Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
amilich
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
amilich
11mo ago
Hey - really sorry to hear this - could you email me andrew@cursor.com? Here are 3 suggestions to try- 1. Reset your settings.json - if shared with vscode, sometimes settings can cause perf regressions 2. Could you try cmd-shift-p -> &qu
2.
▲
by
amilich
3y ago
Thanks for sharing! PGP support has been a huge request and enables end-to-end encryption automatically between large email providers for one of the first times we know of.
3.
▲
by
amilich
3y ago
It's enough of other companies making money on our data. That's why I started Skiff (end-to-end encrypted email/docs/drive/calendar)! It's harder to build products E2EE but you get long-term trust from users.
4.
▲
by
amilich
3y ago
Hello :) Skiff cannot access email content, subject, and header info. To/from/cc/bcc fields are not stored end-to-end encrypted, though.
5.
▲
by
amilich
3y ago
Few notes - iOS issue stems from a recent upgrade from an iframe to a webview. It's fixed on all mobile apps and versions. - All DMARC-failing mail does go to spam. - Caching images on receipt was examined but deemed impractical. It b
6.
▲
by
amilich
3y ago
Thanks for the report. I am investigating this now.
7.
▲
by
amilich
3y ago
I just compared Skiff and Tutanota on your tool. The results were the same. Thank you for confirming this.
8.
▲
by
amilich
3y ago
It's very simple. One of them had access to user's private keys (Lavabit). One never has access to user private keys (Skiff).
9.
▲
by
amilich
3y ago
That's why Skiff has had 4 security audits, not just 1 3 years ago. And, with multiple of the best auditors.
10.
▲
by
amilich
3y ago
No, I'm not joking. We do have this option, and it's consistent with the defaults across private mail providers. Still waiting for your list of the ones that don't load images by default. It does not load the images. That
11.
▲
by
amilich
3y ago
Any security engineer would have a heart attack if any employee, friend, or colleague said "security audit stuff [doesn't] matter." I wouldn't use software that doesn't undergo security audits. Also, pentest ≠ audit
12.
▲
by
amilich
3y ago
Actually, that's completely false. Security audits are a standard, reputable process for software. Trail of Bits is probably the best (or one of very few top) firms in this category. Check out: https://github.com/trailo
13.
▲
by
amilich
3y ago
That's just false. Downloading crypto libraries over the web plagued Javascript crypto for years. We use tweetnacl, stablelib, and webcrypto - and tweetnacl also uses webcrypto!
14.
▲
by
amilich
3y ago
Yes - privacy focused mail providers offer this as an option but do not enable it by default. Mainstream mail providers do not even have it as an option.
15.
▲
by
amilich
3y ago
We use an open-source mailserver (Haraka), but security audits are the most trustworthy way to do this. We've had 4: skiff.com/transparency. Audits cover infrastructure.
16.
▲
by
amilich
3y ago
What mail providers block all remote content by default?
17.
▲
by
amilich
3y ago
Skiff encrypts all received emails with user public keys immediately on receipt. This is quite clear in our security model page and whitepaper. Skiff does not have access to any user emails, including external received ones.
18.
▲
by
amilich
3y ago
No: Skiff does not have access to a single email stored on our platform, including ones received externally. All are public-key encrypted, including subjects and content.
19.
▲
by
amilich
3y ago
We also don't do this. In a near future implementation you can just synchronize the end-to-end encrypted search index.
20.
▲
by
amilich
3y ago
This sounds like a possible captcha error. Can you email me at andrew (at) skiff.com ? Sorry about this.
21.
▲
by
amilich
3y ago
We offer a block remote content feature. There is no foolproof way to load any remote content without possibly exposing email open information.
22.
▲
by
amilich
3y ago
See https://skiff.com/transparency , Trail of Bits has performed 2 audits, Cure53 1 audit, and we had an additional audit 2.5 years ago.
23.
▲
by
amilich
3y ago
No, this is done with public-key encryption which does not require the client.
24.
▲
by
amilich
3y ago
Those ads are still targeted to you, maybe not off of your email content (now vs 2017)
25.
▲
by
amilich
3y ago
Before this basic cryptography was downloaded via JS files which yields no security and gave web cryptography a bad reputation. That is not true now.
26.
▲
by
amilich
3y ago
We do have export to EML and ZIP files. SMTP/IMAP are not trivial due to end-to-end encryption.
27.
▲
by
amilich
3y ago
Also, not really true of Gmail. Try turning your WiFi off, then deleting your Gmail account. You might have mail stored offline on your phone (let alone any other device), as well as any IMAP or other clients. It's the same or worse.
28.
▲
by
amilich
3y ago
Emails are downloaded when you receive them. Isn't that how email works?
29.
▲
by
amilich
3y ago
Darn. Will have to fix it. Thanks.
30.
▲
by
amilich
3y ago
This isn't how it works at all? We don't pay for storage on users devices... buying the device = buying the storage. It's actually much more efficient than doing search through some massive database.
More ›