N
NatiStream
Transcript
Hiển thị

The Overthinking of Private Email

The speaker argues that people overthink private email, noting that email is inherently insecure and that worrying about Swiss vs German privacy laws is excessive. They emphasize that even with encryption, email providers can technically read emails before encryption, and users must trust them. The speaker criticizes misleading explanations from Proton and Skiff about encryption, and praises Cock.li for being honest about its lack of trustworthiness. They conclude that for most users, the goal is simply to get off Google, not to achieve perfect privacy.

Diễn giả cho rằng mọi người suy nghĩ quá mức về email cá nhân, lưu ý rằng email vốn không an toàn và việc lo lắng về luật riêng tư của Thụy Sĩ so với Đức là thái quá. Họ nhấn mạnh rằng ngay cả với mã hóa, các nhà cung cấp email về mặt kỹ thuật có thể đọc email trước khi mã hóa và người dùng phải tin tưởng họ. Diễn giả chỉ trích những giải thích gây hiểu lầm từ Proton và Skiff về mã hóa, và khen ngợi Cock.li vì đã trung thực về việc không đáng tin cậy. Họ kết luận rằng đối với hầu hết người dùng, mục tiêu chỉ đơn giản là thoát khỏi Google, chứ không phải đạt được sự riêng tư hoàn hảo.

you are overthinking private email there is no such thing where are you right now by default is that even a real YouTube channel yeah you've gone completely too deep look I understand dude I need to get off Gmail and email is a core component of both my online and in-person identity so I just need to pick the best thing that makes sense get the best service with the best features

but if you're comparing Swiss vs German privacy laws as if any of that fundamentally matters you have gone too far if you have a personal Libra booted open BSD email server in an unregistered nuclear bunker with a crypto domain connected to Tor and blurred out on Google Maps the other half of your email still went across some ISP Network and it's just sitting on someone else's

email server I'm not saying privacy isn't important and just give up get your email off Google servers but you also can't worry about how protonmail would treat you as if you were a cartel leader or terrorist because if you are you shouldn't be using an inherently insecure protocol like email and all also you should stop doing crimes you can't trust any of these companies no

matter what level of zero trust encryption open source clients Swiss privacy laws they have any of these companies can technically in a theoretical sense serve your IP a malicious login page the next time you log in that just steals your credentials in 2fa so they get full access to your account there are of course legal and corporate safeguards against wiretapping

like this I'm sure this would destroy any company that actually did it but the fact is if you see a little lock icon next to my cool Ultra encryptedemail.com you'll enter your credentials into any page they serve you so at the very least by choosing one of these Services you're trusting them and their employees not to hijack your account via a malicious page on their own domain and obviously all

these Services could just read your email as it's coming in before they encrypt it on their servers if they wanted to I imagine many of you know this because this is your 11th video you're watching about encrypted emails services but your email provider receives your regular ass unencrypted emails then they perform whatever zero access hot Switzerland encryption before

they write it to their database both proton and Skip have Pages where they're upfront about this but they're usually not shouting from the rooftops like hey we can read all your email in particular this proton blog post is excellent someone using a Gmail account sends an email to a protonmail account when it arrives at protonmail our servers can read that email this isn't some secret

this is just how unencrypted email works but it's important for proton to make sure their customer understands how it works the skiff white paper is pretty upfront about this too you've got unencrypted mail going to the skiff encryption service in a little box it's like it's saying hey we get all your unencrypted stuff and then our encryption service encrypts it before we

store it usually if anything providers will have like one little sentence about this despite it relating to virtually all email they will ever process proton actually has another really bad encryption explained page that I don't like it says unless you use pgp okay proton cool no one uses pgp just delete the second bullet point too because no one uses pgp the email message is

encrypted in transit using TLS and stored on our servers using zero access encryption it is not end-to-end encrypted however it might be accessible to the sender's email service this kind of explanation does not help average users understand encryption it's basically implying that only the far end service could possibly see the email contents yeah it's TLS encrypted in Transit to where to the

protonmail server where it is decrypted and then zero access encrypted before being stored this one basic thing is so important because it's the primary reason that you have to trust your email provider no matter if their code is open source no matter if they've been audited in the past you are trusting that the code running on their email servers at this instant is not copying

your emails and I almost got really mad at proton for this kind of explanation until I found the blog post where they actually give by far the best explanation of any company for a more typical example here's two to notice crappy explanation we never store unencrypted emails on our server however the non-encrypted emails are not protected with end-to-end encryption but

are only encrypted once they reach our servers like yeah I get the sense that unencrypted email is unsafe but if I'm a normal person I really only have a vague idea of what this literally means I don't know if I was running an email service for paranoid weirdos I would want to make it extremely clear how a message is encrypted as it traverses each component and who gets to decrypt

it if you want the most transparent and most upfront email service it's cock.lee how can I trust you can't it is 100 possible for me to read all your email any encryption implementation would still technically allow me to read email too then it tells you to use your own pgp encryption because why would you trust the code running on your email provider servers to be clear you

definitely shouldn't use cock.lee but I appreciate that they tell you honestly that they can't be trusted rather than throwing around words like encryption and open source a lot of these Services have detailed information about how end-to-end encrypted emails within their ecosystem works like I'm sure proton to proton skiff to skiff and two denoda to two denoted email messages are the most

Quantum resistant nuclear bomb proof Edward Snow Odin approved encrypted messages that you can send on the internet but I've never investigated their security because of course it's entirely useless if you have a two to NoDa account you will never send another email to another to anoda account and if you're like aha but me and my weird friend actually do have the same

encrypted email provider and we're gonna send each other end-to-end encrypted sensitive information even then why are you trusting a cloud-hosted third-party Webmail service to send Ultra secure messages rather than a purpose-built secure messenger that wouldn't even leave the encrypted messages on someone else's server like I understand the contents of the email message are

encrypted and decrypted client-side with end-to-end encryption so it is impossible for the service provider to read the message but they still have the metadata in the case of proton they might still have the subject and send and receive email address like this is a nice benefit don't get me wrong but if you need to hide your Communications with someone depending on the service it

still only goes so far no matter how many times they say end to end encryption I understand hating the state of online privacy I understand wanting the best hottest most modern trustless open source whiz-bang encrypted email but you can't pretend you're choosing your web-based email provider like your Communications threat model includes the United States government it's like doing

15 hours of research on the best waterproof open source t-shirt to keep you dry in a rainstorm if you are an activist political dissident journalist whistleblower criminal stopped doing crime persecuted minority live under a repressive regime or otherwise your life or Freedom depend on private email you need to stop using email like I don't know maybe check out Breyer or Matrix

apparently they're good enough that the Indian Government tried to ban them alright for everyone else we understand that all Webmail is just a CIA Honeypot all of our emails are sitting on NSA and Australian intelligence servers and getting analyzed with Quantum Dark Matter AI algorithms and the primary evil that we're actually getting away from here is Google right okay so that

1 / 3