🔐 Every unencrypted email is readable by 10+ entities and stored forever.
-
🔐 Every unencrypted email is readable by 10+ entities and stored forever.
Web Key Directory (WKD) changes this: automatic encryption using your domain name. No manual keys. No central servers. Just cryptographic certainty.
WKD makes encrypted email as simple as HTTPS made web browsing secure.
https://www.nicfab.eu/en/posts/wkd2/
#WebKeyDirectory #WKD #EmailEncryption #Privacy #InfoSec #Cryptography #OpenPGP
-
🔐 Every unencrypted email is readable by 10+ entities and stored forever.
Web Key Directory (WKD) changes this: automatic encryption using your domain name. No manual keys. No central servers. Just cryptographic certainty.
WKD makes encrypted email as simple as HTTPS made web browsing secure.
https://www.nicfab.eu/en/posts/wkd2/
#WebKeyDirectory #WKD #EmailEncryption #Privacy #InfoSec #Cryptography #OpenPGP
@yunohost
@nextcloud (Mail)
@freedomboxfndnAre / will you support this option for encrypted email? (^^^ Previous toot)
#Encryption #Email #WKD #Privacy #Yunohost #Nextcloud #Freedombox #WebKeyDirectory #Cryptography #OpenPGP
-
@yunohost
@nextcloud (Mail)
@freedomboxfndnAre / will you support this option for encrypted email? (^^^ Previous toot)
#Encryption #Email #WKD #Privacy #Yunohost #Nextcloud #Freedombox #WebKeyDirectory #Cryptography #OpenPGP
@Blort @yunohost @nextcloud @freedomboxfndn
Yes, of course! Why not?
I have my WKD -
@Blort @yunohost @nextcloud @freedomboxfndn
Yes, of course! Why not?
I have my WKDFYI That question was primarily aimed at Yunohost / Nextcloud / Freedombox, as I'd love to know if the tools I already use, make this user friendly to setup yet. ;)
Either way, this looks fascinating! While I lack the technical expertise to validate the approach, the promise is extremely appealing, raising the possibility that the most popular, #FOSS social network on the planet (email) could finally be made encrypted for the masses (such as I), doing for email what Let's Encrypt did for web servers.
Coming more from a marketing background myself, my first thought was what it would take to get widespread adoption, which seems to be support from major (FOSS + commercial) email server applications. From a quick skim of your article, it seems adding support shouldn't be onerous...
-
FYI That question was primarily aimed at Yunohost / Nextcloud / Freedombox, as I'd love to know if the tools I already use, make this user friendly to setup yet. ;)
Either way, this looks fascinating! While I lack the technical expertise to validate the approach, the promise is extremely appealing, raising the possibility that the most popular, #FOSS social network on the planet (email) could finally be made encrypted for the masses (such as I), doing for email what Let's Encrypt did for web servers.
Coming more from a marketing background myself, my first thought was what it would take to get widespread adoption, which seems to be support from major (FOSS + commercial) email server applications. From a quick skim of your article, it seems adding support shouldn't be onerous...
@Blort
Sorry for the misunderstanding.
I strongly believe that everyone should communicate exclusively via encrypted email, and I have held this position for many years.
I published several posts on my blog on that topic. -
🔐 Every unencrypted email is readable by 10+ entities and stored forever.
Web Key Directory (WKD) changes this: automatic encryption using your domain name. No manual keys. No central servers. Just cryptographic certainty.
WKD makes encrypted email as simple as HTTPS made web browsing secure.
https://www.nicfab.eu/en/posts/wkd2/
#WebKeyDirectory #WKD #EmailEncryption #Privacy #InfoSec #Cryptography #OpenPGP
@nicfab seeing https://wkd.dp42.dev referenced has made my day!
-
@Blort
Sorry for the misunderstanding.
I strongly believe that everyone should communicate exclusively via encrypted email, and I have held this position for many years.
I published several posts on my blog on that topic.@nicfab I take full credit / blame for any misunderstanding there! I forgot Masto would automatically @ you in any reply, and didn't think about how it would look like I was directing the question at you. My bad!
I'd love to see a wider discussion of this though, as the ramifications could be groundbreaking to private communications.
If there's one thing my professional life has taught me, it's how making things even a tiny bit easier / harder can have huge ramifications on what people actually do (or not).
This seems like it could genuinely make encrypted email easy after decades of adoption being very hard. That gets me very interested in the strengths and limitations of the approach and how it's adoption could be encouraged.
Could it be extended to something like @delta chat?
-
@nicfab seeing https://wkd.dp42.dev referenced has made my day!
@chimbosonic I mentioned your tool in my article. Read it! 😀
Congratulations on your work! Great resource! -
@nicfab I take full credit / blame for any misunderstanding there! I forgot Masto would automatically @ you in any reply, and didn't think about how it would look like I was directing the question at you. My bad!
I'd love to see a wider discussion of this though, as the ramifications could be groundbreaking to private communications.
If there's one thing my professional life has taught me, it's how making things even a tiny bit easier / harder can have huge ramifications on what people actually do (or not).
This seems like it could genuinely make encrypted email easy after decades of adoption being very hard. That gets me very interested in the strengths and limitations of the approach and how it's adoption could be encouraged.
Could it be extended to something like @delta chat?
@Blort @nicfab we know about wkd and some of us have engaged with it in earlier times. Our current trajectory of #chatmail developments is not directly fitting as we are aiming to hide all cryptographic identity information from the transport layer (email servers). Wkd rather reinforces the central role of email servers in managing and controlling a users cryptographic identity. Besides there are error cases (wkd down/erroring), stale keys and other issues that cause UX challenges.
-
🔐 Every unencrypted email is readable by 10+ entities and stored forever.
Web Key Directory (WKD) changes this: automatic encryption using your domain name. No manual keys. No central servers. Just cryptographic certainty.
WKD makes encrypted email as simple as HTTPS made web browsing secure.
https://www.nicfab.eu/en/posts/wkd2/
#WebKeyDirectory #WKD #EmailEncryption #Privacy #InfoSec #Cryptography #OpenPGP
@nicfab I did not know of this, and find it fascinating. I use proton with a custom domain, so I don't benefit from it based on the article. Next project: setting up my wkd server!
Only downside: I make extensive use of catch-all addresses, and I suppose wkd doesn't account for a "default user inbox" if it relies on username hashes like the article explains. But still worth setting up!
-
@Blort @nicfab we know about wkd and some of us have engaged with it in earlier times. Our current trajectory of #chatmail developments is not directly fitting as we are aiming to hide all cryptographic identity information from the transport layer (email servers). Wkd rather reinforces the central role of email servers in managing and controlling a users cryptographic identity. Besides there are error cases (wkd down/erroring), stale keys and other issues that cause UX challenges.
-
@nicfab I did not know of this, and find it fascinating. I use proton with a custom domain, so I don't benefit from it based on the article. Next project: setting up my wkd server!
Only downside: I make extensive use of catch-all addresses, and I suppose wkd doesn't account for a "default user inbox" if it relies on username hashes like the article explains. But still worth setting up!
@PierricD You can set up WKD with your domain name even if the MX records are on Proton. You need a server.
-
@nicfab @Blort we know there is an IETF doc about wkd. Delta is probably one of the most standards based messengers out there https://github.com/chatmail/core/blob/main/standards.md
But that doesn't mean any IETF standard is unconditionally a good idea for resilient decentralized messaging. -
@PierricD You can set up WKD with your domain name even if the MX records are on Proton. You need a server.
-
🔐 Every unencrypted email is readable by 10+ entities and stored forever.
Web Key Directory (WKD) changes this: automatic encryption using your domain name. No manual keys. No central servers. Just cryptographic certainty.
WKD makes encrypted email as simple as HTTPS made web browsing secure.
https://www.nicfab.eu/en/posts/wkd2/
#WebKeyDirectory #WKD #EmailEncryption #Privacy #InfoSec #Cryptography #OpenPGP
@nicfab I appreciate every attempt to make the web more secure by default.
What is your opinion on if I would state: Isn’t encrypted mail also stored forever and readable in the future? As e-mail lacks PFS…
I’m more concerned about that and things like headers being not encrypted and therefore, leaking meta data, than getting my keys to ppl.
If things must change it is probably SMTP that needs a successor with things like double ratchet session keys and key exchange parameters. And while we’re on it, probably some post quantum ability would fit the timeline we are in.
What do you think?
-
🔐 Every unencrypted email is readable by 10+ entities and stored forever.
Web Key Directory (WKD) changes this: automatic encryption using your domain name. No manual keys. No central servers. Just cryptographic certainty.
WKD makes encrypted email as simple as HTTPS made web browsing secure.
https://www.nicfab.eu/en/posts/wkd2/
#WebKeyDirectory #WKD #EmailEncryption #Privacy #InfoSec #Cryptography #OpenPGP
@nicfab @koehntopp Sounds too good. Hope it's not. 😃👍
-
@nicfab @koehntopp Sounds too good. Hope it's not. 😃👍
@micha @koehntopp Why not?
-
🔐 Every unencrypted email is readable by 10+ entities and stored forever.
Web Key Directory (WKD) changes this: automatic encryption using your domain name. No manual keys. No central servers. Just cryptographic certainty.
WKD makes encrypted email as simple as HTTPS made web browsing secure.
https://www.nicfab.eu/en/posts/wkd2/
#WebKeyDirectory #WKD #EmailEncryption #Privacy #InfoSec #Cryptography #OpenPGP
-
@nicfab I appreciate every attempt to make the web more secure by default.
What is your opinion on if I would state: Isn’t encrypted mail also stored forever and readable in the future? As e-mail lacks PFS…
I’m more concerned about that and things like headers being not encrypted and therefore, leaking meta data, than getting my keys to ppl.
If things must change it is probably SMTP that needs a successor with things like double ratchet session keys and key exchange parameters. And while we’re on it, probably some post quantum ability would fit the timeline we are in.
What do you think?
@lennybacon 1/6
Your analysis hits the nail on the head. The fundamental architecture of email predates modern cryptography, and what we do today is essentially retrofitting security onto a protocol from the 1970s. -
@nicfab I appreciate every attempt to make the web more secure by default.
What is your opinion on if I would state: Isn’t encrypted mail also stored forever and readable in the future? As e-mail lacks PFS…
I’m more concerned about that and things like headers being not encrypted and therefore, leaking meta data, than getting my keys to ppl.
If things must change it is probably SMTP that needs a successor with things like double ratchet session keys and key exchange parameters. And while we’re on it, probably some post quantum ability would fit the timeline we are in.
What do you think?
@lennybacon 2/6
The lack of PFS is indeed critical: every encrypted email becomes a time capsule waiting for quantum computers or a key compromise. Unlike Signal or Matrix, which utilize double-ratchet algorithms to ensure both forward and backward secrecy, email encryption remains static — a single key leak compromises entire email histories.
Gli ultimi otto messaggi ricevuti dalla Federazione
Post suggeriti
-
È successo di nuovo, anche Linkedin come Facebook e Instagram utilizzano i dati degli utenti per addestrare i modelli IA senza chiedere il consenso esplicito
Senza categoria2
-
-
🔎 Google Vulnerability that allows to delete pages from Google SearchIn the cybersecurity scenarios we usually encounter, we would hardly take into consideration SEO and Google’s search results.
Senza categoria1
-