โฒ 56 โผ Thunderbird Shares New Details on Upcoming Pro Features (Thundermail's servers to be located in Germany! ๐ฉ๐ช) (www.omgubuntu.co.uk) submitted 1 year ago by cm0002@piefed.world to c/privacy@programming.dev 21 comments fedilink hide all child comments
[โ] RvTV95XBeo@sh.itjust.works 10 points 1 year ago (6 children) Who would be able to access my emails at rest? If the answer isn't abso-fucking-lutely no one, I'm not interested. permalink fedilink source hideshow 6 child comments replies: [โ] lena@gregtech.eu 3 points 1 year ago (5 children) How would that work? Their mail server still has to receive emails on your behalf. Unless you mean whether they plan to sell data, which I agree they should absolutely not. permalink fedilink source parent hideshow 5 child comments replies: [โ] RvTV95XBeo@sh.itjust.works 1 point 1 year ago In transit, it's impossible to get them all, though it should support PGP to anyone else that has it. At rest, it should all be locked down so only I can access, they may have to store some messages temporarily until I connect to provide the encryption, but everything else better be completely inaccessible. permalink fedilink source parent [โ] cooligula@sh.itjust.works 1 point 1 year ago (3 children) Emails could be end to end encrypted, so the mail server wouldnt be able to see the emails. Basicslly PGP but out-of-the-box permalink fedilink source parent hideshow 3 child comments replies: [โ] lena@gregtech.eu 3 points 1 year ago (2 children) The problem is that basically no one uses PGP. Adoption would be hard permalink fedilink source parent hideshow 2 child comments replies: [โ] cooligula@sh.itjust.works 1 point 1 year ago (1 child) But there are workarounds like the one Infomaniak uses (I believe Proton does it too). When sending an encrypted email to a non encrypted user, a link is sent instead of the contents of the email instead. In any case, encryption at rest with user provided keys and things like that are always an option. permalink fedilink source parent hideshow 1 child comment replies: [โ] lena@gregtech.eu 1 point 1 year ago If the encryption at rest is done by the server, that defeats the point. Also, how does the user receiving an encrypted email access it? Do they have to enter a password? How is the password transmitted to them? permalink fedilink source parent
[โ] lena@gregtech.eu 3 points 1 year ago (5 children) How would that work? Their mail server still has to receive emails on your behalf. Unless you mean whether they plan to sell data, which I agree they should absolutely not. permalink fedilink source parent hideshow 5 child comments replies: [โ] RvTV95XBeo@sh.itjust.works 1 point 1 year ago In transit, it's impossible to get them all, though it should support PGP to anyone else that has it. At rest, it should all be locked down so only I can access, they may have to store some messages temporarily until I connect to provide the encryption, but everything else better be completely inaccessible. permalink fedilink source parent [โ] cooligula@sh.itjust.works 1 point 1 year ago (3 children) Emails could be end to end encrypted, so the mail server wouldnt be able to see the emails. Basicslly PGP but out-of-the-box permalink fedilink source parent hideshow 3 child comments replies: [โ] lena@gregtech.eu 3 points 1 year ago (2 children) The problem is that basically no one uses PGP. Adoption would be hard permalink fedilink source parent hideshow 2 child comments replies: [โ] cooligula@sh.itjust.works 1 point 1 year ago (1 child) But there are workarounds like the one Infomaniak uses (I believe Proton does it too). When sending an encrypted email to a non encrypted user, a link is sent instead of the contents of the email instead. In any case, encryption at rest with user provided keys and things like that are always an option. permalink fedilink source parent hideshow 1 child comment replies: [โ] lena@gregtech.eu 1 point 1 year ago If the encryption at rest is done by the server, that defeats the point. Also, how does the user receiving an encrypted email access it? Do they have to enter a password? How is the password transmitted to them? permalink fedilink source parent
[โ] RvTV95XBeo@sh.itjust.works 1 point 1 year ago In transit, it's impossible to get them all, though it should support PGP to anyone else that has it. At rest, it should all be locked down so only I can access, they may have to store some messages temporarily until I connect to provide the encryption, but everything else better be completely inaccessible. permalink fedilink source parent
[โ] cooligula@sh.itjust.works 1 point 1 year ago (3 children) Emails could be end to end encrypted, so the mail server wouldnt be able to see the emails. Basicslly PGP but out-of-the-box permalink fedilink source parent hideshow 3 child comments replies: [โ] lena@gregtech.eu 3 points 1 year ago (2 children) The problem is that basically no one uses PGP. Adoption would be hard permalink fedilink source parent hideshow 2 child comments replies: [โ] cooligula@sh.itjust.works 1 point 1 year ago (1 child) But there are workarounds like the one Infomaniak uses (I believe Proton does it too). When sending an encrypted email to a non encrypted user, a link is sent instead of the contents of the email instead. In any case, encryption at rest with user provided keys and things like that are always an option. permalink fedilink source parent hideshow 1 child comment replies: [โ] lena@gregtech.eu 1 point 1 year ago If the encryption at rest is done by the server, that defeats the point. Also, how does the user receiving an encrypted email access it? Do they have to enter a password? How is the password transmitted to them? permalink fedilink source parent
[โ] lena@gregtech.eu 3 points 1 year ago (2 children) The problem is that basically no one uses PGP. Adoption would be hard permalink fedilink source parent hideshow 2 child comments replies: [โ] cooligula@sh.itjust.works 1 point 1 year ago (1 child) But there are workarounds like the one Infomaniak uses (I believe Proton does it too). When sending an encrypted email to a non encrypted user, a link is sent instead of the contents of the email instead. In any case, encryption at rest with user provided keys and things like that are always an option. permalink fedilink source parent hideshow 1 child comment replies: [โ] lena@gregtech.eu 1 point 1 year ago If the encryption at rest is done by the server, that defeats the point. Also, how does the user receiving an encrypted email access it? Do they have to enter a password? How is the password transmitted to them? permalink fedilink source parent
[โ] cooligula@sh.itjust.works 1 point 1 year ago (1 child) But there are workarounds like the one Infomaniak uses (I believe Proton does it too). When sending an encrypted email to a non encrypted user, a link is sent instead of the contents of the email instead. In any case, encryption at rest with user provided keys and things like that are always an option. permalink fedilink source parent hideshow 1 child comment replies: [โ] lena@gregtech.eu 1 point 1 year ago If the encryption at rest is done by the server, that defeats the point. Also, how does the user receiving an encrypted email access it? Do they have to enter a password? How is the password transmitted to them? permalink fedilink source parent
[โ] lena@gregtech.eu 1 point 1 year ago If the encryption at rest is done by the server, that defeats the point. Also, how does the user receiving an encrypted email access it? Do they have to enter a password? How is the password transmitted to them? permalink fedilink source parent