Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You can authenticate messages in a way that only the recipient can verify (Diffie-Hellman plus MAC).


If you had access to a public key for every email address then why stop at authentication - you could encrypt all email on the web. But we don't, so we can't.


Authentication in this context doesn't need to be end-to-end. Instead of a custom protocol, we could probably just use SSL client certificates authenticating the sending domain to achieve the same effect.


Maybe we should.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: