• hperrin@lemmy.ca
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    3
    ·
    3 days ago

    Fax machines. Phone lines are pretty private, and sending a fax is usually more secure than emailing something, especially if someone else manages your email.

    • Willard@lemm.ee
      link
      fedilink
      arrow-up
      28
      ·
      3 days ago

      Counterpoint, fax is not encrypted and wire taps are very easy. At least e-mail can be encrypted so Joe shmoe on the street can’t see it.

      Besides, all faxing these days is going through VOIP and computers anyways.

      • hperrin@lemmy.ca
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        2 days ago

        Having to physically wire tap the phone line is a lot more difficult and requires local bad actors. Email’s exposure to the internet makes it easier to hack. Yes, email can be encrypted, but if your server is compromised, that doesn’t matter. End to end encryption for email is much harder, and isn’t really used by any institutions (and usually can’t be because of data retention regulations), so the server has complete access to the unencrypted email in almost all cases. Compromising a fax machine that isn’t connected to the internet is a lot harder.

        Not all faxes go through VoIP. Your everyday home fax machine probably uses VoIP, because having a landline installed in your home is stupid expensive and unnecessary, but faxes in institutions probably use the PSTN. These institutions most likely need landlines anyway, so having a dedicated fax line makes a lot more sense.

        And if a fax goes through VoIP, it’ll be encrypted the same way email is. So in that case, it’s the same level of security as email, which is to say, easier to compromise. At least you can’t trick someone into clicking a link in a fax though.

        • BCsven@lemmy.ca
          link
          fedilink
          arrow-up
          1
          ·
          19 hours ago

          Proton mail is encrypted on the server with your key and proton does not have access to it. If you lose your login credentials and have to reset then you lose your old email because that key is not getting recovered.

          • hperrin@lemmy.ca
            link
            fedilink
            English
            arrow-up
            1
            ·
            19 hours ago

            The email comes into their server unencrypted. They promise that they will encrypt it for you, though. Of course, you’re also relying on the sending server to keep the message secure as well.

            • BCsven@lemmy.ca
              link
              fedilink
              arrow-up
              1
              ·
              9 hours ago

              Proton Mail’s end-to-end encryption and zero-access encryption ensure only you can see your emails. Not even Proton can view the content of your emails and attachments.

              • hperrin@lemmy.ca
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                6 hours ago

                The vast majority of senders do not send email using end to end encryption. If you’re sending an email from a PM address to another PM address, sure, it’s end to end encrypted. If you’re sending to another service, it’s not end to end encrypted unless you’ve both gone through the painful steps of setting up PGP encryption. Same as if you’re receiving from another service.

                You can read about it here:

                https://proton.me/support/proton-mail-encryption-explained

                So that quote you just responded with is saying exactly what I had just said above it. They promise that they’ll encrypt that unencrypted email that just came into their server for you. And they promise that they’ll encrypt that unencrypted email you just sent outside their service.

                • BCsven@lemmy.ca
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  32 minutes ago

                  I know, but I was answering the question about encryption, rather than users. Proton also allows sending encrypted to non participating receivers. They get a weblink and have to open it to view the email a with password if supplied. That decrypts the email at the browser, and has an expiry time on the link.

        • WhyJiffie@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          3
          ·
          1 day ago

          you can choose whatever email provider you trust, and then they apply encryption on the transport level. but there is often very few phone companies, and zero encryption. they don’t have to install any kind of wiretaps, they can just record everything automatically that passes through

          • hperrin@lemmy.ca
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 day ago

            That is true that they have the technical ability to do that, but it is also illegal if they disclose that information to anyone, and it’s unnecessary to run the service, so it simply puts them in a lot of legal jeopardy and adds to service costs.

            https://www.law.cornell.edu/uscode/text/18/2511

            I personally trust AT&T with a fax line a lot more than I trust Google with an email.

            Google specifically discloses that it does record the contents of every email (obviously), and that when you delete an email, it’s not really gone from their servers. AT&T (as well as any phone company in the US) is not allowed to disclose the contents of your phone call or fax without a valid wiretap order (which don’t apply to privileged communications), so they almost never record call content. Keep in mind, email providers must also hand over any emails covered under a valid search warrant.

            So when you send an email, your document is 100% definitely recorded by at least two companies (or one if you use the same provider as the recipient). When you send a fax, it’s highly unlikely that the contents of your document are recorded at all, except on the printed page at the receiving end. It’s just not necessary and puts the phone company at risk, so it doesn’t make any business sense.