#AutoCrypt

2026-02-07
#Autocrypt should allow for possible >10d delays.

(Perhaps warn or something I suppose.)

The use-case of snailmail transport of messages isn't necessarily covered in less depending on adverse conditions.

(I am seeing it in the optic of NNCP midpoints & tertiary endpoints that aren't owned by the NNCP nodes necessarily. Perhaps family members or whatever.)
LΞX/NØVΛ 🇪🇺lexinova@cyberplace.social
2026-02-06

@Tutanota will you finally implement autocrypt with their V2 ? PFS and PQC ? i know your own already do this but pgp support would allow us to talk to other people securely not only tuta user or the incredibly not convenient password.

#autocrypt #interoperability #encryption #email #security #eu

2025-12-17

Unverschlüsselte E-Mails von Behörden sind Einbahnstraßen.

Der Staat schreibt mir unverschlüsselt. Ich soll vertrauen. Ich soll reagieren. Ich soll unterscheiden, ob das echt ist oder Phishing.

Technisch ist das nichts weiter als eine Postkarte mit Briefkopf. Jeder auf der Strecke kann mitlesen, kopieren, archivieren. Authentizität: Glückssache. Vertraulichkeit: Hoffnung. Haftung: natürlich beim Bürger.

Hinschreiben darf ich. Antworten auch. Aber einen geschlossenen Kommunikationskreis gibt es nicht. Inbound unsicher, outbound optional. Eine Einbahnstraße – mit Gegenwind.

Dass dabei Phishing explodiert, ist kein Unfall. Es ist Systemlogik.

Die Ironie: Lösungen existieren. Offene. Funktionierende. Autocrypt wäre benutzbar. PGP wäre möglich. Aber offen heißt: nicht kontrollierbar. Also politisch unerwünscht.

Stattdessen: Schulterzucken. „De-Mail ist tot.“ „Wir arbeiten an einer Lösung.“ Seit Jahren.

Man kann keine sichere Kommunikation verlangen, wenn man selbst nur Postkarten verschickt.

#ITSecurity #Behörden #Email #Verschlüsselung #Autocrypt #Einbahnstraße #Fediverse

Wer noch nicht mit Mail-Verschlüsselung arbeitet, könnte langsam mal darüber nachdenken, wenn jetzt der Bundeskanzler von "präventiver Telekommunikationsüberwachung" spricht (riecht nach einem neuen Branding für die Chatkontrolle).

Früher hätte ich jetzt erklärt, wie man PGP mit Thunderbird nutzt. Stattdessen empfehle ich seit einigen Jahren der Usability und Portabilität nur noch
https://delta.chat/de/

Installieren (für alle geläufigen mobilen und Desktop Systeme verfügbar), vorhandene Emailadresse eintragen, fertig.

Die Verschlüsselung ist voll automatisiert nutzbar (man kann weiterhin den bereits existierenden PGP Key verwenden).

Probiert es mal aus, kinderleicht!
@delta

#deltachat #Verschlüsselung #Email #PGP #autocrypt #EinsteigerFreundlich

O Iago :linux: :debian:IGVazquez@vivaldi.net
2025-08-13

Regarding @thunderbird, that is applicable to you too. In support.mozilla.org/en-US/kb/o it is claimed: "Thunderbird does not support the Autocrypt philosophy that encryption should be fully automatic" Well, what is the advantage of an email non-being encrypted, always that the two senders support OpenPGP (and share the public keys) or whatever common encryption method? Of course, if one does not have a public key, I understand it is impossible to make automatic encryption.

Further, I have another question: in the link above claims: 'At this time, Thunderbird doesn't support the "Gossip" feature.'
However, on the Autocrypt webpage, it appears a table where it seems thunderbird supports gossip. (docs.autocrypt.org/dev-status.). Then?

#Autocrypt

Yonhap Infomax Newsinfomaxkorea
2025-07-13

South Korea’s IPO market sees Autocrypt debut on KOSDAQ, with three firms opening retail subscriptions and three others launching institutional bookbuilding this week.

en.infomaxai.com/news/articleV

2025-06-29

@a32 Ich sehe #autocrypt als die realistischste form von email Verschlüsselung die bei vielen Leuten ankommen kann. #DeltaChat basiert darauf, und zeigt das alles was man früher in einem 45min Crypto-Talk zum Verschlüsseln mit Enigmail und Thunderbird machen sollte fast vollständig weg-automatisiert werden kann. Breit aufgestellter software support ist bis eben auf DeltaChat Fehlanzeige. Leider.

docs.autocrypt.org/

delta.chat

Yonhap Infomax Newsinfomaxkorea
2025-06-29

South Korea’s IPO market sees GFC Life Science and NewN AI debut on KOSDAQ, while Autocrypt opens retail subscriptions and four firms set IPO prices via institutional bookbuilding.

en.infomaxai.com/news/articleV

Yonhap Infomax Newsinfomaxkorea
2025-06-22

NuEn AI and Daishin Value REITs launch retail IPO subscriptions this week, while Autocrypt sets its offering price via institutional bookbuilding amid active South Korean capital markets.

en.infomaxai.com/news/articleV

Yonhap Infomax Newsinfomaxkorea
2025-06-01

Kistron, a bimetal wire manufacturer, will list on South Korea's KOSDAQ on June 2, while vehicle software firm Autocrypt begins institutional bookbuilding for its IPO, highlighting robust activity in the country's capital markets.

en.infomaxai.com/news/articleV

Farooq | فاروق [Master Patata]farooqkz@cr8r.gg
2025-05-31

@pixelschubsi @treefit

The point is that DeltaChat didn't invent a new protocol, start something from scratch and write the software for it from the first line. As there is a saying:

Good programmers write programs from scratch. Great programmers find an already existing program and use it as a base.

#DeltaChat didn't invent #Email, #PGP, #autocrypt or new technology for #webxdc. Even WebXDC's real time channels don't use a technology invented by DC.

2025-04-09

In 2014 @matthew_d_green wrote "What's the matter with PGP?" blog.cryptographyengineering.c

We'd like to humbly report completion of its main suggestions. Better late than never! :)

- Key management is automatic through #securejoin and #autocrypt protos

- #chatmail relays form an end-to-end encrypted email enclave interoperable with any e-mail address using proper end-to-end encryption.

- RFC 9580 "cryptorefresh" is rolled out in current releases and will be activated soon.

One to go? ;)

screenshot of a part of the blog post from Matthew Greene:

So what should we be doing? 

Quite a lot actually. The path to a proper encrypted email system isn’t that far off. At minimum, any real solution needs:

[a green verified checkmark on the following paragraph]
« A proper approach to key management. This could be anything from centralized key management as in Apple’s iMessage — which would still be better than nothing — to a decentralized (but still usable) approach like the

o one offered by Signal or OTR. Whatever the solution, in order to achieve mass deployment, keys need to be made much more manageable or else submerged from the user altogether.

« Forward secrecy baked into the protocol. This should be a pre-condition to any secure messaging system.

« Cryptography that post-dates the Fresh Prince. Enough said.

[a green verified checkmark on the following paragraph]

o « Screw backwards compatibility. Securing both encrypted and unencrypted email is too hard. We need dedicated networks that handle this from the start.
Rasheed Ahmedrasheedahmed
2025-03-06

@lns Should but they never will, with good reason. They don't really need to, for email encryption at least there's that non-technical people have a better chance of learning. Yes, it only uses a subset of called , but if you really want to use PGP, there are much better tools than like: , and . I know some of these are front-ends for GPG.

2025-03-06

@qgustavor @adbenitez you can add as many profiles/accounts as you like, some of them can be classic email accounts that can email everyone that uses email, even if they don't support encryption. If they have a client with #autocrypt support (or deltachat), then the conversation is encrypted as soon as they answer you (outgoing messages contain your pubkey, there is no key server).

Go to the profile switcher -> Add Profile -> new profile -> use different server -> classical email login

2025-02-14

@sardon not that we know off. As far as we know thunderbirds current extension model does not allow even an #autocrypt compliant plugin let alone all the rest that delta offers. #enigmail used to offer full autocrypt support but when thunderbird changed the plugin model and integrated openpgp into thunderbird they went back to the old idea of "users have to consciously manage their encryption keys" ... An unfortunate old tradition. We aim for modern usable security like signal delivers.

2025-02-06

看起來 #mailvelope#pgp #autocrypt 的支援還是不行,我看起來 S/MIME encrypt-subject 也都沒有支援?
官網沒有講得很清楚,但 s/mime 的 issue 開著,官網也直接寫不支援加密主旨。
autocrypt 則是寫有做,但又標沒有 web mail provider 支援, autocrypt.org 也沒有列,不太懂是什麼情況,可能要實際用一次。
如果只是 autocrypt header 沒做,金鑰有發布的話還能靠 mailvelope 自家的 key server 找,但不支援 s/mime 的話 autocrypt 也不可能了。
畢竟 mailvelope 是基於 web-mail ,不能直接讀 header,很多功能做不到。
如果有 mailvelope 使用者歡迎補充。

2025-01-01

@ryanleesipes still #autocrypt support 🙃

Islamic Audiobooks Centralislamicaudiobooks
2024-11-07

@hund @coffe I think using and may have solved many of the usability issues with .

People seem to have forgotten (or simply weren't around at the time) that #decentralized #e2ee has been available to the public since the early 90's. It's just that it was too complicated to use for most people. That's where #autocrypt and #delta.chat come in. You can build all the #decentralized and #distributed solutions you want, unless an entity cannot (economically) afford to block it, it will be blocked, no matter what you believe. So stick with #email #smtp #imap and build on that.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst