this post was submitted on 08 Mar 2025
-10 points (35.3% liked)

Privacy

1301 readers
174 users here now

Protect your privacy in the digital world

Welcome! This is a community for all those who are interested in protecting their privacy.

Rules

PS: Don't be a smartass and try to game the system, we'll know if you're breaking the rules when we see it!

  1. Be nice, civil and no bigotry/prejudice.
  2. No tankies/alt-right fascists. The former can be tolerated but the latter are banned.
  3. Stay on topic.
  4. Don't promote big-tech software.
  5. No reposting of news that was already posted. Even from different sources.
  6. No crypto, blockchain, etc.
  7. No Xitter links. (only allowed when can't fact check any other way, use xcancel)

Related communities:

founded 4 months ago
MODERATORS
 

"email is inherently insecure, email can never be secure, it leaks a LOT of metadata and only the body is encrypted, subject can NOT be encrypted, you can NOT build a secure system on top of email"

top 13 comments
sorted by: hot top controversial new old
[–] fxomt@lemmy.dbzer0.com 8 points 1 day ago (2 children)

Question: why not use a protocol built and strengthened around secure chatting specifically?

Why not SimpleX or signal?

[–] nichtburningturtle@feddit.org 4 points 1 day ago (1 children)

Where is the fun in that? :D

[–] fxomt@lemmy.dbzer0.com 4 points 1 day ago (1 children)

You're right. You know what? Fuck it let's use carrier pigeons with manual GPG encryption, the feds will never think of checking the skies.

Too bad that birds aren't real.

[–] adbenitez@lemmy.ml 3 points 1 day ago (1 children)

it is all about the sassy retro style and base64 MIME body

more seriously: Signal is centralized and based on phone numbers, and as said by Signal themselves: "Privacy is Priceless, but Signal is Expensive" https://signal.org/blog/signal-is-expensive/ while email infra is WAY more economic and decentralized

SimpleX maybe but I it is not powerful/flexible nor as solid/mature as email server infra

[–] fxomt@lemmy.dbzer0.com 3 points 1 day ago (1 children)

I see, thank you. I think delta is audited too so it's pretty solid.

Though, if you advertised delta/arcane directly instead of a meme, people might not have been so angry haha. You're free to make a post about them but please do cite the audit :)

[–] adbenitez@lemmy.ml 3 points 1 day ago* (last edited 1 day ago) (1 children)

I didn't want to advice/promote DeltaChat/ArcaneChat, they are not the only possible way of using email securely, just came here with the meme as a way of leaving out a rant because I have seen a lot of people talking like that and it is by now an urban legend people just repeat like parrots and pointing to articles that basically are misleading. Had a recent discussion about that in the Privacy Guides forum and just came here with the meme to shake the frustration away ;-)

[–] fxomt@lemmy.dbzer0.com 2 points 1 day ago

Yeah i checked that thread, that user that kept bickering seemed like an asshole, sorry. I think delta/arcane is pretty novel and noble.

Standard OpenPGP e-mail encryption protects message contents, but not message headers such as From, To and Subject fields. To protect Subject header Delta Chat and other email clients such as Thunderbird and K-9 Mail replace Subject with “…” or “Encrypted Message” and place real Subject into the encrypted part of an e-mail message

Clearly they didn't even read the audit 🤦‍♂️ Thanks for your good work, btw :D

[–] Fermiverse@gehirneimer.de 3 points 1 day ago (1 children)
[–] scrubbles@poptalk.scrubbles.tech 4 points 1 day ago (1 children)

Yeah this is the guy who has been plugging it. It's not that I don't like it, but I don't like the use of the email protocols being used in that ways it wasn't meant for. Its also yet another standard when we already have a few, keeping people separate

[–] Fermiverse@gehirneimer.de 2 points 1 day ago

fair enough

[–] DragonsInARoom@lemmy.world 2 points 1 day ago (1 children)

Good bait, you could says its a masterbait. What do you recommend we switch to when making accounts?

[–] Draconic_NEO@lemmy.dbzer0.com 1 points 21 hours ago* (last edited 21 hours ago)

Matrix could be a good solution, though that only works if the services actually support it for activation and verification.

Which ultimately is the problem with any alternative to email, they need to be supported by other services to be any useful.