...Or you could just use https://www.mailpile.is/ , which is a genuinely less painful way to do encrypted email.
Encrypted email is still a pain
381–390 of 450 posts
Re: Encrypted email is still a pain
#382Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…
As you say, it's a problem that's already been solved in the minds of most people, with encrypted messaging apps. Most of the people using that want to hide from a spouse, or their weed dealer from their parents... they don't give a shit if the NSA is snooping.
Until/Unless people get seriously burned, the current trend will continue. A world that is gobbling up the IoT is not ready to learn about encryption.
Re: Encrypted email is still a pain
#383Earlier quoted context omitted.
This also raises the question: With a walled garden like Signal/Wire/etc, how do you get+trust the other's key? Their convenience comes at a cost.
One idea: send them a signal (hi, this you?) then immediately dial their number and confirm.
Re: Encrypted email is still a pain
#384Keybase, Nylas mail plugin. Done. or GPG Tools beta, Mail app, done. or even just the Keybase built in encrypt/decrypt.
I wanted to give this a go, I downloaded nylas but there aint no Encryption plugin or anything. How do you go about configuring it ?
Re: Encrypted email is still a pain
#385Earlier quoted context omitted.
That the NSA cracked, backdoored, or intercepted most providers people trusted but couldnt beat GPG isnt an argument for GPG being secure? I think it's quite an endorsement for GPG given most people's adversaries will be weaker than NSA.
1) I don't take the snowden leaks as gospel, sorry. 2) Even if i did, "most peoples adversary" is a meaningless phrase at this point, and also used quite often as a rhetorical feint to take down someones arg. And given the profound unification of the security state across seemingly all lines, its also dead wrong. Technically everyones adversary is the NSA, as long as data is shared surreptiously and , more and more,…
Don't take them as gospel. That's faith. Review the evidence they're true from U.S. governments' reaction to them to what similar malware was found by third parties. Once evidence is in, then you have reason to believe them and then in stuff such as GPG by extension. And the leaks didn't say anything about faraday cages. Just that they had to rely on the extremely-limited resources of TAO... such as targeted attacks on specific sites/configurations/endpoints... if the target used something strong.
Re: Encrypted email is still a pain
#386Earlier quoted context omitted.
I made this pretty quickly: http://kuuv.io/i/L4rZomr.png Slower than if I just used Python with tkinter since I wanted to learn a new UI framework with Clojure at the same time... But it's literally just a dropdown and some buttons wrapping some system calls to 'gpg'. I never bothered with the 'decrypt file' since I can remember 'gpg --decrypt' easily enough. :) So I agree using GPG isn't very hard, it's easy to make…
A GUI that wraps some system calls is how you end up using "p" for all your passwords. One of the many symptoms of OpenPGP not getting the investment it deserves and sorely needs is that there is no production-quality library implementation going.
Re: Encrypted email is still a pain
#387I wrote a blog post on using mailvelope to send/receive encrypted emails via existing mail providers such as Google mail ... Linked into my post about getting a private/public key pair using keybase.io I'd like to think they explain it fairly well but I hadn't considered the implications of people believing they're more secure than they actually are ... Until I read the comments here - disclaimer: not claiming encryp…
Re: Encrypted email is still a pain
#388Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…
Re: Encrypted email is still a pain
#389Earlier quoted context omitted.
Riot might be a great platform for doing business, but it's pretty useless for any other kind of activity. If you're a political activist having an app called 'Riot' on your phone or computer is not going to look good to anyone in law enforcement.
"having an app called riot" is the absolute least of an actual activists concern when selecting something to help them communicate. One of the most well known leftist platforms for email is riseup.
Re: Encrypted email is still a pain
#390Earlier quoted context omitted.
Totally agree; it's just been my experience that crypto specialists don't care about UX any more than UX people care about crypto.
Whoah. Hang on there. Crypto specialists aren't the people lobbying loudly for PGP-encrypted email in 2017. They're the ones who made the world's most popular messaging application double-ratchet deniably encrypted by default without the userbase even noticing.