Zum Inhalt der Seite gehen

Beiträge, die mit chatmail getaggt sind

Suche

Beiträge, die mit chatmail getaggt sind


In 2014 @matthew_d_green wrote "What's the matter with PGP?" https://blog.cryptographyengineering.com/2014/08/13/whats-matter-with-pgp/

We'd like to humbly report completion of its main suggestions. Better late than never! :)

- Key management is automatic through #securejoin and #autocrypt protos

- #chatmail relays form an end-to-end encrypted email enclave interoperable with any e-mail address using proper end-to-end encryption.

- RFC 9580 "cryptorefresh" is rolled out in current releases and will be activated soon.

One to go? ;)
screenshot of a part of the blog post from Matthew Greene:

So what should we be doing? 

Quite a lot actually. The path to a proper encrypted email system isn’t that far off. At minimum, any real solution needs:

[a green verified checkmark on the following paragraph]
« A proper approach to key management. This could be anything from centralized key management as in Apple’s iMessage — which would still be better than nothing — to a decentralized (but still usable) approach like the

o one offered by Signal or OTR. Whatever the solution, in order to achieve mass deployment, keys need to be made much more manageable or else submerged from the user altogether.

« Forward secrecy baked into the protocol. This should be a pre-condition to any secure messaging system.

« Cryptography that post-dates the Fresh Prince. Enough said.

[a green verified checkmark on the following paragraph]

o « Screw backwards compatibility. Securing both encrypted and unencrypted email is too hard. We need dedicated networks that handle this from the start.


Delta Chat es demasiado buena 🔥


Delta Chat es la aplicación de mensajería más revolucionaria que has visto: descentralizada, libre, súper rápida, multiplataforma y con funciones increíbles como juegos integrados, listas colaborativas y más.

Estoy enamorado.

#SoftwareLibre #OpenPGP #criptografía

⏳ CAPÍTULOS
00:00 Introducción
00:16 Aplicación: multiplataforma
00:58 Multi-cuentas
01:31 Crear una cuenta en 10 segundos
01:53 Descentralizado (usa tu servidor o Chatmail)
02:38 Basado 100 % en estándares
04:11 ¡Mini-apps integradas! (juegos, listas, etc.)
05:35 Demo lista de compras colaborativa
06:41 Un equipo muy pequeño
07:30 Y mucho más

🔗 ENLACES:
Web oficial de Delta Chat: https://delta.chat
Sobre chatmail: https://chatmail.at
Un grupo en #DeltaChat sobre el #fediverso: https://i.delta.chat/#C2846EB4C1CB8DF84B1818F5E3A638FC3FBDC981&a=stalebot1%40nine.testrun.org&g=Fediverso&x=PMs39UbcjCSBeT0sQPN4_rZo&i=IoMtoJX6HV3jBX6frhz0Cefi&s=WbLE-SBerSdASeIWMjPY3d_o

¿QUIERES MÁS?
Chequea más vídeos sobre software libre: https://fediverse.tv/w/p/kPKdnevCsK5pmikNCFiXLi

Sígueme en Mastodon: https://mastodon.social/@ivangj

This work is licensed under #CreativeCommons Attribution-ShareAlike 4.0 International


1) Many people want end to end encryption by default and only. Signal has dropped SMS chats three years ago. Mixing cleartext and e2ee is problematic from a usable security pov

2) Several #chatmail operators in repressive situations/environments want to be sure their servers do not contain data that can hurt people. Strictly requiring end to end encryption helps.

3) We use IETF standardized protocols for interoperability and discuss with other MUA devs and help where we can.


#openpgp traditions and #signal both bind a cleartext identifier, phone number or email address, to a cryptographic key. It opens up attack vectors as the servers/orgs controlling this binding can interfere.

#deltachat avoids such cleartext identity bindings by creating random #chatmail addresses, as transport only. The cryptographic key becomes the identifier and we want it hidden from the transport layer. Only people being in end-to-end encrypted chat need to identify each other, after all.


yes, our whole project is about proving in reality (meaning: working code) that email protocols can be streamlined for instant messaging. #chatmail relays provide low latency always end to end encrypted interoperable messaging. The family of #deltachat apps work with the permission free chatmail relay server network but also with run-of-the-mill email servers. Just make sure to use a dedicated chat address and don't mix classic and chat email on the same address.


this is a nice offer! Please note "Delta Chat" is a cross-platform instant messsenger app offering that works with e-mail servers worldwide. #chatmail relay servers are minimal specialized e-mail servers that only relay E2EE-encrypted e-mail. There is a growing community of #chatmail relay operators. If you can provide some free credits for those folks, in exchange for some exposure and publicity for supporting what we call people-sovereign infrastructure, you'd be welcome :)


Free credits for anyone running #chatmail on UpCloud


Inhaltswarnung: CW Messenger Security


Currently testing our new #chatmail server.

WE LOVE IT!

Thanks @delta
It's so simple!

A new project is underway and Chatmail (DeltaChat) will probably be part of it (still testing).

Coming from Matrix, it is a blessing that these options are finally available (see picture)!

#email #messenger #digitalprivacy #privacy #project #OpenSource #digitalsovereignty #deltachat
Shows some deltachat configurations and the deltachat logo. 
Focus on the configuration “Delete old messages” (from the device and from the server) and “ Disappearing messages”.


Thanks for the reply! I created a profile on android in the default #chatmail and I used a new account in my email server (custom domain with infomaniak) for a second profile in mz Linux Desktop to check out how this works. I see #deltachat created a new imap folder in my email server and started adding emails there (as expected).


we always recommend dedicated accounts and not sharing an e-mail address with another e-mail client. For newcomers among your friends, they will then not have to care about an an e-mail address at all but can just use the default onboarding one or other #chatmail server servers. We strive for users not having to *think* about e-mail when onboarding the first time. But if you can create an e-mail address yourself somehwere, by all means, go for it ;)


We beg to disagree a little :) The e-mail system is a very wondrous beast and we are untapping interesting new possibilities with our #chatmail efforts. As to sealed sender/receivers that's entirely possible. However, we prefer to make further arguments in released code when the time comes and stars align ;)


Great stuff! A thorough step-by-step guide for setting up a #chatmail server from @nerdvm
includes also considerations regarding firewall, setting up of ssh and some topics left out of the current main setup guide.

Note that even on a very small server you can easily host 10Ks of active chatmail addresses so if you succeed setting up a server don't be shy letting others know the domain :)

https://blog.lifeupgraded.me/setup-a-chatmail-server-for-delta-chat/


Services that #chatmail adds like "filtermail" run as its own user or as "vmail" if they need to access mailboxes. "echobot" is sandboxed to some extent using systemd.


There is no shortage of startups and enterprises animated by, or outright proclaiming, replacing e-mail as the de-facto open internet messaging standard. VC Investors are forever fascinated by funding such endeavours. #matrix #simplex #slack etc are examples.

#deltachat endorses e-mail but reconfigures and repurposes it to serve for interoperable instant messaging. The #chatmail server network relays end to end encrypted e-mail only, and servers are reduced to dumb store-and-forward relays.


every App allows to create anonymous chat profiles on #chatmail servers. Just hit "create profile"


#chatmail setup docs are here https://github.com/chatmail/server/
if you hit any problem feel free to open an issue in the same repo.

Popular problems:
- DNS settings (a zone file is provided but most providers don't allown importing)
- getting your hosting provider to allow sending and receiving to/at port 25


Yes, building magic wormhole with iroh direct connections would be cool! Currently magic wormhole traffic is all relayed via a server AFAIK.
Iroh is open source, and you can self-host a relay. And iroh runs on mobiles. E.g. @delta does all of those things and integrates an #iroh relay in their #ChatMail server. And #DeltaChat runs on mobiles.


You don't have to install the server, you can use a public #chatmail server or setup a normal email server with e.g. @doncow if you want to self-host your email. You can also setup a #chatmail server just for yourself and then close new account registration if you don't want to offer it as a service for others but want to have push notifications working.


it's still an evolving discussion. World-wide, multi-device setups are an edge case. On the fediverse, single-device-only is an edge case likely.

FWIW introducing some form of multi-device P2P syncing (preferably without requring that both devices are online -- there are actually ways to achieve that) would mean that #chatmail servers can always remove delivered mails, further minimizing costs of operating a chatmail server which is already exceptionally cheap.


#chatmail if a single device setup is used end-to-end encrypted message get removed after the app downloaded it. The situation is different for multi device setups, right?


#chatmail servers do not keep persistent logs, and only the end-devices have the readable messages of a conversation. Servers briefly see an end-to-end encrypted message but it gets removed after the app downloaded it.


The downside of our project approach was that we often got experts being very dismissive on re-using email and #OpenPGP ... and there still is some opposition which often subsides when actually trying #deltachat and #chatmail, looking at security audits and our strong usable security focus.

There may also be surprising upsides. The UK "Online Safety Bill" which attacks end-to-end encryption integrity seems to not apply for ... e-mail. Because everyone knows, e-mail is unencrypted, right? :)
screenshot of page 7 of https://www.legislation.gov.uk/ukpga/2023/50/enacted

CHAPTER 7Interpretation of Part 3
55“Regulated user-generated content”, “user-generated content”, “news publisher content”

(1)This section applies for the purposes of this Part.

(2)“Regulated user-generated content”, in relation to a regulated user-to-user service, means user-generated content, except—

(a)emails,

(b)SMS messages,

(c)MMS messages,

(d)one-to-one live aural communications (see subsection (5)),

(e)comments and reviews on provider content (see subsection (6)),

(f)identifying content that accompanies content within any of paragraphs (a) to (e), and

(g)news publisher content (see subsection (8)).


we work with the assumptions stated here https://github.com/chatmail/models/tree/main/group-membership#assumptions and those include that the group-id is secret and only known to the members. #Chatmail servers never see the group id as it is transmitted in the end-to-end encrypted part of messages between peers.


@titaniumbiscuit not all classic e-mail providers work equally well but many do. Since #chatmail entered the global e-mail server network 14 months ago, and we introduced instant-onboarding april 2024, we de-emphasize #gmail #outlook and #iCloud and don't perform "free" work to help them continue to dominate. Instead we put our energy into growing the chatmail server network which does away with spam/rate-limit problems by design. Everything is based on #interoperable #cryptography .


@bjoern Seit April 2024 ist die Benutzung sehr einfach geworden, als "instant onboarding" mit hilfe von #chatmail servern hinzufügt wurde, und auch sonst viele UI Verbesserungen eingeführt wurden. Ein 3rd party Erfahrungsbericht: https://gladtech.social/@avoca/114097638574628729 und dann gibts noch mehr beim #deltachat hashtag


With #deltachat #chatmail and #webxdc developments we aim to instigate a new modern foundation for secure E-Mail and a resilient Web without platforms. We are building a kind of #minecraft system for modern decentralized messaging.

But who are we building it for?

For all who need reliable trustable means of modern private communication.

While our work needs hackers and experts it's not designed for them. @tante raises interesting and important related thoughts https://tante.cc/2025/03/03/who-is-free-software-for/


https://arcanechat.me server reached 1500 users!!!

the server is using around 1GB of RAM, CPU is almost unused, and only 1.4GB of storage used for encrypted user volatile data, that is around 1MB per user on average!

the cost of self-hosting a #chatmail server for #ArcaneChat / #DeltaChat is really low! and you don't even need to trust the server operator or even the VPS provider if you are selfhosting since all is #e2ee and safe against #mitm thanks to the green checkmark in chats


#deltachat community milestones:

Dec 2023: first #chatmail server

Feb 2024: iOS push notifications

March 2024: ETH Zuerich #security analysis

June 2024: Instant onboarding on all clients

Nov 2024: #P2P #webxdc realtime and home-screen apps

Dec 2024: rPGP #security audit, 20 known #chatmail servers world-wide

Jan 2025: new #webxdc store, UI integrated app-picker, webxdc push notifications.

Spring 2025: is coming :)

money used: ~600K EUR, a tiny amount compared to other messengers.


-- es gibt eine grosse Auswahl an e-mail und #chatmail servern, die von unterschiedlichgen gruppen und firmen betrieben werden, und ein eigener mail-server oder eine addresse bei einem massen-hoster geht auch. Zudem sind alle Nachrichten in der Regel ende-zu-ende verschlüsselt inklusive der meisten metadaten wie gruppenname, avatar, memberlist etc.


Delta Chat leaks exactly this metadata today:

- Message-date,
- Sender/Recipients (*),
- the size of the message.

(*) Newly onboarding #chatmail users get random e-mail addresses so Sender and Recipients do not tell you anything about the (passport) identity behind it.


to bring push notification also to the fdroid installations #chatmail server should support #unifiedpush.


10 Million push notifications for #chatmail messages were delivered in the last 30 days, up from 3 Million half a year ago.

F-droid installs do not use push notifications, and classic e-mail users also do not use push notifications. These usages are therefore not contained in the number which therefore marks a lower bound on number of messages delivered.

For more info on push notifications and instant message delivery, and also on privacy and security concerns, see https://delta.chat/en/help#instant-delivery
A diagram titled "Direct notifications for the last day" 

X axis covering last 24 hours

Y-axis number of notifications.  

Android had 202205 and Apple 102392


every #chatmail server has an echo@ bot that will reply with a copy of your message and usually fast :)


No coins, no chains, no big machinery but plain, efficient and scalable decentralization, leveraging the largest open internet messaging network ever created by humans ... made safe, fast and resource efficient with #chatmail servers using strong and audited #interoperable #cryptography. It just works (tm) in many places where Signal and WhatsApp fail today. It's time to reclaim "decentralization" from techbros, insist on real-life #resilience and trust this cute figure from @Xeniax :)
A photograph of a small blue figure with a mask, holding a little "decentralized" handwritten banner with "d" being the delta logo symbol.  Background of the photo is a forest and a lake in early spring.


There is a new #chatmail server deployment using #chef tooling, put together by @feld , incorporating the same "chatmaild" services used by the mainline chatmail server template, and also otherwise achieving feature-parity ... Thanks Mark!

https://github.com/feld/chatmail-cookbook


The #chatmail #fosdem talk from @compl4xx is public. It goes into topics such as

- why chatmail servers?
- how to setup a server with your child
- (avoiding) spam filtering
- metadata and guaranteed end to end encryption in #deltachat
- #cryptographic #interoperability for email message routing

Thanks to attendees for the great energy even if was the last talk on the day and also for questions and conversations afterwards!

https://ftp.fau.de/fosdem/2025/k4601/fosdem-2025-5217-chatmail-server-networks-for-anonymous-end-to-end-encrypted-messaging.mp4


the quoted post does not well reflect what delta chat is today. Since end 2023 there are #chatmail servers and since april 2024 anonymous onboarding on chatmail servers is directly integrated. A pre-existing e-mail address is not needed. Messages in the growing chatmail server network are always end-to-end encrypted as clear text messages are not relayed. For any security-related discussion, we suggest to keep this new reality in mind.


Seguint amb el meu enamorament per #DeltaChat, increïble de ràpid enviant fotos de molt alta resolució, un segon ha trigat des del servidor per defecte al meu servidor, una foto de 24 Mpx amb una resolució de 5712 x 4284 i 2,8 MB d'espai en disc.
Es nota molt que el servidor #chatmail està molt optimitzat per a que sigui tant ràpid com les apps de missatgeria tradicional.