Earlier quoted context omitted.
It seems like teaching people to use GPG for the authentication is probably the first step. Sending to someone who doesn't use GPG then is still readable, and if you want to push the point with a particular person then every time they email you call them and say "I got an email, I wanted to be sure it was from you, since there was no signature..." Once you can count on contacts using GPG, the path to encrypting is mu…
I'd argue that getting address books to understand what keys are and how to use them would be more impactful. If I put public keys in my address book, which is nicely integrated with my mail client anyway, then sending encrypted mail should be far more straightforward. The problem then is getting people to use new address books.
Email Self-Defense – a guide to fighting surveillance with GnuPG
41–50 of 59 posts
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#42If you're using a Mac, the excellent MailMate mail client supports GnuPG natively. http://manual.mailmate-app.com/preferences#openpgp_and_smime I can't speak to any shortcomings in its PGP support, as it's not something I personally use, but I've been using it as a MacMail/Thunderbird replacement since last September and have been quite satisfied.
This looks great but it is closed source. Perhaps that will change with his crowd finding? Until it becomes OSS there is no way I can use it
If you were concerned about what was being sent and to where, you would probably be better off to capture all traffic originating from your computer and verify that nothing extra is being sent, and that the destination is appropriate. Whether it was sent by open or closed source software is utterly irrelevant
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#43It will be more helpful when GMail has it built in... Google?
Google makes money on GMail by reading your email and serving related ads. They will never support built-in encryption.
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#44Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#45FireGPG was super easy to use with Gmail (that said, I suppose Google would have grabbed the cleartext in the interim draft state anyway)
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#46It will be more helpful when GMail has it built in... Google?
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#47I get and send ~ 10 to 15 emails per week. Not even 1 of my regular 'correspondence' uses GnuPG. It's too complicated to setup and even harder to use for avg Joe, like bitcoin, he has to spent time understanding totally new concepts. And no one is willing to do that, unfortunately :-(
Except for the part where they want you to upload your private key to them. But that is optional.
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#48For Android you can use APG and K9-Mail. You will learn to love it if you have multiple accounts and 'get' the interface. Recommended use is with Thunderbird and Enigmail on desktop, where you should also have your mail filters sorting your mail to the IMAP folders. To install use F-Droid. F-Droid ist the Open Software Repository for Android. https://f-droid.org/ This is/feels like the recommended way to use PGP at t…
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#49The very first step, assuming you already have an email account, for all platform pages: >INSTALL THE ENIGMAIL PLUGIN FOR YOUR EMAIL PROGRAM I Googled Enigmail as I was not familiar with it. It is "a security extension to Mozilla Thunderbird and Seamonkey." This seems incredibly shortsighted. Tons of people out there are on Outlook, Apple Mail, Gmail, etc. and not interested in Thunderbird. There are other options, f…
GPGMail for OS X (what you recommended here) works quite well, and I recommend it too. That team also does a good job of keeping up with Mail.app versions (which is a hard job).
But I thought I'd do things the "right" way. Use master/sub keys, linked identities, with masters kept offline... The friction was _immense_, especially managing the identities, mucking with the keyring files, then deleting the master key from the online keyring, and so on.
I still have my off-site db secure, but I don't look forward at all to opening it again. I don't want to remember the precise series of steps involved before everything worked correctly.
How can I solve this? I just want to manage a few identities (personal, as a citizen, work account, "stuff", etc.), some of them trusting each other.
Common sense makes me think I'm way over-complicating. But I was always told that any other way wouldn't really be secure. I though I would just be very pro-active with key revocation and that would eliminate most of the problem...
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#50I get and send ~ 10 to 15 emails per week. Not even 1 of my regular 'correspondence' uses GnuPG. It's too complicated to setup and even harder to use for avg Joe, like bitcoin, he has to spent time understanding totally new concepts. And no one is willing to do that, unfortunately :-(
They still don't really care, but at least my communication with them is encrypted.
Also, they see that using encryption is not hard (once set up), except that they have to type in a password from time to time.