Live data from Hacker News

End-To-End – OpenPGP Chrome extension from Google

code.google.com

11–20 of 173 posts

Re: End-To-End – OpenPGP Chrome extension from Google

#12
post #10

Isn't this contrary to Google's goals as an advertising business? If people are using end-to-end encryption, they won't have cleartext emails to mine, &c. I need to wonder what the catch is, because there is definitely one: does Google own all the keys, or does Google secretly own all the keys?

Google is not mining all networks for cleartext email. They are mining gmail which they have control of the "end". This is a huge advantage for Google as ISPs are starting to offer ability to advertise to end users by mining traffic.

Re: End-To-End – OpenPGP Chrome extension from Google

#13
post #10

Isn't this contrary to Google's goals as an advertising business? If people are using end-to-end encryption, they won't have cleartext emails to mine, &c. I need to wonder what the catch is, because there is definitely one: does Google own all the keys, or does Google secretly own all the keys?

What if there is no catch? Google's security team is apparently pissed off over the NSA revelations with regards to the infiltration of their infrastructure.

EDIT: NSA Smiley Face [http://theweek.com/article/index/252034/why-google-isnt-too-...]

Re: End-To-End – OpenPGP Chrome extension from Google

#14
post #11

The FAQ states: > Only the body of the message. Please note that, as with all OpenPGP > messages, the email subject line and list of recipients remain > unencrypted. Hopefully attachments are considered part of the body?

Why would attachments be considered part of the body?

Encrypt them before uploading them, and send the decrypting key in the body.

Re: End-To-End – OpenPGP Chrome extension from Google

#16
post #11

The FAQ states: > Only the body of the message. Please note that, as with all OpenPGP > messages, the email subject line and list of recipients remain > unencrypted. Hopefully attachments are considered part of the body?

I don't think so. PGP scrambles the text of the message for you (that's the body), but you're still using the standard email protocol, which sends attachments without making changes to them. You'd need to encrypt the files before sending them. (And the recipient would have to unencrypt them manually.)

Re: End-To-End – OpenPGP Chrome extension from Google

#17
post #4

"Please note that enabling Chrome’s "Automatically send usage statistics and crash reports to Google" means that, in the event of a crash, parts of memory containing private key material might be sent to Google." I hope that has more than a FAQ warning when they release it to the Chrome Store. Otherwise....:/ It isn't perfect but it is probably the best in-browser option given the constraints available.

Does this also mean parts of memory containing, say, passwords could be send to Google?

Re: End-To-End – OpenPGP Chrome extension from Google

#18
post #4

"Please note that enabling Chrome’s "Automatically send usage statistics and crash reports to Google" means that, in the event of a crash, parts of memory containing private key material might be sent to Google." I hope that has more than a FAQ warning when they release it to the Chrome Store. Otherwise....:/ It isn't perfect but it is probably the best in-browser option given the constraints available.

That makes it largely unusable even to test for a few users, I guess.

If you are testing you are not mailing about nuclear secrets.

Re: End-To-End – OpenPGP Chrome extension from Google

#19
post #14
post #11

The FAQ states: > Only the body of the message. Please note that, as with all OpenPGP > messages, the email subject line and list of recipients remain > unencrypted. Hopefully attachments are considered part of the body?

Why would attachments be considered part of the body? Encrypt them before uploading them, and send the decrypting key in the body.

Any decent PGP plugin encrypts the attachments.

Re: End-To-End – OpenPGP Chrome extension from Google

#20
post #10

Isn't this contrary to Google's goals as an advertising business? If people are using end-to-end encryption, they won't have cleartext emails to mine, &c. I need to wonder what the catch is, because there is definitely one: does Google own all the keys, or does Google secretly own all the keys?

Google is not mining all networks for cleartext email. They are mining gmail which they have control of the "end". This is a huge advantage for Google as ISPs are starting to offer ability to advertise to end users by mining traffic.

"End-to-end" implies that Gmail won't be able to read your emails. That means that this software and Gmail, one of Google's largest products, are going to be competing. One of them needs to adapt or die: if this software isn't backdoored or vulnerable right now, it will either be shuttered, backdoored or made vulnerable in the future. (Certainly Gmail is of tangible, financial good to them: it's more likely for them to favor it over End-to-End, which is a non-profit and humanitarian effort.)
Post reply on HN