Hacker News .hnnew | past | comments | ask | show | jobs | submitlogin

"send end-to-end encrypted (E2EE) emails to anyone, even if the recipient uses a different email provider" but the video shows Gmail asking the recipient to authenticate. How does that work? If a Gmail user sends an email to my self-hosted server, there is nowhere to authenticate me to.

And it means either Gmail or the actual email stores decryption keys, so what is the threat model in which E2EE is useful here?

The only "advantage" I see is that now recipients must manually archive these "encrypted" emails if they want to keep access to them in the future (so most of them won't). That would be consistent with Google's strategy with AMP's editable emails.



The threat model seems to be "there are other email providers beside Google. How can we change that?"

Not necessarily a threat model that benefits you


> If a Gmail user sends an email to my self-hosted server, there is nowhere to authenticate me to.

They'll probably just force external recipients to create a Google account and verify control over the independent email address...


Exactly this. No different from if someone shares a Google Doc with your email address.

And it makes sense. It's the logical way to prove you have access to the email account.


But that's not end-to-end encryption, that's a pastebin with a login


MITM.

This is likely about regulatory compliance. Many industries require encryption and transit.


In other words?

> The only way that would work if Google could decrypt the message!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: