Salta al contenuto
0
  • Home
  • Piero Bosio
  • Blog
  • Mondo
  • Fediverso
  • News
  • Categorie
  • Recenti
  • Popolare
  • Tag
  • Utenti
  • Home
  • Piero Bosio
  • Blog
  • Mondo
  • Fediverso
  • News
  • Categorie
  • Recenti
  • Popolare
  • Tag
  • Utenti
Skin
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Predefinito (Nessuna skin)
  • Nessuna skin
Collassa

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone
  1. Home
  2. Categorie
  3. Senza categoria
  4. 🔐 Every unencrypted email is readable by 10+ entities and stored forever.

🔐 Every unencrypted email is readable by 10+ entities and stored forever.

Pianificato Fissato Bloccato Spostato Senza categoria
webkeydirectorywkdemailencryptionprivacyinfoseccryptographyopenpgp
40 Post 11 Autori 0 Visualizzazioni
  • Da Vecchi a Nuovi
  • Da Nuovi a Vecchi
  • Più Voti
Rispondi
  • Topic risposta
Effettua l'accesso per rispondere
Questa discussione è stata eliminata. Solo gli utenti con diritti di gestione possono vederla.
  • Jeff Mossundefined Jeff Moss

    @nicfab @yawnbox An article about email security, but no mention of S/MIME?

    Nicola Fabianoundefined Questo utente è esterno a questo forum
    Nicola Fabianoundefined Questo utente è esterno a questo forum
    Nicola Fabiano
    scritto ultima modifica di
    #26

    @thedarktangent @yawnbox This article is not about email security but about WKD. I have already written about email security and will likely revisit the topic in the near future.

    Jeff Mossundefined 1 Risposta Ultima Risposta
    • Delta Chatundefined Delta Chat

      @nicfab @Blort we know there is an IETF doc about wkd. Delta is probably one of the most standards based messengers out there https://github.com/chatmail/core/blob/main/standards.md
      But that doesn't mean any IETF standard is unconditionally a good idea for resilient decentralized messaging.

      Nicola Fabianoundefined Questo utente è esterno a questo forum
      Nicola Fabianoundefined Questo utente è esterno a questo forum
      Nicola Fabiano
      scritto ultima modifica di
      #27

      @delta @Blort 1/3 - Absolutely right — IETF standards aren't automatically the best fit for every use case. DeltaChat is actually a great example of this nuanced approach: it leverages email infrastructure creatively while adding features like Autocrypt and ChatMail servers to address some of email's inherent limitations.

      1 Risposta Ultima Risposta
      • Delta Chatundefined Delta Chat

        @nicfab @Blort we know there is an IETF doc about wkd. Delta is probably one of the most standards based messengers out there https://github.com/chatmail/core/blob/main/standards.md
        But that doesn't mean any IETF standard is unconditionally a good idea for resilient decentralized messaging.

        Nicola Fabianoundefined Questo utente è esterno a questo forum
        Nicola Fabianoundefined Questo utente è esterno a questo forum
        Nicola Fabiano
        scritto ultima modifica di
        #28

        @delta @Blort 2/3 - WKD solves one specific problem (key discovery), making traditional email encryption more accessible. However, as you point out, true resilience requires more: forward secrecy, metadata protection, and decentralization without single points of failure.

        1 Risposta Ultima Risposta
        • Delta Chatundefined Delta Chat

          @nicfab @Blort we know there is an IETF doc about wkd. Delta is probably one of the most standards based messengers out there https://github.com/chatmail/core/blob/main/standards.md
          But that doesn't mean any IETF standard is unconditionally a good idea for resilient decentralized messaging.

          Nicola Fabianoundefined Questo utente è esterno a questo forum
          Nicola Fabianoundefined Questo utente è esterno a questo forum
          Nicola Fabiano
          scritto ultima modifica di
          #29

          @delta @Blort 3/3 - That's why I see WKD and projects like DeltaChat as complementary rather than competing — WKD improves the email baseline. At the same time, Delta pushes the boundaries of what email-based messaging can achieve. Different tools for different threat models and use cases.

          1 Risposta Ultima Risposta
          • Nicola Fabianoundefined Nicola Fabiano

            @thedarktangent @yawnbox This article is not about email security but about WKD. I have already written about email security and will likely revisit the topic in the near future.

            Jeff Mossundefined Questo utente è esterno a questo forum
            Jeff Mossundefined Questo utente è esterno a questo forum
            Jeff Moss
            scritto ultima modifica di
            #30

            @nicfab @yawnbox I have lived through essentially the same issues with PGP keys in DNS, hashes of SMime keys in DNS, MTA-STS, DANE for SMTP, automatic SMIME using SMILE, etc.

            I hope WKD does better! But I fear that without a solution to local email search it will be a victim of its own success, or you will have to put so much information in the subject line to remind you what is in the encrypted body that some privacy is lost.

            Nicola Fabianoundefined 1 Risposta Ultima Risposta
            • Nicola Fabianoundefined Nicola Fabiano

              @tudobem @PierricD It depends on the provider you chose. You can check Netcup or Contabo, which are more affordable options.

              tudobemundefined Questo utente è esterno a questo forum
              tudobemundefined Questo utente è esterno a questo forum
              tudobem
              scritto ultima modifica di
              #31

              @nicfab @PierricD thank you! would it be okay if I get back to you with questions in case they come up along the way?

              Nicola Fabianoundefined 1 Risposta Ultima Risposta
              • Jeff Mossundefined Jeff Moss

                @nicfab @yawnbox I have lived through essentially the same issues with PGP keys in DNS, hashes of SMime keys in DNS, MTA-STS, DANE for SMTP, automatic SMIME using SMILE, etc.

                I hope WKD does better! But I fear that without a solution to local email search it will be a victim of its own success, or you will have to put so much information in the subject line to remind you what is in the encrypted body that some privacy is lost.

                Nicola Fabianoundefined Questo utente è esterno a questo forum
                Nicola Fabianoundefined Questo utente è esterno a questo forum
                Nicola Fabiano
                scritto ultima modifica di
                #32

                @thedarktangent @yawnbox I share your concern — past attempts (PGP in DNS, DANE, SMILE, etc.) struggled with adoption. WKD isn’t a complete solution, but it’s worth setting up: it removes a key barrier and makes encrypted mail more usable, even if challenges like local search and subject-line leaks remain.

                1 Risposta Ultima Risposta
                • tudobemundefined tudobem

                  @nicfab @PierricD thank you! would it be okay if I get back to you with questions in case they come up along the way?

                  Nicola Fabianoundefined Questo utente è esterno a questo forum
                  Nicola Fabianoundefined Questo utente è esterno a questo forum
                  Nicola Fabiano
                  scritto ultima modifica di
                  #33

                  @tudobem @PierricD Of course, feel free to reach out anytime.

                  1 Risposta Ultima Risposta
                  • Nicola Fabianoundefined Nicola Fabiano

                    🔐 Every unencrypted email is readable by 10+ entities and stored forever.

                    Web Key Directory (WKD) changes this: automatic encryption using your domain name. No manual keys. No central servers. Just cryptographic certainty.

                    WKD makes encrypted email as simple as HTTPS made web browsing secure.

                    https://www.nicfab.eu/en/posts/wkd2/

                    #WebKeyDirectory #WKD #EmailEncryption #Privacy #InfoSec #Cryptography #OpenPGP

                    Grant_Hundefined Questo utente è esterno a questo forum
                    Grant_Hundefined Questo utente è esterno a questo forum
                    Grant_H
                    scritto ultima modifica di
                    #34

                    @nicfab
                    Reading the article, I can't see how this works out in a hybrid situation - where not all your email recipients are using WKD. Am I missing something?
                    You mention the strength of email being its own prison - we need something that would encrypt where possible, and fall back to plaintext where not (with warning). HTTPS was not implemented across the board overnight.

                    Nicola Fabianoundefined 2 Risposte Ultima Risposta
                    • Grant_Hundefined Grant_H

                      @nicfab
                      Reading the article, I can't see how this works out in a hybrid situation - where not all your email recipients are using WKD. Am I missing something?
                      You mention the strength of email being its own prison - we need something that would encrypt where possible, and fall back to plaintext where not (with warning). HTTPS was not implemented across the board overnight.

                      Nicola Fabianoundefined Questo utente è esterno a questo forum
                      Nicola Fabianoundefined Questo utente è esterno a questo forum
                      Nicola Fabiano
                      scritto ultima modifica di
                      #35

                      @grant_h 1/2 You're right — WKD alone doesn't handle the hybrid scenario. It's just key discovery, not the complete solution.
                      For opportunistic encryption, you need WKD plus smart clients: Thunderbird, DeltaChat, and others already do this — they check for keys via WKD/Autocrypt, encrypt when possible, and fall back to plaintext with warnings.

                      1 Risposta Ultima Risposta
                      • Grant_Hundefined Grant_H

                        @nicfab
                        Reading the article, I can't see how this works out in a hybrid situation - where not all your email recipients are using WKD. Am I missing something?
                        You mention the strength of email being its own prison - we need something that would encrypt where possible, and fall back to plaintext where not (with warning). HTTPS was not implemented across the board overnight.

                        Nicola Fabianoundefined Questo utente è esterno a questo forum
                        Nicola Fabianoundefined Questo utente è esterno a questo forum
                        Nicola Fabiano
                        scritto ultima modifica di
                        #36

                        @grant_h 2/2 - Think of it like HTTPS adoption:

                        - WKD = certificate infrastructure (like Let's Encrypt)
                        - Autocrypt/client logic = protocol negotiation
                        - Warnings = mixed content alerts

                        So yes, the ecosystem supports "encrypt when possible" — WKD makes finding keys automatic. The clients handle the graceful degradation you're looking for.

                        Grant_Hundefined 1 Risposta Ultima Risposta
                        • Nicola Fabianoundefined Nicola Fabiano

                          @grant_h 2/2 - Think of it like HTTPS adoption:

                          - WKD = certificate infrastructure (like Let's Encrypt)
                          - Autocrypt/client logic = protocol negotiation
                          - Warnings = mixed content alerts

                          So yes, the ecosystem supports "encrypt when possible" — WKD makes finding keys automatic. The clients handle the graceful degradation you're looking for.

                          Grant_Hundefined Questo utente è esterno a questo forum
                          Grant_Hundefined Questo utente è esterno a questo forum
                          Grant_H
                          scritto ultima modifica di
                          #37

                          @nicfab My use case is a school. Teachers and students. Particularly the counselling staff. It has to be easy and seamless, and resetable by our admins.
                          Unfortunately, the big companies have no incentive to make our email private, and every incentive to make it easy to join. The precise opposite of so many FOSS projects. We will persevere!

                          Nicola Fabianoundefined 1 Risposta Ultima Risposta
                          • Grant_Hundefined Grant_H

                            @nicfab My use case is a school. Teachers and students. Particularly the counselling staff. It has to be easy and seamless, and resetable by our admins.
                            Unfortunately, the big companies have no incentive to make our email private, and every incentive to make it easy to join. The precise opposite of so many FOSS projects. We will persevere!

                            Nicola Fabianoundefined Questo utente è esterno a questo forum
                            Nicola Fabianoundefined Questo utente è esterno a questo forum
                            Nicola Fabiano
                            scritto ultima modifica di
                            #38

                            @grant_h Go ahead!

                            1 Risposta Ultima Risposta
                            • Nicola Fabianoundefined Nicola Fabiano

                              🔐 Every unencrypted email is readable by 10+ entities and stored forever.

                              Web Key Directory (WKD) changes this: automatic encryption using your domain name. No manual keys. No central servers. Just cryptographic certainty.

                              WKD makes encrypted email as simple as HTTPS made web browsing secure.

                              https://www.nicfab.eu/en/posts/wkd2/

                              #WebKeyDirectory #WKD #EmailEncryption #Privacy #InfoSec #Cryptography #OpenPGP

                              Sebastian Schinzelundefined Questo utente è esterno a questo forum
                              Sebastian Schinzelundefined Questo utente è esterno a questo forum
                              Sebastian Schinzel
                              scritto ultima modifica di
                              #39

                              @nicfab @Fr333k Just an observation: that's a long blog post, with a lot of words and with a lot of computer commands and that somewhat contradicts the sentence "WKD makes encrypted email as simple as HTTPS made web browsing secure."

                              Nothing is simple with OpenPGP and email and that's broadly documented in academia and annecdotes. WKD does not change that.

                              If you absolutely positively must use email for sending sensitive info, use S/MIME.

                              Nicola Fabianoundefined 1 Risposta Ultima Risposta
                              • Sebastian Schinzelundefined Sebastian Schinzel

                                @nicfab @Fr333k Just an observation: that's a long blog post, with a lot of words and with a lot of computer commands and that somewhat contradicts the sentence "WKD makes encrypted email as simple as HTTPS made web browsing secure."

                                Nothing is simple with OpenPGP and email and that's broadly documented in academia and annecdotes. WKD does not change that.

                                If you absolutely positively must use email for sending sensitive info, use S/MIME.

                                Nicola Fabianoundefined Questo utente è esterno a questo forum
                                Nicola Fabianoundefined Questo utente è esterno a questo forum
                                Nicola Fabiano
                                scritto ultima modifica di
                                #40

                                @seecurity @Fr333k You’re right that nothing in email crypto is ever “simple” — WKD doesn’t change the complexity of OpenPGP itself. However, it does solve a particular problem that has long blocked adoption: key discovery.

                                That doesn’t contradict the analogy with HTTPS — it’s about lowering friction, not erasing complexity.
                                And yes, S/MIME can be smoother in some contexts, but WKD gives domains a way to make OpenPGP more usable in practice.

                                1 Risposta Ultima Risposta
                                Rispondi
                                • Topic risposta
                                Effettua l'accesso per rispondere
                                • Da Vecchi a Nuovi
                                • Da Nuovi a Vecchi
                                • Più Voti


                                • 1
                                • 2
                                Feed RSS
                                🔐 Every unencrypted email is readable by 10+ entities and stored forever.

                                Gli ultimi otto messaggi ricevuti dalla Federazione
                                • mr brown :unverified: :nona:undefined
                                  mr brown :unverified: :nona:

                                  @quinta io onestamente sono sorpreso: pensavo che fossero genuinamente idioti, farsi pagare è già un passo avanti. imparano: prepariamoci al peggio

                                  per saperne di più

                                • Dret :mastodon:undefined
                                  Dret :mastodon:

                                  @liberotoncello @sandropisano

                                  👍

                                  per saperne di più

                                • :fedora: filippodb ⁂ :cc:undefined
                                  :fedora: filippodb ⁂ :cc:

                                  @vstrappato Disattiva tutte le protezioni Di Brave, creano casino nei sistemi Di pagamento.

                                  per saperne di più

                                • William Lindsey :toad:undefined
                                  William Lindsey :toad:

                                  "Despite what Trump and some in the media want you to believe, this case is not about Epstein and his co-conspirator Ghislaine Maxwell recruiting children and women simply to have sex with Epstein.

                                  Rather, the two were building a massive international sex ring to blackmail people in power. That is why Donald Trump and many of his allies including in the corporate media—are so desperate to move on from this story."

                                  #Epstein #Trump #CoverUp #blackmail #LisaPhillips
                                  /2

                                  per saperne di più

                                • Veeundefined
                                  Vee
                                  This post did not contain any content.
                                  per saperne di più

                                • William Lindsey :toad:undefined
                                  William Lindsey :toad:

                                  "Earlier this week I spoke to Epstein survivor Lisa Phillips—who made it crystal clear that Epstein was the mastermind of a massive sex scandal involving countless powerful men from around the globe. (You can watch my interview of Lisa at end of this article.)"

                                  ~ Dean Obeidallah

                                  #Epstein #Trump #CoverUp #blackmail #LisaPhillips
                                  /1

                                  https://deanobeidallah.substack.com/p/jeffrey-epstein-ran-a-massive-international

                                  per saperne di più

                                • Maronno Winchester :antifa:undefined
                                  Maronno Winchester :antifa:

                                  Tex Willer (@texwiller7.bsky.social)

                                  https://bsky.app/profile/texwiller7.bsky.social/post/3lzvrhhep222q

                                  per saperne di più

                                • Andy Piperundefined
                                  Andy Piper

                                  @jay this feels like an elaborate attempt to get more viewers

                                  per saperne di più
                                Mastodon
                                Powered by NodeBB Contributors
                                Post suggeriti
                                • Em :official_verified:undefined

                                  I know there's a general "cause fatigue" with the current state of the world, and I feel it too.

                                  Seguito Ignorato Pianificato Fissato Bloccato Spostato Senza categoria chatcontrol privacy democracy humanrights masssurveillance stopscanningme eupol ukpol
                                  1
                                  0 Votazioni
                                  1 Post
                                  3 Visualizzazioni
                                  Nessuno ha risposto
                                • Redhotcyberundefined

                                  Chi conosce il signore sulla destra dell'immagine?

                                  Seguito Ignorato Pianificato Fissato Bloccato Spostato Senza categoria redhotcyber storia informatica web hacking privacy
                                  1
                                  1
                                  0 Votazioni
                                  1 Post
                                  6 Visualizzazioni
                                  Nessuno ha risposto
                                • Sheldonundefined

                                  Is anyone else getting a huge number of bot visits from servers in the Fastly network?

                                  Seguito Ignorato Pianificato Fissato Bloccato Spostato Senza categoria fastly infosec ddos sysadmin
                                  1
                                  0 Votazioni
                                  1 Post
                                  3 Visualizzazioni
                                  Nessuno ha risposto
                                • Nicola Fabianoundefined

                                  📊 Major #AI data protection update:@Curia Judgement C-413/23 P: pseudonymized data has "relative" nature - personal for controllers, potentially not for recipients

                                  Seguito Ignorato Pianificato Fissato Bloccato Spostato Senza categoria gdpr aiact privacy biometricdata machinelearning
                                  1
                                  0 Votazioni
                                  1 Post
                                  3 Visualizzazioni
                                  Nessuno ha risposto
                                • Accedi

                                • Accedi o registrati per effettuare la ricerca.
                                • Primo post
                                  Ultimo post