deltachat / deltachat-desktop

Email-based instant messaging for Desktop.
GNU General Public License v3.0
951 stars 170 forks source link

first send email from desktop-client to native-email unencrypted #423

Closed viisauksena closed 5 years ago

viisauksena commented 5 years ago
r10s commented 5 years ago

hi @viisauksena, thank you for your post.

you're right, the first message is not encrypted by Autocrypt (Autocrypt is used by Delta Chat by default).

Autocrypt wants to protect against mass surveillance while keeping things for the user as simple as possible - the encryption should not stay in the way of communication - otherwise it won't be widely adapted - see gpg & co.

however, Autocrypt does not aims to be a replacement for pgp/gpg - it wants to be a replacement for clear text mails.

but, of course, we know that there are users that require a higher level of security. Delta Chat offers so called verified groups for this purpose. While still being in development, they will offer an even higher level of security as they not only encrypt by default but also allow a very simple out-of-band-verification flow.

ralphtheninja commented 5 years ago

Since this is by design, closing.

okdistribute commented 5 years ago

I do think it's important and perhaps would be nice to think about this for both android and desktop -- could be a suggested 'first message' that is sent during the contact request process 'Hi, let's start an encrypted chat, just reply here.' or something of that nature.

r10s commented 5 years ago

yeah, sth. like that is possible. maybe even more autocrypt-related. we could file an issue in the interface repo or in the forum. not sure what the correct place for this is :)

viisauksena commented 5 years ago

Since this is by design, closing.

*wtf - delta.chat is promoted heavily with end2end encryption - and even if the device know the public key in the agent (but not the desktop-app) - first email is send unencrypted without a hint - and this is in your words "is broken by design"

hpk42 commented 5 years ago

On Wed, Dec 12, 2018 at 16:08 -0800, viisauksena wrote:

Since this is by design, closing.

*wtf - delta.chat is promoted heavily with end2end encryption - and even if the device know the public key in the agent (but not the desktop-app) - first email is send unencrypted without a hint - and this is in your words "is broken by design"

I think a hint would be useful indeed. Currently it says in a grey box:

Send message to XXX:

and maybe we could rather say:

?

r10s commented 5 years ago

@hpk42 added your suggestion