| |||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||
原始链接: https://news.ycombinator.com/item?id=43604308
Hacker News 上的一篇讨论批评了 Gmail 端到端加密的实现方式,认为它复制了安全电子邮件中已存在的问题:将电子邮件变成指向安全门户网站的通知链接。评论者指出,这种方法在医疗保健(HIPAA 合规)和银行等行业很常见,因为普通用户对真正安全电子邮件(如 PGP)的采用率很低。密钥管理的复杂性是一个障碍,导致人们依赖于集中式、通常是特定国家的安全门户网站。一位评论者对客户端 JavaScript 处理加密内容的安全风险表示担忧,尤其是在 ProtonMail 和 MEGA 等服务中,因为信任 Google 处理客户端页面就违背了端到端加密的初衷。普遍缺乏用于验证签名资产和确保代码可信的浏览器扩展程序仍然是一个重要的未解决问题。总体而言,人们认为确保电子邮件安全仍然是一个挑战,需要合作、切实可行的规章制度以及摆脱专有的“护城河”式解决方案。
| |||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||
Then there are the national governments and things like insurance companies. All happily sending message notifications where you need to sign in to their own portals.
Securing email is too complex, so everyone builds their own secured portal thingy, and your mailbox has become a receptacle for notifications. Figuring out a solution would require cooperation, pragmatic lawmaking, and giving up those nice cashcows of moated portals, so it won't happen.
reply