> PGP needs to be as simple as the SSL Lock in a browser if there is to ever be any hope of widespread adoption.
Something like the level of confidentiality feature in (soon to be) caliopen[1]:
>>
What is behind the idea of confidentiality level?
In Caliopen, every element has its own "confidentiality level" which tells the user what is the security level for any contact or message or conversation...
Each terminal declared by the user is graded according to its use (e.g. strictly personal, at home or as a public access within the enterprise), its type (a phone is necessarily less secure than a desktop PC, as it is much easier to loose). When used for the first time, a non declared terminal receives a note of zero.
Incoming messages are rated whether they are or not encrypted, and also according to the type of encryption key. The type of transport (secured or not) influences the rating as well as confidentiality level associated to the related contact if it is known. The algorithm that rates a conversation is more complex, but takes into account all described elements.
For a user's contact, the confidentiality level is equal to the global confidentiality level of this contact's account: this global confidentiality level is the only public element of a CaliOpen account.
Finally, every CaliOpen instance should eventually geWhat is behind the idea of confidentiality level?
[1]: https://caliopen.org/