|
|
|
|
|
by dfabulich
2010 days ago
|
|
Signal isn't just more convenient; it's also more secure than your PGP encrypted emails. https://latacora.micro.blog/2020/02/19/stop-using-encrypted.... * The encrypted emails you send will transmit the headers in plaintext, including the sender, the recipient, and the subject line (which is message content!) * Anyone who replies to your email unencrypted (which is the default way to reply, because email is insecure by default) will leak not just their own message but your encrypted message as well * Every archived message will eventually leak PGP offers you more control over the infrastructure, which might be valuable to you, but that control comes at a cost of reduced security. That's not an appropriate tradeoff for anyone who actually needs to send a secure message. SHA-1 is just the cherry on top. |
|
since when does Signal support emails? Sorry but a chat application is no replacement for async messaging.
> * Anyone who replies to your email unencrypted (which is the default way to reply, because email is insecure by default) will leak not just their own message but your encrypted message as well
This is major bullshit as they would have to know how to setup encryption to be able to decrypt your message in the first place, and all email clients I know will default to making the reply encrypted if the first message was encrypted in the first place.
> Every archived message will eventually leak
Even if that were remotely true, and it's not, the point is that you are able to TRANSMIT it over email in a safe way regardless of which provider you use. Archiving is besides the point.