|
|
|
|
|
by johannes1234321
258 days ago
|
|
> Regarding confidentiality, coincidentally not even 2 weeks ago a friend was telling me about a case of hos company sending an invoice, and being man-in-the-middle'd so the attacker just changed the bank account number and the customer thus paid to the wrong account. That sounds like a quite sophisticated attack. By far most Mail these days should be transport encrypted. The attacker thus must have control (legal or illegal, at least to fake a wrong MX DNS record) over either side and then manipulate the invoice and then need a bank account which can receive the payment, while hiding their traces. Seems quite sophisticated and targeted as an attack. > Nobody uses GPG, sadly. User experience there was never good. Signal/WhatsApp probably are the most userfiendly e2ee systems around: automatic key exchange with ability to verify. (While proprietary clients require trusting those, which is a big ask especially with Whatsapp/meta) |
|