STARTTLS considered harmful
STARTTLS considered harmful
Posted Aug 18, 2021 5:10 UTC (Wed) by NYKevin (subscriber, #129325)In reply to: STARTTLS considered harmful by gdt
Parent article: STARTTLS considered harmful
Unless you are specifically alluding to E2EE over email with something like PGP (which I personally wrote off as an utterly hopeless endeavor* about five years ago), encryption at rest is an entirely unrelated problem, which each host can solve as it sees fit. There is no reason for the protocol to become involved in the minutiae of how a given endpoint encrypts its files/disks and rotates its keys.
* There's no PKI, there's no reasonable UI or UX, normal people are either unwilling or unable to understand what a "public key" even is, let alone sign other people's keys, https://xkcd.com/1181/, Signal already provides most of this functionality anyway, etc.