frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Poor Johnny still won't encrypt

https://bfswa.substack.com/p/poor-johnny-still-wont-encrypt
27•zdw•2h ago

Comments

tomlockwood•1h ago
I thought this title was a reference to this David Bowie/NIN song: https://www.youtube.com/watch?v=LT3cERVRoQo
erelong•1h ago
Issue 1: Establishing lots of reasons why people should encrypt

Issue 2: Making it easy to encrypt

Issue 3: Popularizing encryption or getting more people to do it

FerretFred•1h ago
Issue 3.. most/many governments are taking active steps to discourage this practice or better still (for them), stamp it out completely.
xeonmc•1h ago
If you want encrypted communication over email, there's DeltaChat.
bradley13•1h ago
It's weird. Almost all web traffic is now https - even though very little of it is sensitive. Email, on the other hand, is quite often sensitive, and yet...no one cares.

Why?

wmf•1h ago
HTTPS is pervasive because Google encouraged it. Gmail could force S/MIME but they don't care.
hugo1789•52m ago
I think mandatory S/MIME without user-friendly key management would either be reverted pretty soon or it would kill Gmail.
wmf•49m ago
Google would have to build some kind of Let's Encrypt for S/MIME before they turned on the encouragement.
ghssds•41m ago
why did google wanted it?
laserbeam•1h ago
Unfortunately, those are 2 different problems. It’s easy to have servers store encryption keys to make https work. You only need to encrypt trafic between you and a server for 5 seconds at a time.

It’s hard for personal communications. The server shouldn’t know the keys, and they need to survive for decades.

mmh0000•1h ago
Nearly all email is encrypted in transit. All major MTA systems send encrypted and accept encrypted as the default.

This article is about encrypting the body of the email which is easy* but no widely implemented standard exists.

* Stupid easy for two nerds to email securely.

* Stupid hard to work with multiple people and non-nerds.

xeonmc•40m ago
might age fit the bill?
laserbeam•1h ago
Someone needs to design a super dumb and robust system where I can safely store all my keys on all devices I use an account. The fact that whatsapp, signal and other platforms tend to have a primary device for keys is bonkers to me. A primary device that can randomly die, get stolen or fall in a lake.

I have lost chat histories more times than I can remember, and I have to be extra diligent about this these days.

I don’t even want to think about pgp when I have to manually take care of this problem. Not because of my own skills, but because I could never make it reliable for my family and friends on their side.

wmf•1h ago
Apple/Google passkeys.
throwaway82931•46m ago
Indeed, passkeys would seem to represent a step forward from single-device to single-account.
AnonC•1h ago
> I have lost chat histories more times than I can remember, and I have to be extra diligent about this these days.

As per Signal’s diehard proponents, losing chat history is a feature, not a bug (I’m not being facetious when saying this, and you can see comments of this kind in Signal related threads here).

Edited to add: I don’t agree with that premise and have long disliked losing chat history.

laserbeam•1h ago
I know you are not being facetious. My problem is random Joe on the street sees it as a bug. He really does care more about actually being able to talk with his wife than Signal’s mathematically correct principles. He needs it to be reliable first, secure second.
AnonC•1h ago
GP here. I agree. I should’ve stated that I don’t like losing chat history and have seen that as a problem with Signal.

I have edited my previous comment to reflect that I don’t like losing chat history.

IlikeKitties•1h ago
> He needs it to be reliable first, secure second.

Than he should use something else. I need signal to be secure first, second and third and reliable in edge cases like this a distant number.

golem14•59m ago
Yeah, but if use proton for everything else and signal only for my secret world domination plans, traffic analysis will be so much easier…
wood_spirit•44m ago
My company recently really cut back on slack retention. At first I was frustrated, but we all quickly got over it and work carried on getting done at the same pace as before and nothing really got impacted like many of us imagined it might.
Helmut10001•20m ago
I set up automatic backups of WhatsApp to my self-hosted Nextcloud once. Since you need 'tested backups', I tried to decrypt these WhatsApp backups independent of my phone, but this was not possible. You need the original device. There are some hacks online, but they are always out of date.

I am tending now to running Mautrix Whatsapp bridge and backing up my data through this.

zkmon•1h ago
Maybe Johnny doesn't have a need to encrypt. The post card in India was just a card with message written on both sides, fully visible in plain text. It's very common that a postman would read out the letter to recipients sometimes, when they deliver it. Privacy is not an universal need.

Poor are those people who are forced to hide their message in encrypted formats,

dghlsakjg•1h ago
Nobody expects privacy when they send a postcard.

Most people keep their emails behind a password for a reason...

zkmon•52m ago
The point is, why not let people to have freedom of not having to encrypt? And why such freedom is considered as poor? This is like forcing everyone to have a smart phone, car, passport, zillions of IDs, internet profiles and calling their shackled life as rich.

The other day someone was shocked to see that I don't have FB and instagram accounts. When did people lose their freedom not have social media accounts?

viraptor•13m ago
Because if the default is unencrypted, you'll accidentally send secrets in plaintext one day. And if the default is encrypted and works well - why would you ever take time to explicitly disable that? What's the situation where you want to say "just in case someone intercepts this message, I want them to be able to read it"?
pcthrowaway•1h ago
> Proton is a notable exception.

Proton doesn't provide public APIs for retrieving the public GPG keys associated with their users' accounts, nor do they provide a way to send encrypted mail to their users' accounts without using their official apps.

Ergo, Proton is not really working to further the state of cryptography for email, they're only working to compel users to use their proprietary software (and ultimately their paid services).

If services which do automated sending of emails to their subscribers/users have no way to encrypt those emails for its users who are on proton mail, I don't understand how Proton can claim to care about encryption.

burnt-resistor•29m ago
Proton still appears to suffer from Lavabit's pathologies in several ways because it ultimately stores GPG private keys, hasn't had their "zero-access encryption" audited by an independent third-party, it hosts servers in privacy-hostile jurisdictions that can be seized, and they've already handed user data to authorities over 30k times. [0] Proton Mail is a simulacra of privacy as a service that lies to its customers.

At present time, the best way to assure privacy is to lease (using cryptocurrency) VPS instances in a neutral, privacy-respecting country and self-host a web-mail stack oneself. There isn't really a practical way around this because powerful nation states are able to demand access to customer data from almost every cloud/VPS provider in their jurisdiction.

0. https://proton.me/legal/transparency

sorbusherra•1h ago
I consider e-mails to be digital versions of postcards. Both are obsolete but have some usage scenarios. There is no need to use private communication in obsolete postcard type messaging, so there is no need for encryption. For private communications there are other better(easier) means which people use.
yardstick•39m ago
I’ve got hundreds of emails from the early 2010s between a couple of coworkers and myself that I can no longer read because they were S/MIME encrypted and I’ve got no idea what happened to my keys or even if my current client supports it anymore.

I wish the client stored it decrypted once received.

tptacek•20m ago
Yeah, at some point people are going to work out that the problem isn't Johnny, it's email. Email is distinctively hostile to secure messaging. No matter what software Johnny uses, "secure" email will always be inferior to alternative options.

https://www.latacora.com/blog/2020/02/19/stop-using-encrypte...

OpenAI are quietly adopting skills, now available in ChatGPT and Codex CLI

https://simonwillison.net/2025/Dec/12/openai-skills/
280•simonw•7h ago•161 comments

macOS 26.2 enables fast AI clusters with RDMA over Thunderbolt

https://developer.apple.com/documentation/macos-release-notes/macos-26_2-release-notes#RDMA-over-...
351•guiand•10h ago•193 comments

Apple has locked my Apple ID, and I have no recourse. A plea for help

https://hey.paris/posts/appleid/
197•parisidau•1h ago•70 comments

Poor Johnny still won't encrypt

https://bfswa.substack.com/p/poor-johnny-still-wont-encrypt
27•zdw•2h ago•31 comments

1300 Still Images from the Animated Films of Hayao Miyazaki's Studio Ghibli (2023)

https://www.ghibli.jp/info/013772/
51•vinhnx•3h ago•12 comments

GNU Unifont

https://unifoundry.com/unifont/index.html
185•remywang•9h ago•53 comments

Ferrari's Formula 1 Handovers: Handovers from Surgery to Intensive Care 2008;pdf

https://gwern.net/doc/technology/2008-sower.pdf
32•bookofjoe•6d ago•9 comments

Rats Play DOOM

https://ratsplaydoom.com/
245•ano-ther•10h ago•90 comments

Gild Just One Lily

https://www.smashingmagazine.com/2025/04/gild-just-one-lily/
8•serialx•4d ago•0 comments

Show HN: Tiny VM sandbox in C with apps in Rust, C and Zig

https://github.com/ringtailsoftware/uvm32
109•trj•8h ago•6 comments

Sick of smart TVs? Here are your best options

https://arstechnica.com/gadgets/2025/12/the-ars-technica-guide-to-dumb-tvs/
222•fleahunter•18h ago•230 comments

So What Should We Call This – A Grue Jay?

https://cns.utexas.edu/news/research/so-what-should-we-call-grue-jay
41•surprisetalk•5d ago•14 comments

50 years of proof assistants

https://lawrencecpaulson.github.io//2025/12/05/History_of_Proof_Assistants.html
70•baruchel•7h ago•11 comments

Show HN: I made a spreadsheet where formulas also update backwards

https://victorpoughon.github.io/bidicalc/
101•fouronnes3•1d ago•49 comments

Ensuring a National Policy Framework for Artificial Intelligence

https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-nati...
101•andsoitis•1d ago•159 comments

Freeing a Xiaomi humidifier from the cloud

https://0l.de/blog/2025/11/xiaomi-humidifier/
61•stv0g•1d ago•35 comments

The Coming Need for Formal Specification

https://benjamincongdon.me/blog/2025/12/12/The-Coming-Need-for-Formal-Specification/
12•todsacerdoti•3h ago•11 comments

Doxers Posing as Cops Are Tricking Big Tech Firms into Sharing People's Data

https://www.wired.com/story/doxers-posing-as-cops-are-tricking-big-tech-firms-into-sharing-people...
29•iamnothere•1h ago•7 comments

Slax: Live Pocket Linux

https://www.slax.org/
14•Ulf950•4d ago•1 comments

Google Removes Sci-Hub Domains from U.S. Search Results Due to Dated Court Order

https://torrentfreak.com/google-removes-sci-hub-domains-from-u-s-search-results-due-to-dated-cour...
65•t-3•3h ago•17 comments

Go is portable, until it isn't

https://simpleobservability.com/blog/go-portable-until-isnt
52•khazit•5d ago•46 comments

Capsudo: Rethinking Sudo with Object Capabilities

https://ariadne.space/2025/12/12/rethinking-sudo-with-object-capabilities.html
57•fanf2•9h ago•32 comments

The Checkerboard

https://99percentinvisible.org/episode/650-the-checkerboard/
37•thread_id•6h ago•6 comments

Koralm Railway

https://infrastruktur.oebb.at/en/projects-for-austria/railway-lines/southern-line-vienna-villach/...
295•fzeindl•20h ago•173 comments

Beautiful Abelian Sandpiles

https://eavan.blog/posts/beautiful-sandpiles.html
3•eavan0•3d ago•0 comments

Motion (YC W20) Is Hiring Senior Staff Front End Engineers

https://jobs.ashbyhq.com/motion/715d9646-27d4-44f6-9229-61eb0380ae39
1•ethanyu94•9h ago

Show HN: A real-time 4D fractal explorer in the browser using WebGPU

https://bryanjj.github.io/nebula/
5•bryan0•1d ago•2 comments

Oliver sacks put himself into his case studies. What was the cost?

https://www.newyorker.com/magazine/2025/12/15/oliver-sacks-put-himself-into-his-case-studies-what...
49•talonx•3h ago•10 comments

Building small Docker images faster

https://sgt.hootr.club/blog/docker-protips/
46•steinuil•20h ago•11 comments

Pg_ClickHouse: A Postgres extension for querying ClickHouse

https://clickhouse.com/blog/introducing-pg_clickhouse
84•spathak•2d ago•32 comments