That’s the reason we have to still use fax machines right?

I know there are ways to do encryption like PGP on your message directly or I think email sent over TLS? But that isn’t the default right and that’s why I can’t send a picture of my license to the insurance company directly over email?

64 points

Lol no, faxes do not have encryption. However, they are transferred over old school phone lines, which are not exposed to the internet, therefore making them harder to intercept. Also, federal wire tap laws are pretty beefy so risk in doing so is higher. That’s pretty much it though

permalink
report
reply
31 points

therefore making them harder to intercept.

You mean far, far easier to intercept? You used to be able to just stick a coil around the wires.

The main issue is just a lot of countries governments’ don’t trust computers still. In Germany they insist on fax and post as it’s the only thing they can use as proof of signature in court, etc.

But it’s government laws and regulation that is behind. It’s not so much of a technical problem (although E2EE email standard would be nice!).

permalink
report
parent
reply
30 points

“Harder to intercept” as in you have to go outside where the grass is to play around with the telephone wires, as opposed to typey-typey in your mom’s basement. Ain’t nobody got time for that

permalink
report
parent
reply
5 points

It’s the same though.

To intercept the email you need to be on a network that receives it (i.e. ISPs).

It being stored unencrypted is a totally different problem (and also for letters, faxes, etc.)

permalink
report
parent
reply
4 points

But it’s government laws and regulation that is behind. It’s not so much of a technical problem (although E2EE email standard would be nice!).

No. Government had nothing to do with it, these are separate issues. WhatsApp was never approved by the government, yet it’s widely used and it has E2E. OTOH, German government accepts email for lots of things. I know of some public sectors requiring email with PGP even.

The actual problem is that both email and PGP are really bad. This on my opinion describes it very well: https://latacora.micro.blog/2019/07/16/the-pgp-problem.html https://latacora.micro.blog/2020/02/19/stop-using-encrypted.html

permalink
report
parent
reply
3 points

On top of that these days most phone calls are routed over the internet at some point too.

permalink
report
parent
reply
1 point

Well, how do you proof an email has been delivered if you don’t get a confirmation? That’s the main problem when going to court.

permalink
report
parent
reply
4 points

Yeah, this is a pain with faxes and letters too though - I had first-hand experience in Germany unfortunately.

permalink
report
parent
reply
2 points

Would be interesting to require read receipts to be on.

permalink
report
parent
reply
1 point

You can’t without the logs from the recipient server.

permalink
report
parent
reply
8 points

Phone systems are all digital these days. A phone tap is easier than ever, and in higher quality.

Also playing back the sound of a fax can reproduce a fax, with the right tools.

permalink
report
parent
reply
6 points

Most companies now use fax severs which use the same SIP trunks that phone calls to the business use. Even if they are using old POTS lines the fax machines themselves are usually not in a secure area, but out in the open where anyone can walk by and pick them up.

I had to have a discussion with our cyber group that didn’t understand this and insisted that we encrypt our digital fax sever. I tried many ways to convince them that it simply was not possible to encrypt faxes when we were getting or sending faxes to random people in the general population. It really tested my patience and my ability to stretch the truth so they would drop their idiotic request.

permalink
report
parent
reply
26 points

Fax isn’t encrypted. What keeps it alive is just inertia.

As for why your insurance company won’t take emailed photo, that probably has more to do with whatever system your insurance is using for their backend.

Email content can be end to end encrypted by GPG and S/MIME as well as through a few other standards. Email in transit can be (but not always is) encrypted via TLS.

The reason encryption is not default is because (I think) of backwards compatibility. E-mail originated at a time when almost nothing electronic was ever encrypted, including the username and password you used to log into a system with. Most of the encryption we use of today has simply been “bolted on” to standards that were already in place at the time and it did take a few tries to get it right.

When the internet was first getting started, few people, if anyone, thought it would become as invasive (possibly the wrong word) as it has become. Everyone on the net knew each other. They were friends, why would they ever need to hide anything from each other. /s

That and the early systems couldn’t really spare the processing power for encrypting and decrypting things.

permalink
report
reply
4 points

Insurance won’t take it because no one is going to work hard to make sure you get paid.

permalink
report
parent
reply
2 points

Yeah, but you can just deny email that hasn’t got TLS. Many businesses that do business with eachother do this by creating rules in their mailserver.

permalink
report
parent
reply
20 points
*

It’s very easy to E2E encrypt stuff you’re sending via email: zip it up in a password protected archive. Even the email client won’t know what it’s sending.

And even if that isn’t good for whatever reason, there’s no reason to use email. A web form via https is secure and encrypted, and cuts out the email middleman.

That’s not the reason we still use fax machines. The reason we still use fax machines is because someone very old and set in their ways is the one in charge of making the decision to move away from fax machines.

permalink
report
reply
1 point

How secure are password protected zip files?

permalink
report
parent
reply
2 points

Zip files aren’t very secure by default, however you can specify better encryption with better zipping tools. It would be more accurate to say you should put the content into an encrypted archive file.

permalink
report
parent
reply
1 point

Probably shouldn’t have been so specific, as I don’t know how deeply encrypted zip files can be in terms of bits. Broadly speaking, there is definitely some kind of encrypted archive file that would be secure when sent over email

permalink
report
parent
reply
14 points

PGP is already that answer. We just need a common trusted CA. It would be nice if the government did this and issued certs with your driver license or ID. We could replace our reliance on SSNs with actually good cryptography.

permalink
report
reply
16 points

Trust the government to link security certs with your ID? No thank you

permalink
report
parent
reply
5 points

We have that already in Belgium. It’s been a while. It’s used to authenticate for government services or sign stuff. Why the hate?

permalink
report
parent
reply
13 points

trusting the government with certs to access data they’re providing you == good

trusting the government not to listen to every email and website you ever visit and then not use that data to lock up dissidents. == bad

permalink
report
parent
reply
1 point

You have clearly not met the ineptitude British government.

permalink
report
parent
reply
12 points

I’m sure there is a much more sophisticated explanation from the lawyers’ end, but more fundamentally, I’m pretty sure that encryption is not part of the basic protocol. Privacy is not actually a basic feature of the internet, so something as basic as email does not include it. Anything that uses email to do private coms would have to be referred to as ________ over email.

PGP/GPG has been around as an option since the 90s, but it’s rather clunky to implement and you need to know how to keep your private key safe. So, the problem has long been functionally “solved” for the competent, and there we stay; you and anyone you want to talk to privately will always be free (possibly not legal, but free) to generate a key pair each, share your public keys, and then talk privately using those keys for as long as you can keep your private keys safe.

And really, I personally find the idea fairly silly, that some company is going to keep my key for me and respect my privacy. No, if someone wants to keep your private key for you, they want to know your business, all of it. You don’t ask to hold anyone’s keys anymore than you ask to hold their johnson for them when they piss. I do use some corporate encryptions, signal for things I don’t want the DEA to know about mainly. Oh also FUCK THE DEA

permalink
report
reply
4 points

anymore than you ask to hold their johnson for them when they piss

Noted.

permalink
report
parent
reply

Ask Lemmy

!asklemmy@lemmy.world

Create post

A Fediverse community for open-ended, thought provoking questions

Please don’t post about US Politics. If you need to do this, try !politicaldiscussion@lemmy.world


Rules: (interactive)


1) Be nice and; have fun

Doxxing, trolling, sealioning, racism, and toxicity are not welcomed in AskLemmy. Remember what your mother said: if you can’t say something nice, don’t say anything at all. In addition, the site-wide Lemmy.world terms of service also apply here. Please familiarize yourself with them


2) All posts must end with a '?'

This is sort of like Jeopardy. Please phrase all post titles in the form of a proper question ending with ?


3) No spam

Please do not flood the community with nonsense. Actual suspected spammers will be banned on site. No astroturfing.


4) NSFW is okay, within reason

Just remember to tag posts with either a content warning or a [NSFW] tag. Overtly sexual posts are not allowed, please direct them to either !asklemmyafterdark@lemmy.world or !asklemmynsfw@lemmynsfw.com. NSFW comments should be restricted to posts tagged [NSFW].


5) This is not a support community.

It is not a place for ‘how do I?’, type questions. If you have any questions regarding the site itself or would like to report a community, please direct them to Lemmy.world Support or email info@lemmy.world. For other questions check our partnered communities list, or use the search function.


Reminder: The terms of service apply here too.

Partnered Communities:

Tech Support

No Stupid Questions

You Should Know

Reddit

Jokes

Ask Ouija


Logo design credit goes to: tubbadu


Community stats

  • 11K

    Monthly active users

  • 4.3K

    Posts

  • 233K

    Comments