Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Delta Chat
Delta Chat
@delta@chaos.social  ·  activity timestamp 3 weeks ago

Don't believe those who loudly claim email can not avoid metadata! They are ignorant of our continuous works on minimizing metadata:

DONE:

- no phone number other identifying data needed
- no cleartext "Subject"
- no cleartext "To"
- randomized "Date"
- no IP addresses
- group/avatar/attachment/etc metadata only contained in encrypted message parts

Upcoming:

- servers to never see cryptographic ID metadata
- remove "threading" and auxilliary headers
- experiment with Sealed Sender

  • Copy link
  • Flag this post
  • Block
Adam Katz
Adam Katz
@adamhotep@infosec.exchange replied  ·  activity timestamp 2 weeks ago

@delta thoughts from an anti-spam professional:

If the unencrypted Date header is more than a few hours off, it is likely to be blocked as spam. Randomly skewing it by up to 1800 seconds in either direction should be safe. Changing the time zone to grossly mismatch the geoIP is probably unwise, though +0000 is fine.

I suspect you're trying to make your headers super generic with all the important and identifiable aspects (and metadata) in the encrypted body. That's a good move, just be careful about spam filters.

  • Copy link
  • Flag this comment
  • Block
SkyLuke
SkyLuke
@SkyLuke@bolha.us replied  ·  activity timestamp 2 weeks ago

@delta I think emails should be remade from scratch. They are too old and have trust in too much stuff. We need a newer and better protocol that still feels like email, but encrypts everything and doesn't allow spoofing.

  • Copy link
  • Flag this comment
  • Block
patter
patter
@patterfloof@meow.social replied  ·  activity timestamp 3 weeks ago

@delta think what of the entire routing info in mail headers, which server it originated from & those it passed through etc

  • Copy link
  • Flag this comment
  • Block
FoolishOwl
FoolishOwl
@foolishowl@social.coop replied  ·  activity timestamp 2 weeks ago

@patterfloof @delta If it doesn't conform to RFC standards for email, it's not email. It may be better, it may be worse, but it's not email anymore.

  • Copy link
  • Flag this comment
  • Block
Delta Chat
Delta Chat
@delta@chaos.social replied  ·  activity timestamp 2 weeks ago

@foolishowl @patterfloof see https://github.com/chatmail/core/blob/main/standards.md for how delta is based on IETF standards.

  • Copy link
  • Flag this comment
  • Block
maxmoon 🌱
maxmoon 🌱
@utopify_org@veganism.social replied  ·  activity timestamp 3 weeks ago

@delta

Is Delta Chat actually a good messenger if it's about privacy?

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.2 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct