Live data from Hacker News

Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

arxiv.org

31–40 of 165 posts

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#31

I mean using (Keybase) https://keybase.io/ is pretty easy

I created an account there and never used it ever again, same for most people I know. Even the rock stars featured there don't seem to be using it. Also, in what world is a cli tool with a git-like interface "pretty easy" outside of the tiny world of computer programmers?

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#32
post #11

I think of it like this: usability can be a security feature. If you build a "perfectly secure" piece of software, but it takes a very high level of skill to use it, your users will use something else that is easier to use, but less secure. And then how has your ideologically perfect piece of software helped improve their security? If you make tradeoffs for usability, you will raise the bar because people will actual…

Fork Thunderbird or some such client, also make a web client available. Make a new service which offers only encrypted e-mail by default (with a new e-mail address that includes e-mail hosting for your own domain) and provides the key server and everything else. Advertise it as something different from e-mail like encrypted e-mail. Set a new precedent, create a new industry.

Unless they can check their email on their phones, it wont take off. Mobile email clients are much more important than desktop nowadays IMO.

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#34
Our approach here is to make security usable to developers via a programmatic interface/API, so users' data is better protected without them having to do anything at all.

https://www.trycryptomove.com

Eventually if/when we think about making consumer-facing wrappers to CryptoMove, the key is going to be usability. Security will need to be as easy/fun as consumer applications. Easier said than done though.

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#35

I mean using (Keybase) https://keybase.io/ is pretty easy

I created an account there and never used it ever again, same for most people I know. Even the rock stars featured there don't seem to be using it. Also, in what world is a cli tool with a git-like interface "pretty easy" outside of the tiny world of computer programmers?

Same here. I set up a Keybase account and never used it. And I'm somebody who actually uses PGP every day.

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#36
post #27

Earlier quoted context omitted.

But who would use it? This study is all about getting the average computer user to use PGP. Most people with webmail accounts won't want to switch back to a desktop client and possibly have to change their email address in order to send & receive secure mail. Besides which, 'make a new client' doesn't answer the main issue, which is how to write a usable client. There are plenty of existing unpleasant PGP clients out…

It has to be an all-in-one solution that you download that has to pretty much do everything for you so your mother can download a file and just go. With a simple wizard that lets you register a new e-mail address and potentially allows you to invite other users via their e-mail addresses... imported from Gmail or something like that. I would not worry too much about compatibility with existing mail solutions or what…

Tutanota (https://tutanota.com/) does that, and even has compatibility with the existing SMTP network. It seems to be web-only at the moment though. I'm pretty sure other systems exist, unfortunately as long as we stay with SMTP nothing will change.

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#37

Real secure encryption is and always will be not user friendly because it means only you can know the private key. This means no "Forgot my password" functionalities, no fancy powerful cloud AI analyzing your data and suggesting cool stuff, no free hosted full text search of your data, no open directory of friends to search on etc. So basically, no gmail, icloud, facebook, dropbox etc. It would require a complete new…

Because I have no interest in memorizing keys, I store them on disk protected by a passphrase. I don't know if this counts as "Real secure encryption" but it's sure a lot more secure than more typical use of email.

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#38
post #8

Earlier quoted context omitted.

Yep! https://www.mailvelope.com/

Did you guys read the paper, or even the abstract? This whole paper is about Mailvelope and the difficulty people had using it.

Maybe that's the joke.

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#39

I think it's easy to pick on a weak example, but much progress has been made since the original "Why Johnny Can't Encrypt". A recent example: Textsecure / Signal has been very, very smooth for me and I doubt it'd be much more difficult for laypeople either: https://whispersystems.org/

Agreed, Whisper is doing this right.

Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

#40

Hey HN, I'm one of the authors on this paper. I'd be happy to answer any questions.

> While our results are disheartening, we also discuss several ways that participant experiences and responses indicate how PGP could be improved.

Have you approached the developers of both Mailvelope and Gmail to discuss these improvements? How did they respond? Also, have you participated in usability discussion with the OpenPGP developer community at large? Any insights?

I ask because it seems like everyone who isn't very active in the OpenPGP developer community thinks that usability is a high priority. But, in my experience, when you start to bring up the topic of user-friendliness in the mailing lists, you get resistance or apathy. It seems like this is a problem of culture and incentives. How can those issues be addressed?

Post reply on HN