Skip to content
0
  • Home
  • Piero Bosio
  • Blog
  • World
  • Fediverso
  • News
  • Categories
  • Old Web Site
  • Recent
  • Popular
  • Tags
  • Users
  • Home
  • Piero Bosio
  • Blog
  • World
  • Fediverso
  • News
  • Categories
  • Old Web Site
  • Recent
  • Popular
  • Tags
  • Users
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone
seecurity@infosec.exchangeundefined

Sebastian Schinzel

@seecurity@infosec.exchange
About
Posts
2
Topics
0
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • 🔐 Every unencrypted email is readable by 10+ entities and stored forever.
    seecurity@infosec.exchangeundefined seecurity@infosec.exchange

    @nicfab @Fr333k Email crypto is extremely complex and because of this, has plenty of attack surface. We published close to 10 papers in the last seven years attacking email and email encryption with OpenPGP and S/MIME.

    I am at the point where I find recommending email encryption to be actively harmful. Metadata leaks all over the place, crypto from the '90s, plaintext fallbacks everywhere, user hate it, in particular the gnupg devs are very toxic, mail client developers lack time and (too often) expertise to implement it properly.

    Just use Signal. If you got budget, build an app on top of Signal. Heck, just use WhatsApp. Just don't even try to send sensitive information with email encryption.

    Uncategorized webkeydirectory wkd emailencryption privacy infosec cryptography openpgp

  • 🔐 Every unencrypted email is readable by 10+ entities and stored forever.
    seecurity@infosec.exchangeundefined seecurity@infosec.exchange

    @nicfab @Fr333k Just an observation: that's a long blog post, with a lot of words and with a lot of computer commands and that somewhat contradicts the sentence "WKD makes encrypted email as simple as HTTPS made web browsing secure."

    Nothing is simple with OpenPGP and email and that's broadly documented in academia and annecdotes. WKD does not change that.

    If you absolutely positively must use email for sending sensitive info, use S/MIME.

    Uncategorized webkeydirectory wkd emailencryption privacy infosec cryptography openpgp
  • 1 / 1
  • Login

  • Login or register to search.
  • First post
    Last post