Live data from Hacker News

Email Self-Defense – a guide to fighting surveillance with GnuPG

emailselfdefense.fsf.org

41–50 of 59 posts

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#41
post #19

Earlier quoted context omitted.

It seems like teaching people to use GPG for the authentication is probably the first step. Sending to someone who doesn't use GPG then is still readable, and if you want to push the point with a particular person then every time they email you call them and say "I got an email, I wanted to be sure it was from you, since there was no signature..." Once you can count on contacts using GPG, the path to encrypting is mu…

I'd argue that getting address books to understand what keys are and how to use them would be more impactful. If I put public keys in my address book, which is nicely integrated with my mail client anyway, then sending encrypted mail should be far more straightforward. The problem then is getting people to use new address books.

Making the Thunderbird address book not suck would be a good firsr step in this regard.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#42
post #39
post #11

If you're using a Mac, the excellent MailMate mail client supports GnuPG natively. http://manual.mailmate-app.com/preferences#openpgp_and_smime I can't speak to any shortcomings in its PGP support, as it's not something I personally use, but I've been using it as a MacMail/Thunderbird replacement since last September and have been quite satisfied.

This looks great but it is closed source. Perhaps that will change with his crowd finding? Until it becomes OSS there is no way I can use it

Does being OSS actually matter for this app? It would still be running on a proprietary OS, and you won't be personally inspecting the code closely enough to know that it's secure anyway.

If you were concerned about what was being sent and to where, you would probably be better off to capture all traffic originating from your computer and verify that nothing extra is being sent, and that the destination is appropriate. Whether it was sent by open or closed source software is utterly irrelevant

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#43
post #22
post #5

It will be more helpful when GMail has it built in... Google?

Google makes money on GMail by reading your email and serving related ads. They will never support built-in encryption.

don't you mean they'll never support built-in encryption because storing your decryption keys on google's servers would totally defeat the purpose of encryption? Their new end-to-end extension is the only logical way to put encryption in gmail.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#46
post #5

It will be more helpful when GMail has it built in... Google?

Having it built into Gmail is a non-starter, because you can't do it right as a webapp. You need to do it locally, either with a browser extension (see the link someone else replied to you with) or a non-webmail client.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#47
post #2

I get and send ~ 10 to 15 emails per week. Not even 1 of my regular 'correspondence' uses GnuPG. It's too complicated to setup and even harder to use for avg Joe, like bitcoin, he has to spent time understanding totally new concepts. And no one is willing to do that, unfortunately :-(

Keybase.io is doing good work in making public key encryption more easily available.

Except for the part where they want you to upload your private key to them. But that is optional.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#48
post #38

For Android you can use APG and K9-Mail. You will learn to love it if you have multiple accounts and 'get' the interface. Recommended use is with Thunderbird and Enigmail on desktop, where you should also have your mail filters sorting your mail to the IMAP folders. To install use F-Droid. F-Droid ist the Open Software Repository for Android. https://f-droid.org/ This is/feels like the recommended way to use PGP at t…

Agreed - I'm using this setup and it works really well.

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#49
post #17
post #4

The very first step, assuming you already have an email account, for all platform pages: >INSTALL THE ENIGMAIL PLUGIN FOR YOUR EMAIL PROGRAM I Googled Enigmail as I was not familiar with it. It is "a security extension to Mozilla Thunderbird and Seamonkey." This seems incredibly shortsighted. Tons of people out there are on Outlook, Apple Mail, Gmail, etc. and not interested in Thunderbird. There are other options, f…

GPGMail for OS X (what you recommended here) works quite well, and I recommend it too. That team also does a good job of keeping up with Mail.app versions (which is a hard job).

I found the GPG tools on Mac quite good as well.

But I thought I'd do things the "right" way. Use master/sub keys, linked identities, with masters kept offline... The friction was _immense_, especially managing the identities, mucking with the keyring files, then deleting the master key from the online keyring, and so on.

I still have my off-site db secure, but I don't look forward at all to opening it again. I don't want to remember the precise series of steps involved before everything worked correctly.

How can I solve this? I just want to manage a few identities (personal, as a citizen, work account, "stuff", etc.), some of them trusting each other.

Common sense makes me think I'm way over-complicating. But I was always told that any other way wouldn't really be secure. I though I would just be very pro-active with key revocation and that would eliminate most of the problem...

Re: Email Self-Defense – a guide to fighting surveillance with GnuPG

#50
post #2

I get and send ~ 10 to 15 emails per week. Not even 1 of my regular 'correspondence' uses GnuPG. It's too complicated to setup and even harder to use for avg Joe, like bitcoin, he has to spent time understanding totally new concepts. And no one is willing to do that, unfortunately :-(

I configured my parents' email program (Thunderbird/Enigmail) to automatically encrypt emails they send to me. Also, I encrypt all emails to them.

They still don't really care, but at least my communication with them is encrypted.

Also, they see that using encryption is not hard (once set up), except that they have to type in a password from time to time.

Post reply on HN