I'm giving up on PGP
blog.filippo.io
I'm giving up on PGP
1–10 of 350 posts
Re: I'm giving up on PGP
#2Re: I'm giving up on PGP
#3It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "power users" that will drop the theoretical best practices and switch to fallback, unsecure modes, given the effort needed to properly verify a key binding. If the community that cares about encryption and privacy is not able to routinely verify keys, the whole system definitely has a weak link.
I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here.
And to me, assuming that the most usable thing we can use instead is something that relies on mobile phone identifiers, more often than not tied to a phisical world identity, is really something to worry about.
Re: I'm giving up on PGP
#4Dark Mail seems to be dead. Are there any efforts to make e-mail secure by default and e2e encrypted?.
- https://pixelated-project.org/
- https://modernpgp.org/memoryhole/
- https://inbome.readthedocs.io/en/latest/
Edit: btw, if you're in Berlin from 14-18 Dec, drop by the AME2016 unconf+hackaton https://github.com/mailencrypt/ame2016
Re: I'm giving up on PGP
#5Re: I'm giving up on PGP
#6Dark Mail seems to be dead. Are there any efforts to make e-mail secure by default and e2e encrypted?.
Re: I'm giving up on PGP
#7Dark Mail seems to be dead. Are there any efforts to make e-mail secure by default and e2e encrypted?.
Re: I'm giving up on PGP
#8Dark Mail seems to be dead. Are there any efforts to make e-mail secure by default and e2e encrypted?.
My recommendation here is Signal: https://whispersystems.org/
Re: I'm giving up on PGP
#9Even if the remote person doesn't know they are talking to you (as a human entity), they know they are talking to the combined online persona of all those accounts, which is all that matters for the vast majority of them. Yes, it is possible for all these services to collude and post false proofs, but that would be relatively easily detectable, and realistically not a concern for the majority of people out there, whose alternative is to not use any encryption. People who are really concerned can always fall back to standard PGP.
[Edit: Looks like I didn't read the article carefully enough, the author himself says he actually does use Keybase too.]