioni
                        Nessuno ha risposto
                      • Accedi

                      • Accedi o registrati per effettuare la ricerca.
                      • Primo post
                        Ultimo post