this post was submitted on 24 Feb 2024
57 points (92.5% liked)

Fediverse

27828 readers
276 users here now

A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!

Rules

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration), Search Lemmy

founded 1 year ago
MODERATORS
 

i think it might in theory

you are viewing a single comment's thread
view the rest of the comments
[–] scytale@lemm.ee 3 points 6 months ago (1 children)

Well for one, email is inherently insecure, so not sure if the fediverse can learn from that. It’s already not private.

[–] helenslunch@feddit.nl -1 points 6 months ago (1 children)

It's not inherently insecure. There are secure email services but all parties have to be using it.

[–] scytale@lemm.ee 1 points 6 months ago (1 children)

Exactly, that was my point. Email as it is, is insecure, because you can’t encrypt it and make it work universally unless everyone else does.

[–] helenslunch@feddit.nl -1 points 6 months ago (1 children)

Exactly, that was my point. That means it is not inherently insecure.

[–] scytale@lemm.ee 2 points 6 months ago* (last edited 6 months ago) (1 children)

English isn’t my first language so I might be using “inherently” incorrectly, but I thought it means:

in a way that exists as a natural or basic part of something

So in its basic and natural form, email is not secure. It wasn’t designed as such. Full E2E encryption was only implemented recently by certain providers within their own domains, and won’t work across the board unless all of them cooperate, which won’t happen.

[–] helenslunch@feddit.nl 0 points 6 months ago

"Inherently" means essentially "no matter how you do it". If you use an encrypted email provider to send a message to another user on another encrypted email provider, it's perfectly secure. Ergo, it's not "inherent".

Full E2E encryption was only implemented recently by certain providers within their own domains

It definitely works across domains. All you have to do is point your domain at your preferred secure email provider.

and won’t work across the board

It doesn't need to.