Author Topic: Encrypted email  (Read 5234 times)

someone

  • Sr. Member
  • ****
  • Posts: 415
Encrypted email
« on: November 20, 2015, 01:31:12 am »
With all the talk about encrypted email used by the Paris terrorists I was wondering if Aquamail has an encryption feature. Does it? Or is it an external app?

StR

  • Hero Member
  • *****
  • Posts: 1558
Re: Encrypted email
« Reply #1 on: November 20, 2015, 01:55:14 am »
It does not have this capability.

Kostya Vasilyev

  • Hero Member
  • *****
  • Posts: 12740
Re: Encrypted email
« Reply #2 on: November 20, 2015, 02:30:23 pm »
@Paris Geek

You almost made it sound like the lack of encryption in AquaMail is some sort of well-thought out stance "for the greater good of mankind"...

Creating debug logs for diagnostics: https://www.aqua-mail.com/troubleshooting/

The official FAQ: https://www.aqua-mail.com/faq/

Лог-файлы для диагностики: https://www.aqua-mail.com/ru/troubleshooting/

Вопросы и ответы: https://www.aqua-mail.com/ru/faq/

someone

  • Sr. Member
  • ****
  • Posts: 415
Re: Encrypted email
« Reply #3 on: November 20, 2015, 04:31:24 pm »
I was just curious about how it worked and whether it was something built into the email app or something added to it.

It's probably too much trouble for everyday use unless one had a special reason.
.....
[Notice not included in the above original message: The U.S. National Security Agency neither confirms nor denies that it intercepted this message.]

Kostya Vasilyev

  • Hero Member
  • *****
  • Posts: 12740
Re: Encrypted email
« Reply #4 on: November 20, 2015, 05:11:13 pm »
At last some part (MIME parsing, and in general, dealing with the different structure of such messages) has to be in the email app itself.

Actual encryption can be elsewhere (cf. K9 Mail and its encryption plugin), but I think this part is the smaller, easier one.

---

And then there is this: how many people asking about encryption in AquaMail would be saying "but it's not open source, how can I trust it" if this feature was present.
Creating debug logs for diagnostics: https://www.aqua-mail.com/troubleshooting/

The official FAQ: https://www.aqua-mail.com/faq/

Лог-файлы для диагностики: https://www.aqua-mail.com/ru/troubleshooting/

Вопросы и ответы: https://www.aqua-mail.com/ru/faq/

ZenoSloim

  • Newbie
  • *
  • Posts: 11
    • Zeno Sloim - Security & Politics - Analysis and Overview
Re: Encrypted email
« Reply #5 on: November 20, 2015, 08:47:10 pm »
At last some part (MIME parsing, and in general, dealing with the different structure of such messages) has to be in the email app itself.

Actual encryption can be elsewhere (cf. K9 Mail and its encryption plugin), but I think this part is the smaller, easier one.

---

And then there is this: how many people asking about encryption in AquaMail would be saying "but it's not open source, how can I trust it" if this feature was present.

The Crypto Plugin in MailDroid uses standard pgp keys generated for ex. by Thialfihar APG Android Privacy Guard.
I personally have nothing to hide, I just installed it only for learning and because is used where I work.

But regarding other requests, I have one very...very old...I 'm frankly ashame to beg for it again... :)
When...if... will be possible to save individual mails as EML... :) ?

Kostya Vasilyev

  • Hero Member
  • *****
  • Posts: 12740
Re: Encrypted email
« Reply #6 on: November 20, 2015, 09:59:29 pm »
Re: When...if... will be possible to save individual mails as EML

An easy one -- "no" :)

This app doesn't download messages in original MIME format, and doesn't store them that way (and can't open .eml files either, rather it decodes .eml attaches transparently to the user).
Creating debug logs for diagnostics: https://www.aqua-mail.com/troubleshooting/

The official FAQ: https://www.aqua-mail.com/faq/

Лог-файлы для диагностики: https://www.aqua-mail.com/ru/troubleshooting/

Вопросы и ответы: https://www.aqua-mail.com/ru/faq/

StR

  • Hero Member
  • *****
  • Posts: 1558
Re: Encrypted email
« Reply #7 on: November 21, 2015, 01:00:29 am »
@Someone:
Encrypted mail could be useful in a bunch of different (legitimate) situations (and some of those are not even that special):
1. Business secrets (communication that contains proprietary information). The type of information can range from some know-how to some business decisions (e.g. trading, market expansion, etc.).
As you probably know, industrial spying could be more fierce than state spying.
2. State, military,  secrets.
3. Variety of client-service_provider communications where privacy is at stake, e.g. client-attorney, patient-doctor....
4. Personal communication (between family members or with romantic partners).
5. Communication of private information (e.g. Social Security Number, credit card numbers, etc.)
6. Other, semi-private business communication.

There are also many other situations, some of which are somewhat extreme, and as such is not related to a "mass market" use case (such as communication of whistle-blowers with journalists, communication of political opposition, etc.).
Of course, for #2 above, and even #1, people should not traditional e-mail system and Android devices.

Even though it may look encrypted e-mail communication is needed only for very small portion of users, the situation in #5 above affects many people. And some people have to invent workarounds (e.g. password-encrypted .zip files), many others are foolish enough to send information in the clear.

I think the reason the encrypted communication has never became "mainstream" is the complexity of its setup. I might be in the dark on this, but I am not aware of any e-mail client (or webmail provider) that makes it easy for non-technically-savvy people to set up and use encrypted e-mails. And the fact that the majority of the users do not recognize the need for the encrypted e-mail, contributes to the lack of the "critical mass" of users.

For an example of how such capability can be enabled, say, in Thunderbird, you can read this page: http://wefightcensorship.org/article/sending-encrypted-emails-using-thunderbird-and-pgphtml.html
Once it is properly installed, it is fairly easy to use it (assuming that your correspondent also has that capability enabled).

I don't think I've ever used an encrypted e-mail myself. However, I've relied on another capability of essentially the same software: digital signing of e-mails.
This is a bit more frequent functionality that is used. E.g. all security announces from FreeBSD team are digitally signed, so that you can verify authenticity of those.

I hope this addresses your curiosity.

mikeone

  • Hero Member
  • *****
  • Posts: 2762
Re: Encrypted email
« Reply #8 on: November 21, 2015, 01:45:27 am »
Email encryption will be a more common practice in Germany in the near future:

https://gigaom.com/2015/03/09/germany-pushes-for-widespread-end-to-end-email-encryption/

http://www.telecompaper.com/news/deutsche-telekom-fraunhofer-to-launch-encryption-service--1114512

Quote
Thursday 19 November 2015
Deutsche Telekom and the Fraunhofer Institute for Secure Information Technology SIT announced the introduct of an encryption service for emails. The service, called “encryption for the people,” was developed by SIT and will be operated at a Deutsche Telekom high-security data centre. The software is due to launch in the first half of next year.

The encryption is a software that generates the necessary encryption information and pre-configures the user’s email programme accordingly. For the encryption itself, the users do not need a new programme as most email programmes can be encrypted if the appropriate key is available.

Initially, Windows users will be able to use the encryption on Outlook or Thunderbird while versions for Mac OS X, Linux, iOS and Android are still developed.

someone

  • Sr. Member
  • ****
  • Posts: 415
Re: Encrypted email
« Reply #9 on: November 21, 2015, 05:11:02 pm »
Thank you StR. Very comprehensive and informative answer.

I agree that the difficulties for the average user to use it is the main reason it is not used more. Every time I explored the topic I decided it was too complicated for me to bother with it. Which is a shame.