• 1 Post
  • 5 Comments
Joined 2 months ago
cake
Cake day: January 21st, 2025

help-circle

  • The issue you’re describing is why I’m not keen on email, and why I mention Signal as an alternative I’ve considered - Signal is a user-friendly way of ensuring both encryption and that meta-data isn’t accessible to providers on either end unless someone’s device is compromised.

    The reason I’m interested in encryption is that I want a higher baseline of security for these orgs. In a changing political landscape it is hard to say what may become sensitive over time. Hypothetically, if one of these orgs is distributing contraceptives internationally we want neither meta-data about who is contacting them nor message contents to be accessible to providers. Since encryption is a pain with email we can assume both are accessible to providers when using that. Ideally I want encryption to be an easy default for both the orgs and the people contacting them.




  • The purpose of the email addresses tends to be something like contact@example.com - it’s the central place outsiders contact the org. A common way to work with it would be that emails are checked during the orgs weekly/monthly meeting, incoming emails are discussed, and someone is tasked with writing a reply with the group’s response to the email. I haven’t seen mailing lists being used for this type of thing, but I guess that could be a solution for the password sharing, but at the cost of having individual email addresses in-house - some type of individual accounts would probably be necessary either way to get away from the whole shared passwords situations…

    The appeal of Signal is that it’s managed and has some level of security by default. My impression of securely configuring email, in particular on someone else’s hardware, is that it is very technically challenging, but it’s also not something I’ve ever attempted. Would you say my impression is correct?

    I’m slowly also realizing that this is probably also a key requirement for a lot of these orgs: they do not have dedicated IT people or a lot of cash. A lot of the time there’s someone with some IT interest, but rarely with time or interest in long term admin-ing.