Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

HTTPS is pervasive because Google encouraged it. Gmail could force S/MIME but they don't care.


No, they couldn't. What they could do--and what they did do--was push for the move of TLS connections for the MX-MX hop of email; I don't have the stats off the top of my head for how prevalent that is, but I think it's in the 80-90% range of email being delivered in this method.

But end-to-end encrypted email? It breaks everything. You need to get all the MUAs to support it (very few do either S/MIME or PGP). You'll break webmail--the most popular way to use email--without lots of major investment. And encrypted email breaks things like spam filtering or server-side filters catastrophically. Key discovery is also unsolved.

There was a time when I was on the everybody-should-use-encrypted-email train. But I've since grown up and realized that encrypted email fundamentally breaks email in ways that people are unprepared for, and people have already figured out how to route around the insecurity of email via other mechanisms.


I think mandatory S/MIME without user-friendly key management would either be reverted pretty soon or it would kill Gmail.


Google would have to build some kind of Let's Encrypt for S/MIME before they turned on the encouragement.


why did google wanted it?


Google makes money off search, which requires that users want to visit websites. All websites using HTTP are not secure. Unsecure websites are uninteresting to most users, but most users don't have the know-how to distinguish what sites are using HTTPS and which aren't. So the simplest solution is to get all websits to switch to HTTPS before it becomes a problem


Another possibility is Google is in an industry that makes money by collecting information about users, and by supporting universal HTTPS, they gained a competitive advantage over ISPs and others regarding user data for Google searches and other services.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: