Live data from Hacker News

GPGMail 2 is finally here

gpgtools.org

51–60 of 77 posts

Re: GPGMail 2 is finally here

#51

Email encryption is a good start! Personally, I think, the user is best served with the "darknet" [0] approach. It's unfortunate that term "darknet" leads a big chunk of the general public to believe it's something "dirty", "illegal" or otherwise undesirable or even dangerous, which doesn't help its cause. So help the Internet out and spread the word: [0] http://en.wikipedia.org/wiki/Darknet_%28file_sharing%29 RetroS…

The perfect is the enemy of the good.

Now I'm curious about how you're applying this to the current context... Care to explain?

Re: GPGMail 2 is finally here

#52
post #33
post #19

My company's internal mail goes through gmail so I decided after recent news to setup GPGmail and s/mime. I identified a couple of usability issues, which where fixed. I'd say all in all its very good. Regardless if you believe or care about the NSA issues, simply the idea of routing clear text email through mail exchanges, and advertisers should give you enough reason to follow the few steps it requires to generate…

Any recommended CAs for S/MIME for personal users? And is it possibly to transparently use both, e.g. sign all outgoing mail with S/MIME by default, but also encrypt with, say, GPG if you happen to have that contact's public key?

No. You absolutely must confirm the key of people you correspond with. An internal CA in your organisation could achieve this, but the "trust a random list of CAs" model of security is fragile, and must be considered compromised in the face of an adversary like the NSA (or any government in a country where a CA on your trusted list is located).

Re: GPGMail 2 is finally here

#53

Earlier quoted context omitted.

The perfect is the enemy of the good.

Now I'm curious about how you're applying this to the current context... Care to explain?

He likely means that email encryption (the good) is incrementally achievable, while RetroShare and Darknet (the perfect) requires a much more disruptive change.

Re: GPGMail 2 is finally here

#54

Earlier quoted context omitted.

Now I'm curious about how you're applying this to the current context... Care to explain?

He likely means that email encryption (the good) is incrementally achievable, while RetroShare and Darknet (the perfect) requires a much more disruptive change.

Ok.

I'd just like to add to that:

Very serious attacks on democratic principles have been carried out behind our backs, for a very long time, apparently.

That is why I think, in order to counter these threats to society appropriately, disruptive approaches should really be welcomed and preferred as often as possible.

And then, of course, it's not an either/or question. Both should be promoted alongside, as lots of different people have lots of different needs/requirements. (Personally, I use both RetroShare and encrypted email, and migrate as many people as possible over to total encryption as soon as possible.)

Re: GPGMail 2 is finally here

#55

Earlier quoted context omitted.

He likely means that email encryption (the good) is incrementally achievable, while RetroShare and Darknet (the perfect) requires a much more disruptive change.

Ok. I'd just like to add to that: Very serious attacks on democratic principles have been carried out behind our backs, for a very long time, apparently. That is why I think, in order to counter these threats to society appropriately, disruptive approaches should really be welcomed and preferred as often as possible. And then, of course, it's not an either/or question. Both should be promoted alongside, as lots of di…

Email encryption is going to be effective against 99% of relevant attacks, and if the NSA wants to know what you're doing, they'll put a bug in your laptop and, no, you won't notice.

Remember, even with lofty "serious attacks on democratic principles" going on, you're still infinity times more likely to have your bank account information stolen by drive-by script kiddies with a 0-day than be a target of government persecution on the back of illicitly obtained intelligence. Even then, it's highly unlikely that even the NSA has the capacity to decrypt internet traffic at scale.

Re: GPGMail 2 is finally here

#56

Earlier quoted context omitted.

Now I'm curious about how you're applying this to the current context... Care to explain?

He likely means that email encryption (the good) is incrementally achievable, while RetroShare and Darknet (the perfect) requires a much more disruptive change.

Yup.

To be clear: encryption _needs_ to be perfect. But "let's fork the web" is a pipe dream, "let's start encrypting emails" is quite achievable.

Re: GPGMail 2 is finally here

#57

Earlier quoted context omitted.

Ok. I'd just like to add to that: Very serious attacks on democratic principles have been carried out behind our backs, for a very long time, apparently. That is why I think, in order to counter these threats to society appropriately, disruptive approaches should really be welcomed and preferred as often as possible. And then, of course, it's not an either/or question. Both should be promoted alongside, as lots of di…

Email encryption is going to be effective against 99% of relevant attacks, and if the NSA wants to know what you're doing, they'll put a bug in your laptop and, no, you won't notice. Remember, even with lofty "serious attacks on democratic principles" going on, you're still infinity times more likely to have your bank account information stolen by drive-by script kiddies with a 0-day than be a target of government pe…

I know, I know, I don't even consider myself a target, at all. I don't really do this to just protect myself.

It's just that we should all do our best in order to erect the collective hurdle that the mass surveillance efforts now require. There's nothing lofty about democracy being attacked, it's very real. And don't forget that you can't really do encryption on your own, you depend on all your contacts doing it, too. Society needs to make that as normal as brushing their teeth.

Re: GPGMail 2 is finally here

#58
post #49

Observations after installing on 10.6.8: * GPG2 seems to be up and running very nicely, and it was an easy switch to get Enigmail set up to recognize it. (My previous MacGPG installation evidently installed GPG1. That seems to be orphaned now, I guess? Any suggestions for an ideal way to clean out its old stuff? I haven't seen it mentioned on your site.) * This is the first GPG distribution that I can remember using…

SHA Hash and signature will be added tomorrow. In all the excitement we forgot about that. Please file the bug report for GPGPreferences on https://support.gpgtools.org Thanks!

Re: GPGMail 2 is finally here

#59
post #19

My company's internal mail goes through gmail so I decided after recent news to setup GPGmail and s/mime. I identified a couple of usability issues, which where fixed. I'd say all in all its very good. Regardless if you believe or care about the NSA issues, simply the idea of routing clear text email through mail exchanges, and advertisers should give you enough reason to follow the few steps it requires to generate…

Just two nitpicks: You can sign email with GPG even if others aren’t using it (of course it will be of little value to them until they, possibly at a later date, verified your key), and it is supported on Android by K-9, I believe.

Worth noting here that K-9 for Android does not support the more modern and useful PGP/MIME. It only supports inline PGP. They've been promising it for years, but I'm not expecting to ever see it.

Hopefully somebody makes a good go at getting PGP onto Firefox OS so I can ditch Android.

Re: GPGMail 2 is finally here

#60
post #27

Earlier quoted context omitted.

Yes you can, but my point was that this is of no utility with GPG. Whereas with s/mime anyone can confirm that your email was signed (with many email clients), so there is value to using s/mime prior to all your contacts also using it.

> anyone can confirm that your email was signed (with many email clients), so there is value to using s/mime prior to all your contacts also using it. Provided that they trust the people handing out these certificates – with PGP, they need a chain of trust to your key to verify that it is you, with S/MIME, they have to trust random third parties. Or do I miss something and you mean something else that is possible wit…

Right now if I send my Grandmother a signed email with s/mime she will see a little notice in her email client that says the message is signed and valid. If I send her an email with a PGP signature it will not.

This is because just like her browser the CA is trusted by her OS.

Post reply on HN