Most people don't encrypt because they're not scared enough. It usually takes some time before their wordlview is repeatedly shattered enough that encryption is the only choice they have.
Most people don't encrypt because they're not scared enough. It usually takes some time before their wordlview is repeatedly shattered enough that encryption is the only choice they have.
* Encryption in transmission emails sent and received, using SSL/TLS
* Encryption in transmission of webmail sessions, using HTTPS
* Authentication security: Do they use 2 factor or other tech?
* Logging and retention of logs
* Reading your mail to build marketing profiles and social graphs
* Access by employees to your data
* Retaining and sharing your personal data with other businesses
* Security of your account information; can they easily be persuaded to surrender it
* Security of the email provider's systems
* Responsiveness to 3rd party requests for your information, whether private parties in lawsuits or legal authorities with/without warrants
* Cooperation with government surveillance dragnets
Security always is a matter of degree. Email will never be perfectly secure but there are some big differences between providers.
Sorry for sniping this specific one, but 2FA is (more often than not), security theater. It gives the illusion of security like how TSA baggage check is a big dance of scanning, pat-downs, and key ceremonies.
For context, consider Yahoo Mail, where emails are read by intelligence agencies before the user even gets them. Does my 2FA help here? Probably not.
I can understand that 2FA does have its uses, but frequently I'm seeing it being used like those 'Secured by Comodo SSL' with a picture of a shield to make a would-be shopper feel like the transaction is more secure. It can be theater.
To summarize, 2FA does not prevent email reading if the provider doesn't, however it does help prevent run of the mill takeovers, especially if you've reused a password somewhere.
Security is all about defense in depth, it's worth keeping in mind that 2FA is an important step there, but by no means the only one.
If you aren't encrypting+signing a message, you've already decided that security requirements of that particular message is minimal.
MFA is used to prevent a third-party who has access to your credentials from being able to login as you and, in the case of U2F, to prevent a successful phishing attempt from compromising your account.
MFA offers no, and never has been billed as, protection against a subverted server or an attacker who can decrypt or tamper with traffic on the wire.
Security is a large, complicated problem. There will never be a single measure which protects against every threat.
Securing against low-level hackers and intrusions increases security, even if it doesn't stop the NSA. It also doesn't stop the CIA from physically spying on you.
Securing yourself against low-level hackers and intrusions is not security theater. For most people, these are the most frequent and direct threats.
I would also argue that over-securing yourself is security theater. It's the same as overselling insurance products to people whose risk profile doesn't match the product. If you're not making security decisions based on the profile of risks you encounter, then you're engaging in theater to make yourself feel better.
This is a completely wrong statement. It helps prevents compromise from non-system-level attackers. Telling a user that 2FA is "security theater" is doing far more harm than good.
That's not true. A friend and I use GPG just to use GPG. You don't have to want to keep something private, just like you don't need to be doing illegal things to want curtains on your house.
"If one would give me six lines written by the hand of the most honest man, I would find something in them to have him hanged"
What I mean is that I can decide to not encrypt and have my emails under public scrutiny, but as I said, most people are not scared enough because it doesn't happen on their watch.
It doesn't matter what the content is, or how non-libelous - if it's encrypted with PGP, it's private.
> Riseup provides online communication tools for people and groups working on liberatory social change. We are a project to create democratic alternatives and practice self-determination by controlling our own secure means of communications.
This is what they claim on their homepage[1]. Tools built by people who believe in a certain philosophy for people working on "liberatory social change".
They try to operate and control their tools. They don't claim that they are "the-most-secure-email-provider".
They claim to work on what they call "Network Security"[2] (traffic encrypting and providing services outside of the tracking bubble), and define other fields of security ("Human Security", "Device Security", "Message Security"), that the user can improve himself by education. They provide means of education for this.
This is an alternative. Gmail is maybe more "secure", or maybe not, but don't claim these kind of social changes. Gmail is "free" and commercial. Riseup is not free and volunteer-run.
[2] https://riseup.net/en/security/#security-overview
edits: typos