• 13 Posts
  • 2.78K Comments
Joined 6 months ago
cake
Cake day: February 8th, 2024

help-circle





  • SMTP doesn’t allow requiring TLS encryption between email servers

    That means TLS encryption can be defeated by MITM modifying the handshake to say one side simply doesn’t support TLS. Boom, no more encryption.

    Email is not confidential unless you use e2ee, such as PGP.

    Using Proton or Tutanota with coin cards offers no protection here because the problem is coincards. One option is for coincards to let a user enter their PGP key, like facebook supports. Another option is for coincards to hire a security engineer to tell them to stop fucking emailing private keys, and just display them on their website like any other decent gift card vendor.