Salta al contenuto
0
  • Home
  • Piero Bosio
  • Blog
  • Mondo
  • Fediverso
  • News
  • Categorie
  • Recenti
  • Popolare
  • Tag
  • Utenti
  • Home
  • Piero Bosio
  • Blog
  • Mondo
  • Fediverso
  • News
  • Categorie
  • Recenti
  • Popolare
  • Tag
  • Utenti
Skin
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Predefinito (Nessuna skin)
  • Nessuna skin
Collassa

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone
  1. Home
  2. Categorie
  3. Senza categoria
  4. 🔐 Every unencrypted email is readable by 10+ entities and stored forever.

🔐 Every unencrypted email is readable by 10+ entities and stored forever.

Pianificato Fissato Bloccato Spostato Senza categoria
webkeydirectorywkdemailencryptionprivacyinfoseccryptographyopenpgp
44 Post 12 Autori 0 Visualizzazioni
  • Da Vecchi a Nuovi
  • Da Nuovi a Vecchi
  • Più Voti
Rispondi
  • Topic risposta
Effettua l'accesso per rispondere
Questa discussione è stata eliminata. Solo gli utenti con diritti di gestione possono vederla.
  • Nicola Fabianoundefined Nicola Fabiano

    @thedarktangent @yawnbox This article is not about email security but about WKD. I have already written about email security and will likely revisit the topic in the near future.

    Jeff Mossundefined Questo utente è esterno a questo forum
    Jeff Mossundefined Questo utente è esterno a questo forum
    Jeff Moss
    scritto ultima modifica di
    #30

    @nicfab @yawnbox I have lived through essentially the same issues with PGP keys in DNS, hashes of SMime keys in DNS, MTA-STS, DANE for SMTP, automatic SMIME using SMILE, etc.

    I hope WKD does better! But I fear that without a solution to local email search it will be a victim of its own success, or you will have to put so much information in the subject line to remind you what is in the encrypted body that some privacy is lost.

    Nicola Fabianoundefined 1 Risposta Ultima Risposta
    • Nicola Fabianoundefined Nicola Fabiano

      @tudobem @PierricD It depends on the provider you chose. You can check Netcup or Contabo, which are more affordable options.

      tudobemundefined Questo utente è esterno a questo forum
      tudobemundefined Questo utente è esterno a questo forum
      tudobem
      scritto ultima modifica di
      #31

      @nicfab @PierricD thank you! would it be okay if I get back to you with questions in case they come up along the way?

      Nicola Fabianoundefined 1 Risposta Ultima Risposta
      • Jeff Mossundefined Jeff Moss

        @nicfab @yawnbox I have lived through essentially the same issues with PGP keys in DNS, hashes of SMime keys in DNS, MTA-STS, DANE for SMTP, automatic SMIME using SMILE, etc.

        I hope WKD does better! But I fear that without a solution to local email search it will be a victim of its own success, or you will have to put so much information in the subject line to remind you what is in the encrypted body that some privacy is lost.

        Nicola Fabianoundefined Questo utente è esterno a questo forum
        Nicola Fabianoundefined Questo utente è esterno a questo forum
        Nicola Fabiano
        scritto ultima modifica di
        #32

        @thedarktangent @yawnbox I share your concern — past attempts (PGP in DNS, DANE, SMILE, etc.) struggled with adoption. WKD isn’t a complete solution, but it’s worth setting up: it removes a key barrier and makes encrypted mail more usable, even if challenges like local search and subject-line leaks remain.

        1 Risposta Ultima Risposta
        • tudobemundefined tudobem

          @nicfab @PierricD thank you! would it be okay if I get back to you with questions in case they come up along the way?

          Nicola Fabianoundefined Questo utente è esterno a questo forum
          Nicola Fabianoundefined Questo utente è esterno a questo forum
          Nicola Fabiano
          scritto ultima modifica di
          #33

          @tudobem @PierricD Of course, feel free to reach out anytime.

          1 Risposta Ultima Risposta
          • Nicola Fabianoundefined Nicola Fabiano

            🔐 Every unencrypted email is readable by 10+ entities and stored forever.

            Web Key Directory (WKD) changes this: automatic encryption using your domain name. No manual keys. No central servers. Just cryptographic certainty.

            WKD makes encrypted email as simple as HTTPS made web browsing secure.

            https://www.nicfab.eu/en/posts/wkd2/

            #WebKeyDirectory #WKD #EmailEncryption #Privacy #InfoSec #Cryptography #OpenPGP

            Grant_Hundefined Questo utente è esterno a questo forum
            Grant_Hundefined Questo utente è esterno a questo forum
            Grant_H
            scritto ultima modifica di
            #34

            @nicfab
            Reading the article, I can't see how this works out in a hybrid situation - where not all your email recipients are using WKD. Am I missing something?
            You mention the strength of email being its own prison - we need something that would encrypt where possible, and fall back to plaintext where not (with warning). HTTPS was not implemented across the board overnight.

            Nicola Fabianoundefined 2 Risposte Ultima Risposta
            • Grant_Hundefined Grant_H

              @nicfab
              Reading the article, I can't see how this works out in a hybrid situation - where not all your email recipients are using WKD. Am I missing something?
              You mention the strength of email being its own prison - we need something that would encrypt where possible, and fall back to plaintext where not (with warning). HTTPS was not implemented across the board overnight.

              Nicola Fabianoundefined Questo utente è esterno a questo forum
              Nicola Fabianoundefined Questo utente è esterno a questo forum
              Nicola Fabiano
              scritto ultima modifica di
              #35

              @grant_h 1/2 You're right — WKD alone doesn't handle the hybrid scenario. It's just key discovery, not the complete solution.
              For opportunistic encryption, you need WKD plus smart clients: Thunderbird, DeltaChat, and others already do this — they check for keys via WKD/Autocrypt, encrypt when possible, and fall back to plaintext with warnings.

              1 Risposta Ultima Risposta
              • Grant_Hundefined Grant_H

                @nicfab
                Reading the article, I can't see how this works out in a hybrid situation - where not all your email recipients are using WKD. Am I missing something?
                You mention the strength of email being its own prison - we need something that would encrypt where possible, and fall back to plaintext where not (with warning). HTTPS was not implemented across the board overnight.

                Nicola Fabianoundefined Questo utente è esterno a questo forum
                Nicola Fabianoundefined Questo utente è esterno a questo forum
                Nicola Fabiano
                scritto ultima modifica di
                #36

                @grant_h 2/2 - Think of it like HTTPS adoption:

                - WKD = certificate infrastructure (like Let's Encrypt)
                - Autocrypt/client logic = protocol negotiation
                - Warnings = mixed content alerts

                So yes, the ecosystem supports "encrypt when possible" — WKD makes finding keys automatic. The clients handle the graceful degradation you're looking for.

                Grant_Hundefined 1 Risposta Ultima Risposta
                • Nicola Fabianoundefined Nicola Fabiano

                  @grant_h 2/2 - Think of it like HTTPS adoption:

                  - WKD = certificate infrastructure (like Let's Encrypt)
                  - Autocrypt/client logic = protocol negotiation
                  - Warnings = mixed content alerts

                  So yes, the ecosystem supports "encrypt when possible" — WKD makes finding keys automatic. The clients handle the graceful degradation you're looking for.

                  Grant_Hundefined Questo utente è esterno a questo forum
                  Grant_Hundefined Questo utente è esterno a questo forum
                  Grant_H
                  scritto ultima modifica di
                  #37

                  @nicfab My use case is a school. Teachers and students. Particularly the counselling staff. It has to be easy and seamless, and resetable by our admins.
                  Unfortunately, the big companies have no incentive to make our email private, and every incentive to make it easy to join. The precise opposite of so many FOSS projects. We will persevere!

                  Nicola Fabianoundefined 1 Risposta Ultima Risposta
                  • Grant_Hundefined Grant_H

                    @nicfab My use case is a school. Teachers and students. Particularly the counselling staff. It has to be easy and seamless, and resetable by our admins.
                    Unfortunately, the big companies have no incentive to make our email private, and every incentive to make it easy to join. The precise opposite of so many FOSS projects. We will persevere!

                    Nicola Fabianoundefined Questo utente è esterno a questo forum
                    Nicola Fabianoundefined Questo utente è esterno a questo forum
                    Nicola Fabiano
                    scritto ultima modifica di
                    #38

                    @grant_h Go ahead!

                    1 Risposta Ultima Risposta
                    • Nicola Fabianoundefined Nicola Fabiano

                      🔐 Every unencrypted email is readable by 10+ entities and stored forever.

                      Web Key Directory (WKD) changes this: automatic encryption using your domain name. No manual keys. No central servers. Just cryptographic certainty.

                      WKD makes encrypted email as simple as HTTPS made web browsing secure.

                      https://www.nicfab.eu/en/posts/wkd2/

                      #WebKeyDirectory #WKD #EmailEncryption #Privacy #InfoSec #Cryptography #OpenPGP

                      Sebastian Schinzelundefined Questo utente è esterno a questo forum
                      Sebastian Schinzelundefined Questo utente è esterno a questo forum
                      Sebastian Schinzel
                      scritto ultima modifica di
                      #39

                      @nicfab @Fr333k Just an observation: that's a long blog post, with a lot of words and with a lot of computer commands and that somewhat contradicts the sentence "WKD makes encrypted email as simple as HTTPS made web browsing secure."

                      Nothing is simple with OpenPGP and email and that's broadly documented in academia and annecdotes. WKD does not change that.

                      If you absolutely positively must use email for sending sensitive info, use S/MIME.

                      Nicola Fabianoundefined 1 Risposta Ultima Risposta
                      • Sebastian Schinzelundefined Sebastian Schinzel

                        @nicfab @Fr333k Just an observation: that's a long blog post, with a lot of words and with a lot of computer commands and that somewhat contradicts the sentence "WKD makes encrypted email as simple as HTTPS made web browsing secure."

                        Nothing is simple with OpenPGP and email and that's broadly documented in academia and annecdotes. WKD does not change that.

                        If you absolutely positively must use email for sending sensitive info, use S/MIME.

                        Nicola Fabianoundefined Questo utente è esterno a questo forum
                        Nicola Fabianoundefined Questo utente è esterno a questo forum
                        Nicola Fabiano
                        scritto ultima modifica di
                        #40

                        @seecurity @Fr333k You’re right that nothing in email crypto is ever “simple” — WKD doesn’t change the complexity of OpenPGP itself. However, it does solve a particular problem that has long blocked adoption: key discovery.

                        That doesn’t contradict the analogy with HTTPS — it’s about lowering friction, not erasing complexity.
                        And yes, S/MIME can be smoother in some contexts, but WKD gives domains a way to make OpenPGP more usable in practice.

                        Sebastian Schinzelundefined 1 Risposta Ultima Risposta
                        • Nicola Fabianoundefined Nicola Fabiano

                          @seecurity @Fr333k You’re right that nothing in email crypto is ever “simple” — WKD doesn’t change the complexity of OpenPGP itself. However, it does solve a particular problem that has long blocked adoption: key discovery.

                          That doesn’t contradict the analogy with HTTPS — it’s about lowering friction, not erasing complexity.
                          And yes, S/MIME can be smoother in some contexts, but WKD gives domains a way to make OpenPGP more usable in practice.

                          Sebastian Schinzelundefined Questo utente è esterno a questo forum
                          Sebastian Schinzelundefined Questo utente è esterno a questo forum
                          Sebastian Schinzel
                          scritto ultima modifica di
                          #41

                          @nicfab @Fr333k Email crypto is extremely complex and because of this, has plenty of attack surface. We published close to 10 papers in the last seven years attacking email and email encryption with OpenPGP and S/MIME.

                          I am at the point where I find recommending email encryption to be actively harmful. Metadata leaks all over the place, crypto from the '90s, plaintext fallbacks everywhere, user hate it, in particular the gnupg devs are very toxic, mail client developers lack time and (too often) expertise to implement it properly.

                          Just use Signal. If you got budget, build an app on top of Signal. Heck, just use WhatsApp. Just don't even try to send sensitive information with email encryption.

                          Nicola Fabianoundefined 1 Risposta Ultima Risposta
                          • Sebastian Schinzelundefined Sebastian Schinzel

                            @nicfab @Fr333k Email crypto is extremely complex and because of this, has plenty of attack surface. We published close to 10 papers in the last seven years attacking email and email encryption with OpenPGP and S/MIME.

                            I am at the point where I find recommending email encryption to be actively harmful. Metadata leaks all over the place, crypto from the '90s, plaintext fallbacks everywhere, user hate it, in particular the gnupg devs are very toxic, mail client developers lack time and (too often) expertise to implement it properly.

                            Just use Signal. If you got budget, build an app on top of Signal. Heck, just use WhatsApp. Just don't even try to send sensitive information with email encryption.

                            Nicola Fabianoundefined Questo utente è esterno a questo forum
                            Nicola Fabianoundefined Questo utente è esterno a questo forum
                            Nicola Fabiano
                            scritto ultima modifica di
                            #42

                            @seecurity @Fr333k

                            It’s true: email crypto has flaws and decades of technical debt. But saying “just use Signal or WhatsApp” trades one problem for another — centralized silos controlled by single entities, which is even worse for long-term resilience, governance, and privacy.

                            WKD won’t magically fix email, but it removes real barriers and raises the baseline. Abandoning open, federated protocols entirely in favor of walled gardens is not a sustainable path.

                            1 Risposta Ultima Risposta
                            • Nicola Fabianoundefined Nicola Fabiano

                              🔐 Every unencrypted email is readable by 10+ entities and stored forever.

                              Web Key Directory (WKD) changes this: automatic encryption using your domain name. No manual keys. No central servers. Just cryptographic certainty.

                              WKD makes encrypted email as simple as HTTPS made web browsing secure.

                              https://www.nicfab.eu/en/posts/wkd2/

                              #WebKeyDirectory #WKD #EmailEncryption #Privacy #InfoSec #Cryptography #OpenPGP

                              ⁉️undefined Questo utente è esterno a questo forum
                              ⁉️undefined Questo utente è esterno a questo forum
                              ⁉️
                              scritto ultima modifica di
                              #43

                              @nicfab I already have a webserver for my website using my own domain name, do I need a second one or is it possible to combine this somehow?

                              Really interesting, first I hear of it. Thanks for sharing it!

                              Nicola Fabianoundefined 1 Risposta Ultima Risposta
                              • ⁉️undefined ⁉️

                                @nicfab I already have a webserver for my website using my own domain name, do I need a second one or is it possible to combine this somehow?

                                Really interesting, first I hear of it. Thanks for sharing it!

                                Nicola Fabianoundefined Questo utente è esterno a questo forum
                                Nicola Fabianoundefined Questo utente è esterno a questo forum
                                Nicola Fabiano
                                scritto ultima modifica di
                                #44

                                @chiefbongo WKD is for a single domain name only. They cannot be combined, but you can have multiple WKD configurations for numerous domain names on the server.

                                1 Risposta Ultima Risposta
                                Rispondi
                                • Topic risposta
                                Effettua l'accesso per rispondere
                                • Da Vecchi a Nuovi
                                • Da Nuovi a Vecchi
                                • Più Voti


                                • 1
                                • 2
                                • 3
                                Feed RSS
                                🔐 Every unencrypted email is readable by 10+ entities and stored forever.

                                Gli ultimi otto messaggi ricevuti dalla Federazione
                                • Gert :debian: :gnu: :linux:undefined
                                  Gert :debian: :gnu: :linux:

                                  #sumudflotilla #GazaFlotilla #gazasolidarity
                                  https://www.aljazeera.com/opinions/2025/9/28/amid-the-genocide-in-gaza-the-italian-people-made-us-smile

                                  per saperne di più

                                • Elena Brescacinundefined
                                  Elena Brescacin

                                  @delawen @Em0nM4stodon @_elena @letsenvision Btw, about Meta Ray-Ban, I have met a friend who bought them and said they detected an obstacle to the right, when it was to the left. I honestly have many reasons not to use Meta, but I defend camera-equipped glasses as an aid, because I'd never like to be treated with suspicion just for my glasses. I already have enough stigma around.

                                  per saperne di più

                                • Mario Seminerio :mastodon:undefined
                                  Mario Seminerio :mastodon:

                                  Alcuni di voi mi scrivono chiedendo esempi del mio "blocco per manifesta stupidità" su X (o altrove, se necessario). Eccone uno: il beota in questione era anche mio follower. Quindi stupidità in purezza (o al quadrato), direi. Per tabella di equivalenza direi quindi imbecillità.

                                  per saperne di più

                                • Elena Brescacinundefined
                                  Elena Brescacin

                                  @delawen @Em0nM4stodon @_elena @letsenvision No save/share feature. Just description. The old version had actually the ability to recognize people, but NOT from Internet. To identify John Doe, he had to stand in front of you, let you take pics from different angles, then you could record his name. I personally have never used that function, because where it could be useful to recognise people (conferences) it's impossible to have it work in practice.

                                  per saperne di più

                                • Dave Winer ☕️undefined
                                  Dave Winer ☕️

                                  @stephtara @pfefferle

                                  an example: <a href="http://scripting.com">this</a> is a link. if it displayed as a link it would support linking in this context.

                                  if you type that text into any of the systems you mention you won't see a link.

                                  per saperne di più

                                • Paolo Amorosoundefined
                                  Paolo Amoroso

                                  @psychotimmy We long lost that innoncence.

                                  per saperne di più

                                • Snow  :gnu: :tux: :debian:undefined
                                  Snow :gnu: :tux: :debian:

                                  @glitch Ho studiato.😉

                                  https://www.digitalocean.com/community/tutorials/how-fail2ban-works-to-protect-services-on-a-linux-server

                                  per saperne di più

                                • quinta - Stefano Quintarelliundefined
                                  quinta - Stefano Quintarelli

                                  Trump (aka “Donnie Trumpeone”) says Microsoft should fire its global affairs president Lisa Monaco | Reuters https://blog.quintarelli.it/2025/09/trump-says-microsoft-should-fire-its-global-affairs-president-lisa-monaco-reuters/

                                  per saperne di più
                                Mastodon
                                Powered by NodeBB Contributors
                                Post suggeriti
                                • AV :tux: :linuxmint:undefined

                                  https://ppc.land/microsoft-cant-protect-french-data-from-us-government-access/#microsoft #MicrosoftAzure #privacy

                                  Seguito Ignorato Pianificato Fissato Bloccato Spostato Senza categoria microsoft microsoftazure privacy
                                  1
                                  0 Votazioni
                                  1 Post
                                  0 Visualizzazioni
                                  Nessuno ha risposto
                                • Redhotcyberundefined

                                  Chi conosce il signore sulla destra dell'immagine?

                                  Seguito Ignorato Pianificato Fissato Bloccato Spostato Senza categoria redhotcyber storia informatica web hacking privacy
                                  1
                                  1
                                  0 Votazioni
                                  1 Post
                                  6 Visualizzazioni
                                  Nessuno ha risposto
                                • Glyn Moodyundefined

                                  Swiss government looks to undercut #privacy tech, stoking fears of mass surveillance - https://therecord.media/switzerland-digital-privacy-law-proton-privacy-surveillance this would be bad... #switzerland

                                  Seguito Ignorato Pianificato Fissato Bloccato Spostato Senza categoria privacy switzerland
                                  1
                                  0 Votazioni
                                  1 Post
                                  1 Visualizzazioni
                                  Nessuno ha risposto
                                • The New Paranoiac :fedora:undefined

                                  Google said the collected data was "nonpersonal, pseudonymous, and stored in segregated, secured, and encrypted locations."Over time, so much “nonpersonal” data can be compiled to create a unique profile

                                  Seguito Ignorato Pianificato Fissato Bloccato Spostato Senza categoria meta privacy security alphabet google bigtech
                                  1
                                  0 Votazioni
                                  1 Post
                                  2 Visualizzazioni
                                  Nessuno ha risposto
                                • Accedi

                                • Accedi o registrati per effettuare la ricerca.
                                • Primo post
                                  Ultimo post