Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The argument that email is inherently insecure is specious. Most providers offer IMAP over TLS. Hotmail offers POP (which is incredibly crappy), but at least over TLS. Some big ISPs (e.g., Verizon) don't offer encrypted mail, and should be ashamed of themselves for this -- but this is definitely the exception these days. Mail between servers is also generally encrypted via TLS. And SPF and DomainKeys generally provide a nice audit trail if someone's hacking. So it's just wrong to suggest that email is usually sent in cleartext form or is otherwise insecure -- even if the users involved haven't set up PGP.

I think it's totally legitimate for consumers to be concerned about the companies that host their email. Unlike social networking, email is for "important stuff", and while webmail providers like Google generally have protections in place to prevent random employees from reading your mail, the fact is that the possibility still exists, and incidents have occurred at companies like Google of rogue employees illicitly reading end-users' email. Someone with access to your Facebook account is unlikely to get access to your bank statements, mortgage emails, or travel plans. But if someone can read all your email, they'll likely get all these and much more.

The only genuinely safe long-term solution is for mail hosts to store their users' email encrypted in such a way that only the end users (and not the company) can read the email. This would preclude server-side ad targeting, but users should -- and I believe, will -- ultimately demand it.



mail between servers is also generally encrypted via TLS

Source for this? It historically has not been, but this may have changed.

Regardless, end-to-end encryption with PGP or S/MIME is the only way to really send "secure" email, and even then you're vulnerable to snooping/mishandling/exposure at the end points when the emails are actually read.


I run my own private mail server and also manage one for a company I consult to and anecdotally I can back this up. The logs for both servers show that the bulk of MTA to MTA traffic is encrypted.


The Mozilla ISP database (https://live.mozillamessaging.com/autoconfig/v1.1) has a zillion entries, most of which clearly indicate SSL or STARTTLS.


There are just over 700 entries in that database, not a zillion.


How fortunate for us that you found the time to offer this insightful rebuttal.

I stand corrected. There are not a zillion entires in that database. There are many hundreds, covering only approximately 2B email accounts. Clearly the question of wether these data are representative of email security at large must be resolved in an properly peer-reviewed academic journal.

I am sorry to have wasted your valuable time with such an ill-considered comment. Please accept my heartfelt apologies.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: