Hacker News new | ask | show | jobs
by AretNCarlsen 5403 days ago
To beat the old drum: Email isn't intended to be secure anyway. Relying on email addresses to maintain privacy and authenticity is like relying on Caller ID to verify callers' identities. (See spoofcard.com.)

Encrypt, encrypt, encrypt. Or, encrypt.

2 comments

Yeah, it's still shocking to me how many fortune 500 companies still don't understand how vulnerable they are to simple hacks like this. I would've thought it would be SOP (standard operating procedure) to encrypt their email years ago.

I guess a normal level of paranoia hasn't quite reached those companies yet huh?

No, email encryption is a godawful mess and impossible for normal humans to use.

And you can't control who sends you email.

You can encrypt your way out of typos and domain-squatting?
Squatters can't use your email if they can't read it.
They could only do traffic analysis.