Live data from Hacker News

Email Self-Defense – a guide to fighting surveillance with GnuPG

emailselfdefense.fsf.org

11–20 of 59 posts

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#11
If you're using a Mac, the excellent MailMate mail client supports GnuPG natively.

http://manual.mailmate-app.com/preferences#openpgp_and_smime

I can't speak to any shortcomings in its PGP support, as it's not something I personally use, but I've been using it as a MacMail/Thunderbird replacement since last September and have been quite satisfied.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#12
post #9

Earlier quoted context omitted.

They already published a stepping stone. https://code.google.com/p/end-to-end/

Sure... but that is hardly ready for the masses! :-)

steps in the right direction happen one step at a time.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#13
post #7
post #3

Earlier quoted context omitted.

ok, get info-raped by any and all then.

Consider this: 1. It's probably better to remain civil in your discourse if you want people to take you seriously, and not just dismiss you as a troll. If you really do feel so strongly about your position, then you're probably doing more harm than good to your cause by firing off such remarks. 2. I doubt that you personally communicate with everyone using encrypted email. If you do, your world is probably fairly ins…

It seems like teaching people to use GPG for the authentication is probably the first step. Sending to someone who doesn't use GPG then is still readable, and if you want to push the point with a particular person then every time they email you call them and say "I got an email, I wanted to be sure it was from you, since there was no signature..."

Once you can count on contacts using GPG, the path to encrypting is much easier.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#14

I'm still constantly surprised that this feature isn't ubiquitously built into mail clients by default and users don't get a big 'enable encryption' button which automates sane defaults/manages the keychain transparently. It doesn't seem like such a complicated abstraction that it needs so much manual setup

I remember it being built-in to clients in the past. Certainly Evolution (Ximian, Novell, Gnome) did when I last used it half a decade ago. You could encrypt your message, sign it, and the other side would (if they had your public key) see a nice 'Signature verified' on the other side.

It was a fairly smooth workflow except for having to type in your passphrase in for everything.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#15
post #4

The very first step, assuming you already have an email account, for all platform pages: >INSTALL THE ENIGMAIL PLUGIN FOR YOUR EMAIL PROGRAM I Googled Enigmail as I was not familiar with it. It is "a security extension to Mozilla Thunderbird and Seamonkey." This seems incredibly shortsighted. Tons of people out there are on Outlook, Apple Mail, Gmail, etc. and not interested in Thunderbird. There are other options, f…

There's also Mailvelope[1], if you use gmail or other webmail.

[1]: https://www.mailvelope.com/

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#16
post #2

I get and send ~ 10 to 15 emails per week. Not even 1 of my regular 'correspondence' uses GnuPG. It's too complicated to setup and even harder to use for avg Joe, like bitcoin, he has to spent time understanding totally new concepts. And no one is willing to do that, unfortunately :-(

It's true, Glenn Greenwald said that he almost gave up on Snowden's information because it was too hard to set up GPG correctly!

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#17
post #4

The very first step, assuming you already have an email account, for all platform pages: >INSTALL THE ENIGMAIL PLUGIN FOR YOUR EMAIL PROGRAM I Googled Enigmail as I was not familiar with it. It is "a security extension to Mozilla Thunderbird and Seamonkey." This seems incredibly shortsighted. Tons of people out there are on Outlook, Apple Mail, Gmail, etc. and not interested in Thunderbird. There are other options, f…

GPGMail for OS X (what you recommended here) works quite well, and I recommend it too. That team also does a good job of keeping up with Mail.app versions (which is a hard job).

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#18
post #7

Earlier quoted context omitted.

Consider this: 1. It's probably better to remain civil in your discourse if you want people to take you seriously, and not just dismiss you as a troll. If you really do feel so strongly about your position, then you're probably doing more harm than good to your cause by firing off such remarks. 2. I doubt that you personally communicate with everyone using encrypted email. If you do, your world is probably fairly ins…

It seems like teaching people to use GPG for the authentication is probably the first step. Sending to someone who doesn't use GPG then is still readable, and if you want to push the point with a particular person then every time they email you call them and say "I got an email, I wanted to be sure it was from you, since there was no signature..." Once you can count on contacts using GPG, the path to encrypting is mu…

IMHO the problem is the NOT infrastructure per se, it's the theoretical part that is cumbersome. If you now why you are doing something, it's easy to understand why you should not save the 'key' in the "Keychain" or sign random emails.

To use GnuPG correctly you need explain to average Joe concepts like:

    * PKI
    * Key signing
    * Web of trust
    * Revocation key
The problem is that, as Einstein said: Everything should be made as simple as possible, but no simple.

Same problem I can't talk bitcoin with most of my real-life friends. They are incredibly smart people, but they are not familiar with key concepts about BTC and don't wanna wrap their minds around it when we're hanging out having fun.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#19
post #7

Earlier quoted context omitted.

Consider this: 1. It's probably better to remain civil in your discourse if you want people to take you seriously, and not just dismiss you as a troll. If you really do feel so strongly about your position, then you're probably doing more harm than good to your cause by firing off such remarks. 2. I doubt that you personally communicate with everyone using encrypted email. If you do, your world is probably fairly ins…

It seems like teaching people to use GPG for the authentication is probably the first step. Sending to someone who doesn't use GPG then is still readable, and if you want to push the point with a particular person then every time they email you call them and say "I got an email, I wanted to be sure it was from you, since there was no signature..." Once you can count on contacts using GPG, the path to encrypting is mu…

I'd argue that getting address books to understand what keys are and how to use them would be more impactful. If I put public keys in my address book, which is nicely integrated with my mail client anyway, then sending encrypted mail should be far more straightforward. The problem then is getting people to use new address books.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#20
post #16
post #2

I get and send ~ 10 to 15 emails per week. Not even 1 of my regular 'correspondence' uses GnuPG. It's too complicated to setup and even harder to use for avg Joe, like bitcoin, he has to spent time understanding totally new concepts. And no one is willing to do that, unfortunately :-(

It's true, Glenn Greenwald said that he almost gave up on Snowden's information because it was too hard to set up GPG correctly!

He did give up on GPG, and instead used Cryptocat, at a time during which it appears to have been possible to decrypt Cryptocat conversations from network traces due to key generation bugs.
Post reply on HN