Live data from Hacker News

Email Self-Defense – a guide to fighting surveillance with GnuPG

emailselfdefense.fsf.org

21–30 of 59 posts

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#21
post #2

I get and send ~ 10 to 15 emails per week. Not even 1 of my regular 'correspondence' uses GnuPG. It's too complicated to setup and even harder to use for avg Joe, like bitcoin, he has to spent time understanding totally new concepts. And no one is willing to do that, unfortunately :-(

I have walked non-technical people through the process of setting up GPGMail on Macs without much problem. I buy that GPGMail is hard to use reliably, and that its user interface is cryptic in ways that make it likely that users will slip up. I do not buy that GPG is particularly hard to get started with.

Unfortunately, all the glamour and the money and the code seems to track vanity crypto projects, and not so much of it goes to projects that make GPG more usable for normal people. Kudos to Google for taking a stab at correcting this.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#23
post #4

The very first step, assuming you already have an email account, for all platform pages: >INSTALL THE ENIGMAIL PLUGIN FOR YOUR EMAIL PROGRAM I Googled Enigmail as I was not familiar with it. It is "a security extension to Mozilla Thunderbird and Seamonkey." This seems incredibly shortsighted. Tons of people out there are on Outlook, Apple Mail, Gmail, etc. and not interested in Thunderbird. There are other options, f…

This guide is geared towards Web of Trust. I think most Email clients implement PKI functionality in one way or another. I've tried to set up Outlook with gpg4win (in a business environment) to work with WoT and it wasn't fun, although definitely not impossible. The easy way to solve any problems I had was to switch everybody to Thunderbird.

But again, that's because I wanted to use WoT. If you want PKI, no need to install anything.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#24
post #4

The very first step, assuming you already have an email account, for all platform pages: >INSTALL THE ENIGMAIL PLUGIN FOR YOUR EMAIL PROGRAM I Googled Enigmail as I was not familiar with it. It is "a security extension to Mozilla Thunderbird and Seamonkey." This seems incredibly shortsighted. Tons of people out there are on Outlook, Apple Mail, Gmail, etc. and not interested in Thunderbird. There are other options, f…

Reminds me of an article I saw the other day from a guy who ran his own mail server realizing Google already has most of his email, even though he didn't have a Google account, because senders and/or recipients other than himself used Gmail.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#25
infographics are nice but as long as all platforms and commonly used clients (not just email ones) have an EASY to use GnuPG implementation this seems bound to fail.

Google's initiative seems like a good idea of course. The command line utility itself could use some MAJOR love tho.

And even the best GUI clients are very confusing for new users. When I explain the concepts behind the trust model they get it. When they have to use the UI they dont find what they need.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#26
post #22
post #5

It will be more helpful when GMail has it built in... Google?

Google makes money on GMail by reading your email and serving related ads. They will never support built-in encryption.

I have worried about this incentive too, but they've just yesterday released some software that moves in this direction (though characterizing it as a special case for people who need extra security). But in the past I feared that they would even periodically update Gmail in ways that would break compatibility with browser-based encryption; I think the fact that they're publishing their own end-to-end browser-based e-mail encryption software shows that they're at a minimum willing to accept it as a supported feature.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#27
post #26
post #22

Earlier quoted context omitted.

Google makes money on GMail by reading your email and serving related ads. They will never support built-in encryption.

I have worried about this incentive too, but they've just yesterday released some software that moves in this direction (though characterizing it as a special case for people who need extra security). But in the past I feared that they would even periodically update Gmail in ways that would break compatibility with browser-based encryption; I think the fact that they're publishing their own end-to-end browser-based e…

Well, good. I'd probably even pay a reasonable monthly fee for that to offset their lost ad revenue.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#29
post #22
post #5

It will be more helpful when GMail has it built in... Google?

Google makes money on GMail by reading your email and serving related ads. They will never support built-in encryption.

It all depends on how they can mine the data. Metadata is hugely valuable, and you can probably infer why people would potentially would want to encrypt based on who the parties are.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#30
post #2

I get and send ~ 10 to 15 emails per week. Not even 1 of my regular 'correspondence' uses GnuPG. It's too complicated to setup and even harder to use for avg Joe, like bitcoin, he has to spent time understanding totally new concepts. And no one is willing to do that, unfortunately :-(

Currently , the most practical way for secure communications looks like textSecure, which is a mobile IM app that is easy to use and install , and relatively easy to convince others to communicate in.
Post reply on HN