home.social

#autocrypt — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #autocrypt, aggregated by home.social.

fetched live
  1. This article is a good summary of the benefits and limits of #AutoCrypt, as a Trust-On-First-Use way of using PGP to encrypt email;

    "Autocrypt does not claim to defend against it [machine-in-the-middle attacks]. What it does claim is to defend against the far more common passive adversary who simply reads mail in transit or at rest, and to do so for the vast population that would otherwise use no encryption whatsoever.

    @[email protected], 2026

    havenmessenger.com/blog/posts/

    #Haven #TOFU #PGP #email

  2. This article is a good summary of the benefits and limits of #AutoCrypt, as a Trust-On-First-Use way of using PGP to encrypt email;

    "Autocrypt does not claim to defend against it [machine-in-the-middle attacks]. What it does claim is to defend against the far more common passive adversary who simply reads mail in transit or at rest, and to do so for the vast population that would otherwise use no encryption whatsoever.

    @[email protected], 2026

    havenmessenger.com/blog/posts/

    #Haven #TOFU #PGP #email

  3. @Razemix @delta From what I understand, yes and no.

    1. Yes with #Thunderbird or other email clients with encrypted email only. No with Delta Chat unless someone makes a TB addon for Chatmail or #autocrypt.

    2. Yes if you use #DeltaChat with DC users and TB with #PGP for instance. In any case, Chatmail relays will only allow encrypted mail in or out.

    Before any of this, you'll have to keep hold of your chatmail email address and password and also be able to export your private key generated by DeltaChat which I think is not available in the UI anymore. This means you'll need to go the manual classic email registration route not the default onboarding.

    I dont know how secondary relays will factor into this.

  4. @Razemix @delta From what I understand, yes and no.

    1. Yes with #Thunderbird or other email clients with encrypted email only. No with Delta Chat unless someone makes a TB addon for Chatmail or #autocrypt.

    2. Yes if you use #DeltaChat with DC users and TB with #PGP for instance. In any case, Chatmail relays will only allow encrypted mail in or out.

    Before any of this, you'll have to keep hold of your chatmail email address and password and also be able to export your private key generated by DeltaChat which I think is not available in the UI anymore. This means you'll need to go the manual classic email registration route not the default onboarding.

    I dont know how secondary relays will factor into this.

  5. @ben
    > I rather like using Thunderbird on Android. It supports Autocrypt too!

    I didn't know either of these things. Thanks for the tip!

    I've installed Thunderbird via F-Droid so I can try this out. I'm told it supports XMPP and Matrix too, which might allow me to get rid of a bunch of the apps I'm currently juggling on my ancient and increasingly decrepit Android.

    #Thunderbird #AutoCrypt #XMPP #Matrix

    @delta @deutrino

  6. @ben
    > I rather like using Thunderbird on Android. It supports Autocrypt too!

    I didn't know either of these things. Thanks for the tip!

    I've installed Thunderbird via F-Droid so I can try this out. I'm told it supports XMPP and Matrix too, which might allow me to get rid of a bunch of the apps I'm currently juggling on my ancient and increasingly decrepit Android.

    #Thunderbird #AutoCrypt #XMPP #Matrix

    @delta @deutrino

  7. @scottjenson I'm pessimistic up to the point where you have to have to assume it will fail completely. Just as XMPP and MAIL failed.

    The only encryption implementation with success were the approaches where the UX can be controlled centrally.

    For MAIL there is #autocrypt now, it is astonishing how good it is – but email is still not encypted today.

    XMPP/Jabber has OMEMO, but stillt struggles with client adoption and it isn't omnipresent.

    Where it worked: #DeltaChat and #Signal both using a central library that can make sure encryption reliably lands at peoples fingertips.

  8. @scottjenson I'm pessimistic up to the point where you have to have to assume it will fail completely. Just as XMPP and MAIL failed.

    The only encryption implementation with success were the approaches where the UX can be controlled centrally.

    For MAIL there is #autocrypt now, it is astonishing how good it is – but email is still not encypted today.

    XMPP/Jabber has OMEMO, but stillt struggles with client adoption and it isn't omnipresent.

    Where it worked: #DeltaChat and #Signal both using a central library that can make sure encryption reliably lands at peoples fingertips.

  9. oh shit, with #Autocrypt v2 being worked on, that means #Deltachat and other chatmail systems will have post-quantum security and full perfect forward secrecy support!

    that means basically the only lingering issues I had with Deltachat as a personal messenger are completely gone

    seriously go to
    https://delta.chat/ right now and try it out
    encryption info:
    https://delta.chat/en/help#e2ee
    https://autocrypt2.org/#/

  10. oh shit, with #Autocrypt v2 being worked on, that means #Deltachat and other chatmail systems will have post-quantum security and full perfect forward secrecy support!

    that means basically the only lingering issues I had with Deltachat as a personal messenger are completely gone

    seriously go to
    https://delta.chat/ right now and try it out
    encryption info:
    https://delta.chat/en/help#e2ee
    https://autocrypt2.org/#/

  11. Unverschlüsselte E-Mails von Behörden sind Einbahnstraßen.

    Der Staat schreibt mir unverschlüsselt. Ich soll vertrauen. Ich soll reagieren. Ich soll unterscheiden, ob das echt ist oder Phishing.

    Technisch ist das nichts weiter als eine Postkarte mit Briefkopf. Jeder auf der Strecke kann mitlesen, kopieren, archivieren. Authentizität: Glückssache. Vertraulichkeit: Hoffnung. Haftung: natürlich beim Bürger.

    Hinschreiben darf ich. Antworten auch. Aber einen geschlossenen Kommunikationskreis gibt es nicht. Inbound unsicher, outbound optional. Eine Einbahnstraße – mit Gegenwind.

    Dass dabei Phishing explodiert, ist kein Unfall. Es ist Systemlogik.

    Die Ironie: Lösungen existieren. Offene. Funktionierende. Autocrypt wäre benutzbar. PGP wäre möglich. Aber offen heißt: nicht kontrollierbar. Also politisch unerwünscht.

    Stattdessen: Schulterzucken. „De-Mail ist tot.“ „Wir arbeiten an einer Lösung.“ Seit Jahren.

    Man kann keine sichere Kommunikation verlangen, wenn man selbst nur Postkarten verschickt.

    #ITSecurity #Behörden #Email #Verschlüsselung #Autocrypt #Einbahnstraße #Fediverse

  12. Wer noch nicht mit Mail-Verschlüsselung arbeitet, könnte langsam mal darüber nachdenken, wenn jetzt der Bundeskanzler von "präventiver Telekommunikationsüberwachung" spricht (riecht nach einem neuen Branding für die Chatkontrolle).

    Früher hätte ich jetzt erklärt, wie man PGP mit Thunderbird nutzt. Stattdessen empfehle ich seit einigen Jahren der Usability und Portabilität nur noch
    https://delta.chat/de/

    Installieren (für alle geläufigen mobilen und Desktop Systeme verfügbar), vorhandene Emailadresse eintragen, fertig.

    Die Verschlüsselung ist voll automatisiert nutzbar (man kann weiterhin den bereits existierenden PGP Key verwenden).

    Probiert es mal aus, kinderleicht!
    @delta

    #deltachat #Verschlüsselung #Email #PGP #autocrypt #EinsteigerFreundlich

  13. In 2014 @matthew_d_green wrote "What's the matter with PGP?" blog.cryptographyengineering.c

    We'd like to humbly report completion of its main suggestions. Better late than never! :)

    - Key management is automatic through #securejoin and #autocrypt protos

    - #chatmail relays form an end-to-end encrypted email enclave interoperable with any e-mail address using proper end-to-end encryption.

    - RFC 9580 "cryptorefresh" is rolled out in current releases and will be activated soon.

    One to go? ;)

  14. In 2014 @matthew_d_green wrote "What's the matter with PGP?" blog.cryptographyengineering.c

    We'd like to humbly report completion of its main suggestions. Better late than never! :)

    - Key management is automatic through #securejoin and #autocrypt protos

    - #chatmail relays form an end-to-end encrypted email enclave interoperable with any e-mail address using proper end-to-end encryption.

    - RFC 9580 "cryptorefresh" is rolled out in current releases and will be activated soon.

    One to go? ;)

  15. Так что, кубинцы(?) сделали свой #ArcaneChat (лёгкий аналог #DeltaChat), что с нового релиза поддержка нешифрованных сообщений убрана? Или я неправильно понял Гуглоперевод? В уме, правда, этот пазл как-то не очень складывается из моих поверхностных познаний, как работает этот их #Autocrypt
    #lang_ru @Russia

  16. @lns Should but they never will, with good reason. They don't really need to, for email encryption at least there's #DeltaChat that non-technical people have a better chance of learning. Yes, it only uses a subset of #PGP called #Autocrypt, but if you really want to use PGP, there are much better tools than #GPG like: #Thunderbird, #Mailvelope and #Kleopatra. I know some of these are front-ends for GPG.

  17. @qgustavor @adbenitez you can add as many profiles/accounts as you like, some of them can be classic email accounts that can email everyone that uses email, even if they don't support encryption. If they have a client with support (or deltachat), then the conversation is encrypted as soon as they answer you (outgoing messages contain your pubkey, there is no key server).

    Go to the profile switcher -> Add Profile -> new profile -> use different server -> classical email login

  18. @qgustavor @adbenitez you can add as many profiles/accounts as you like, some of them can be classic email accounts that can email everyone that uses email, even if they don't support encryption. If they have a client with #autocrypt support (or deltachat), then the conversation is encrypted as soon as they answer you (outgoing messages contain your pubkey, there is no key server).

    Go to the profile switcher -> Add Profile -> new profile -> use different server -> classical email login

  19. @sardon not that we know off. As far as we know thunderbirds current extension model does not allow even an #autocrypt compliant plugin let alone all the rest that delta offers. #enigmail used to offer full autocrypt support but when thunderbird changed the plugin model and integrated openpgp into thunderbird they went back to the old idea of "users have to consciously manage their encryption keys" ... An unfortunate old tradition. We aim for modern usable security like signal delivers.

  20. @sardon not that we know off. As far as we know thunderbirds current extension model does not allow even an #autocrypt compliant plugin let alone all the rest that delta offers. #enigmail used to offer full autocrypt support but when thunderbird changed the plugin model and integrated openpgp into thunderbird they went back to the old idea of "users have to consciously manage their encryption keys" ... An unfortunate old tradition. We aim for modern usable security like signal delivers.

  21. @delta

    Question for you!

    Do you have any documentation, guides, or tips on how to get #neomutt's #autocrypt working with a chatmail server?

    I've gotten as far as importing my keys so I can read messages from the mail server on both clients, but I can't figure out how to extract the keys from a message so I can add them and send successfully from mutt.

    What am I missing?

  22. @delta

    Question for you!

    Do you have any documentation, guides, or tips on how to get #neomutt's #autocrypt working with a chatmail server?

    I've gotten as far as importing my keys so I can read messages from the mail server on both clients, but I can't figure out how to extract the keys from a message so I can add them and send successfully from mutt.

    What am I missing?

  23. An enjoyable and fruitful #OpenPGP email 2024 summit closing up .... with many standardization efforts roughly agreed between several players: maximizing metadata protection (IETF header protection effort), ecosystem transition V4->V6 and PQ-keys (IETF replacement keys), #autocrypt level 2 possibly involving integration of "in-band" with "out of band" key distribution like WKD/HKP which themselves are bound for integration. Believe it or not .... the eco system is moving ;)

  24. An enjoyable and fruitful #OpenPGP email 2024 summit closing up .... with many standardization efforts roughly agreed between several players: maximizing metadata protection (IETF header protection effort), ecosystem transition V4->V6 and PQ-keys (IETF replacement keys), #autocrypt level 2 possibly involving integration of "in-band" with "out of band" key distribution like WKD/HKP which themselves are bound for integration. Believe it or not .... the eco system is moving ;)

  25. @homegrown @delta Apparently, you can have encrypted chats with users using other email clients that support the #Autocrypt standard like @k9mail and #Snappymail webmail. Tried with K-9 a while back and it worked great.

  26. @homegrown @delta Apparently, you can have encrypted chats with users using other email clients that support the #Autocrypt standard like @k9mail and #Snappymail webmail. Tried with K-9 a while back and it worked great.

  27. @wiwet Hat man die Leute erstmal von Webmailern wie Gmail, Gmx, Web.de etc. weg und auf #Thunderbird, dann geht es eigentlich. Da wird #Autocrypt (de.wikipedia.org/wiki/Autocryp) unterstützt, das macht das meiste automagisch :)

  28. @wiwet Hat man die Leute erstmal von Webmailern wie Gmail, Gmx, Web.de etc. weg und auf #Thunderbird, dann geht es eigentlich. Da wird #Autocrypt (de.wikipedia.org/wiki/Autocryp) unterstützt, das macht das meiste automagisch :)

  29. @be literally my experience with matrix, never happens with #DeltaChat and #Autocrypt

  30. @kirschner @fdroid
    - Amethyst, a client for the free/open #Nostr protocol
    - @delta, a chat app using #email with support for #Autocrypt standard
    - @AntennaPod podcast player
    - Voice, for playing #DRM-free audiobooks
    - KreptEY, keyboard for #e2ee communication using any messenger
    - Rethink: DNS + Firewall
    - Fast Shopping, old but beautiful gold.

  31. @qbi Sich mit #PGP rumzuärgern war mir zu lästig. Habe in einem letzten Versuch meine Clients auf #Autocrypt konfiguriert, damit sehe ich die Chance einer automatischen, opportunistischen e2ee bei Mail. Nur fehlen noch die Rezipienten. (Entwicklung in Thunderbird geht voran)
    autocrypt.org/

    Daneben betreibe ich einen eigenen Mailserver mit erzwungener #TLS Verschlüsselung. Damit habe ich auf meiner Seite keine Drittparteien, die meine Mails lesen können.

  32. @itsfoss
    - Filen @filen (#e2ee cloud #backup),
    - DeltaChat @delta (email client supporting #autocrypt),
    - Crowdsec @CrowdSec (malicious ip blocker for servers),
    - Dangerzone @dangerzone (for opening attachments safely),
    - Notesnook @notesnook.

  33. Some issues:
    - #WKD only allows serving a single key
    - #Autocrypt also only allows using 1 key
    - How do we do deprecation of keys without revocation?
    - @thunderbird and other clients only accept 1 key from key servers
    - keys.openpgp.org only serves 1 key per address
    - Client key prioritization (v4 or v6?)
    - Mixed recipients; how do I encrypt?
    - WoT: Corroborative paths
    - Can we link keys?

  34. @phantomprotokoll #deltachat ist glaube ich aus der Mode gekommen, weil man als #maninthemiddle da durch #autocrypt beiden falsche Schlüssel unterjubeln kann. Aber #briar ist glaube ich viel genutzt. Nur dass bzw. wozu man das nutzt posten die meisten vermutlich nur ungern öffentlich ;-)

  35. I’m looking into #Autocrypt and what seems to be its flagship app, #DeltaChat. Unfortunately neither work with my secure #email provider #ProtonMail. The latter have publicly expressed #security concerns but did not state details because they don’t want to discourage the project.

    I think one issue is the unauthenticated #OpenPGP public key exchange. It feels like it’s achingly close, if only Autocrypt would support #WKD. Are there any other issues?

    #GnuPG #GPG #privacy #InfoSec #cybersecurity

  36. @jan Delta.chat does E2EE using AutoCrypt with other DC users. It can also send plain text to standard email clients as a fallback, making it compatible with a huge existing user network. I've had more success getting Jane Average users to use it that any other free code app, mainly because that already have an email account they can use with it

    #AutoCrypt #E2EE #DeltaChat #email

    @delta
    @atomicpoet