Live data from Hacker News

Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

arxiv.org

11–20 of 165 posts

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#11

I think of it like this: usability can be a security feature. If you build a "perfectly secure" piece of software, but it takes a very high level of skill to use it, your users will use something else that is easier to use, but less secure. And then how has your ideologically perfect piece of software helped improve their security? If you make tradeoffs for usability, you will raise the bar because people will actual…

Fork Thunderbird or some such client, also make a web client available. Make a new service which offers only encrypted e-mail by default (with a new e-mail address that includes e-mail hosting for your own domain) and provides the key server and everything else. Advertise it as something different from e-mail like encrypted e-mail. Set a new precedent, create a new industry.

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#13

I think of it like this: usability can be a security feature. If you build a "perfectly secure" piece of software, but it takes a very high level of skill to use it, your users will use something else that is easier to use, but less secure. And then how has your ideologically perfect piece of software helped improve their security? If you make tradeoffs for usability, you will raise the bar because people will actual…

That's the exact line of thinking our lab has been on. Securityusability is a tradeoff, and PGP seems to sit too far on the secure end of the spectrum to be useful to most users. We're working on a way to deliver progressively enhanced security, while onboarding less technical users with more usable features.

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#14
post #11

I think of it like this: usability can be a security feature. If you build a "perfectly secure" piece of software, but it takes a very high level of skill to use it, your users will use something else that is easier to use, but less secure. And then how has your ideologically perfect piece of software helped improve their security? If you make tradeoffs for usability, you will raise the bar because people will actual…

Fork Thunderbird or some such client, also make a web client available. Make a new service which offers only encrypted e-mail by default (with a new e-mail address that includes e-mail hosting for your own domain) and provides the key server and everything else. Advertise it as something different from e-mail like encrypted e-mail. Set a new precedent, create a new industry.

so like hushmail?

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#15
post #14
post #11

Earlier quoted context omitted.

Fork Thunderbird or some such client, also make a web client available. Make a new service which offers only encrypted e-mail by default (with a new e-mail address that includes e-mail hosting for your own domain) and provides the key server and everything else. Advertise it as something different from e-mail like encrypted e-mail. Set a new precedent, create a new industry.

so like hushmail?

No you need to provide a desktop client, open source, by default with everything configured in addition to the service. I guess you should also let users use other IMAP servers but the client should always encrypt all mails it sends out.

Hushmail was always open to court order attack, a desktop client, an open source one, is much less so.

It should always put the name of the client in the subject line or send some unencrypted text along with each message on where they can get a client to view the message. And the client should be able to configure itself with minimal input, sort of like Thunderbird does right now with most e-mail services. And generate, transmit, and store your public key to anyone upon request.

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#16
post #4

This paper should be titled: Why Johnny Still, Still Can't Use Mailvelope: Evaluating the Usability of Mailvelope.

Yes, we probably would have gotten better usability scores if we developed our own PGP client with a better UX and tutorials. We selected Mailvelope because it was rated highly on the EFF's secure messaging scorecard [1] and we were exploring how the state-of-the-art in PGP software actually performed with end users.

[1] https://www.eff.org/secure-messaging-scorecard

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#18
post #4

This paper should be titled: Why Johnny Still, Still Can't Use Mailvelope: Evaluating the Usability of Mailvelope.

Yes, we probably would have gotten better usability scores if we developed our own PGP client with a better UX and tutorials. We selected Mailvelope because it was rated highly on the EFF's secure messaging scorecard [1] and we were exploring how the state-of-the-art in PGP software actually performed with end users. [1] https://www.eff.org/secure-messaging-scorecard

There is a lot wrong with that scorecard, and it's dispiriting to hear that it is actually influencing research.

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#19
post #11

I think of it like this: usability can be a security feature. If you build a "perfectly secure" piece of software, but it takes a very high level of skill to use it, your users will use something else that is easier to use, but less secure. And then how has your ideologically perfect piece of software helped improve their security? If you make tradeoffs for usability, you will raise the bar because people will actual…

Fork Thunderbird or some such client, also make a web client available. Make a new service which offers only encrypted e-mail by default (with a new e-mail address that includes e-mail hosting for your own domain) and provides the key server and everything else. Advertise it as something different from e-mail like encrypted e-mail. Set a new precedent, create a new industry.

But who would use it? This study is all about getting the average computer user to use PGP. Most people with webmail accounts won't want to switch back to a desktop client and possibly have to change their email address in order to send & receive secure mail.

Besides which, 'make a new client' doesn't answer the main issue, which is how to write a usable client. There are plenty of existing unpleasant PGP clients out there, unless you can detail what makes your new attempt better, it will most likely fail as well.

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#20
post #8
post #6

Isn't there a firefox extension that can just do some PGP stuff with some right click in gmail ?

Yep! https://www.mailvelope.com/

Did you guys read the paper, or even the abstract? This whole paper is about Mailvelope and the difficulty people had using it.
Post reply on HN