At the moment, I use the Mailvelope extension. https://www.mailvelope.com/ Excellent in Chrome - a bit slow in Firefox.
It wraps around your existing gnupg installation.
11–20 of 51 posts
At the moment, I use the Mailvelope extension. https://www.mailvelope.com/ Excellent in Chrome - a bit slow in Firefox.
It wraps around your existing gnupg installation.
I tried to use gnupg but can't wrap my head around the web of trust. My main concern of WoT: What my signature of an other guy's public key actually means? My takeaway is that there is an implicit statement that you sign, but I don't really know what it is. According to the gnupg privacy handbook[1] this statement is roughly "I trust that this guy can properly sign other stuff" which is kind of recursive, but I like…
Regarding changing the uid, your scenario cannot happen (if I understand it correctly): you sign uids, not the keys themselves. That means you can sign specific uids. If they delete it and add another uid, it's not signed anymore. (also you can revoke signatures if someone starts misbehaving)
I tried to use gnupg but can't wrap my head around the web of trust. My main concern of WoT: What my signature of an other guy's public key actually means? My takeaway is that there is an implicit statement that you sign, but I don't really know what it is. According to the gnupg privacy handbook[1] this statement is roughly "I trust that this guy can properly sign other stuff" which is kind of recursive, but I like…
- re. multiple identities. cross-Signatures in the web of trust are done on individual identities, not the master key! So if you sign an identity and the key owner then creates another, that new identity will not carry your signature.
- re. key parties: so far it wasn't an issue because it was implicitly assumed that people attending a key parting were savvy enough to understand how to sign. For PGP to be democratized the concept of key party needs to evolve. I personally combine them with a small lecture on PGP use, and say "you get to sign each other only if you have attended the lecture including its small practical".
- re. software keys. These are typically considered as an extension to the developers' keys. You as a user shouldn't sign those.
What is so terrible for people about using an email client? I find using the Gmail web interface to be frustrating because they've removed the ability to pop out the compose view into it's own window, so I can't easily reference information in another browser tab while writing an email for instance. Meanwhile, Gmail has excellent IMAP support, which lets me use Thunderbird + Enigmail to get excellent PGP support.
The fact that all this is the same on my Macbook Pro, on my Arch Linux desktop, or when I reboot to Windows, without any effort on my part to synchronize settings makes this all rather excellent.
What is so terrible for people about using an email client? I find using the Gmail web interface to be frustrating because they've removed the ability to pop out the compose view into it's own window, so I can't easily reference information in another browser tab while writing an email for instance. Meanwhile, Gmail has excellent IMAP support, which lets me use Thunderbird + Enigmail to get excellent PGP support.
Also, I'm sending 90% of emails from my phone anyway and I don't know of any good client that works both with gmail (with transparent caching of recent/viewed messages) and gpg.
I tried to use gnupg but can't wrap my head around the web of trust. My main concern of WoT: What my signature of an other guy's public key actually means? My takeaway is that there is an implicit statement that you sign, but I don't really know what it is. According to the gnupg privacy handbook[1] this statement is roughly "I trust that this guy can properly sign other stuff" which is kind of recursive, but I like…
I don't think pgp ever can provide validation that some person owns some email address. You're signing the uid/address on a key which people prove they control. You can ask them to send you a signed message from that address to prove it, but if they owned someone's key, they likely have access to the email too. Even if they don't emails are still very easy to spoof. Regarding changing the uid, your scenario cannot ha…
Email address spoofing is too easy, I don't think that "owning" an email address is reasonably verifiable.
I wasn't aware that people sign each others uid. What happens if someone's name legally changes? Does he/she have to rebuild his/her WoT? Of course you can send out an email from your old id that you name is changing.
What is so terrible for people about using an email client? I find using the Gmail web interface to be frustrating because they've removed the ability to pop out the compose view into it's own window, so I can't easily reference information in another browser tab while writing an email for instance. Meanwhile, Gmail has excellent IMAP support, which lets me use Thunderbird + Enigmail to get excellent PGP support.
My main issue is that search and labels just don't work as well as in gmail webapp. Also, I'm sending 90% of emails from my phone anyway and I don't know of any good client that works both with gmail (with transparent caching of recent/viewed messages) and gpg.
What is so terrible for people about using an email client? I find using the Gmail web interface to be frustrating because they've removed the ability to pop out the compose view into it's own window, so I can't easily reference information in another browser tab while writing an email for instance. Meanwhile, Gmail has excellent IMAP support, which lets me use Thunderbird + Enigmail to get excellent PGP support.
I tried to use gnupg but can't wrap my head around the web of trust. My main concern of WoT: What my signature of an other guy's public key actually means? My takeaway is that there is an implicit statement that you sign, but I don't really know what it is. According to the gnupg privacy handbook[1] this statement is roughly "I trust that this guy can properly sign other stuff" which is kind of recursive, but I like…
- re. anonymous keys. There is no need for them to be part of the web of trust. If you really want them there it is then a common requirements for signatories to require at least a verifiable e-mail address bound to the person they know and are authenticating. But then arguably it's not very anonymous any more. - re. multiple identities. cross-Signatures in the web of trust are done on individual identities, not the…
It's not only about being savvy though. You trust the person to not misuse his/her key unknowingly or knowingly. If you only use marginal trust on a key signing party then it can be mitigated somewhat though. What's the usual trust level used on such a party?
Edit:
Then the Putty master key is misused according to you: https://pgp.mit.edu/pks/lookup?op=vindex&search=0x4F5E6DF56A...
With today's hacks and the total state of surveillance in which we are in, it's a little crazy to expect people to use the same key 10+ years without it getting compromised. Even a year seems too much.