Show more

@seven @Fairphone @protonmail @FediFollows @1ll173r47 My own time was never the issue. It was always about how much patience they have. Even when I set them up in their preferred MUA, sometimes they still must accept that the workflow will be a little different for them.

@1ll173r47 @FediFollows @protonmail @Fairphone @seven It's unacceptible for an accountant to demand sensitive financial data go exposed without encryption.

@seven @Fairphone @protonmail @FediFollows @1ll173r47 The accountant (like all accountants) ran Windows. This means she not only had an email firewall to check email upon arrival, but she also had realtime scanning of all files that land on her system. So she was protected anyway (nevermind that my linux box was unlikely to get infected and transmit malware to her).

@1ll173r47 @FediFollows @protonmail @Fairphone @seven In one case, I mandated that a new accountant exchange either GPG keys or S/MIME keys. I said I would setup her machine if needed, but she was only comfortable having her own IT guys do the work. I was fine with that but then she came back & said her IT guys are opposed to it because if I send malware in email, it will get past the anti-virus firewall. I didn't hire her over it.

@seven @Fairphone @seven @protonmail @FediFollows @1ll173r47 If I give them my pubkey & ask for theirs, & they are willing and able to comply, then they are proficient enough to be considered an expert user in this context (which is not the case i'm really talking about). If they can't handle that, they are a novice. Sometimes I have still gotten away with that arrangement but only under circumstances where I personally install GPG for them.

In case anyone was wondering, Weinberg is a pushover with no constitution. I once asked him why doesn't filter out privacy-abusing sites & it triggered him. He had no sound defense.. no good answer for it. It's clear that he simply does not have the guts to truly deliver a privacy-respecting search engine. He's fixated on serving normies who are privacy-naive.

@Apolyon_LMR After some research, I've found that there are some microbial cleaners for grease/oil. That is, you can buy microscopic bugs in a liquid form that like to eat the stuff. Well they don't eat it spotless like magic, but they seem to soften the hard baked-on grease enough that a plastic scraper has a fighting chance without removing the non-stick surface.

@Apolyon_LMR it's not good reason. My first choice of search engine is sercxi.nnpaefp7pkadbxxkhz2agtbv2a4g5sgo2fbmv3i7czaua354334uqqad.onion precisely because it filters out unusable garbage sites. Only when despiration calls do I unfold the CF sites at the bottom, & click the favicon to visit the IA mirror of those CF sites (in which case I still manage to avoid CF).

@1ll173r47 @protonmail @ProtonCalendar @protonvpn @Fairphone @FediFollows It seems to be getting harder to impose in any form on the other (novice) party, in which case I generally impose . And now that is pushing CAPTCHAs, i'm somewhat embarrassed to insist that they use protonmail. Wire is going to be filling that gap more going forward. Or -to-tutanota, but that's a pain b/c tuta doesn't have msg notification.

@FediFollows @Fairphone @protonvpn @ProtonCalendar @protonmail @1ll173r47 For expert-to-novice, if it's long term w/frequent contact, I use mutt & pressure the other user to use electronmail, & I walk them through putting my pubkey in their address book & exporting their key. That's rare though. Most often I can't get away w/imposing that burdon on them, so I have to use electronmail & i'm happy enough just to get them on protonmail.

@1ll173r47 @protonmail @ProtonCalendar @protonvpn @Fairphone @FediFollows I don't know what the numbers are, but if we were to survey, we'd have to divide the stats into 2 catorgies: expert-to-novice and novice-to-novice (probably safe to assume expert-to-expert comms excludes webmail). The novice-to-novice case is probably a disaster on par with gmail-to-gmail no crypto, or at best proton_web-to-proton_web.

@1ll173r47 @FediFollows @Fairphone @protonvpn @ProtonCalendar @protonmail users who are not keen to take on the risks of on-the-fly dynamic javascript absolutely do use . Thunderbird does not work with Protonmail unless the user subscribes to get the bridge service, but TB can serve novice users who use a conventional email service in a way that gives e2ee. Otherwise webmail is risky.

@MichaelAltfield @ForbesMagazine It's wrong to call that a "dead man's switch". It's a theft detector. A dead man's switch is something different. Forbes: plz correct the title.

@futureisfoss @protonmail @ProtonCalendar @protonvpn @LemmyDev @FediFollows That's a decent alternative. I also suggest this article (& when reading it, mentally substitute "recaptcha" w/both recaptcha and hcaptcha): nearcyan.com/you-probably-dont

@protonmail @ProtonCalendar @protonvpn @Fairphone @FediFollows If anti-features continue to develop, at some point the better recommendation will be something like Thunderbird + Enigmail, which essentially means we'll have to disregard ease of use & pressure novices to increase their tech proficiency.

@FediFollows @Fairphone @protonvpn @ProtonCalendar @protonmail Both and are increasingly calling for users to make more and more compromizes. I keep teetering back and forth on which gratis ESP I suggest to novice users. It looks like Tutanota may be a better recommendation at the moment. But certainly this race to the bottom of sorts is disturbing as they both services get progressively worse.

@protonmail @ProtonCalendar @protonvpn @Fairphone @FediFollows I should also mention that there are non-CAPTCHA fixes to the problem of password attacks: When a password is incorrectly entered, the server can force a delay before allowing another attempt on the account that was tried. The delay can be long enough to completely render brute force attacks useless.

@FediFollows @Fairphone @protonvpn @ProtonCalendar @protonmail This Mastodon thread herein serves both purposes: 1) to inform of the problem, and 2) to suggest privacy seekers look elsewhere for email until the problem is resolved.

@protonvpn @ProtonCalendar @protonmail @FediFollows The CAPTCHA problem is an extension of another problem: there is no POP3 service. If users had pop3 service, there would be no CAPTCHA problem. Paying customers can get a "bridge" which perhaps circumvents the CAPTCHA, but users of gratis accounts do not have that option.

@FediFollows @protonmail @ProtonCalendar @protonvpn That's not what I consider an open discussion platform.. that's exclusive for MS users. Github is not a good venue for FOSS tools with a security/privacy mission. Solving an hCAPTCHA or reCAPTCHA prior to /reading/ email is unacceptible. There are lots of CAPTCHA alternatives, but as users we seek alternatives to bad tools. E.g. Tutanota does not impose CAPTCHA upon login.

Show more
Mastodon 🔐 privacytools.io

Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance.

Website: privacytools.io
Matrix Chat: chat.privacytools.io
Support us on OpenCollective, many contributions are tax deductible!