For Android you can use APG and K9-Mail. You will learn to love it if you have multiple accounts and 'get' the interface. Recommended use is with Thunderbird and Enigmail on desktop, where you should also have your mail filters sorting your mail to the IMAP folders. To install use F-Droid. F-Droid ist the Open Software Repository for Android. https://f-droid.org/ This is/feels like the recommended way to use PGP at t…
Agreed - I'm using this setup and it works really well.
Email Self-Defense – a guide to fighting surveillance with GnuPG
51–59 of 59 posts
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#52The very first step, assuming you already have an email account, for all platform pages: >INSTALL THE ENIGMAIL PLUGIN FOR YOUR EMAIL PROGRAM I Googled Enigmail as I was not familiar with it. It is "a security extension to Mozilla Thunderbird and Seamonkey." This seems incredibly shortsighted. Tons of people out there are on Outlook, Apple Mail, Gmail, etc. and not interested in Thunderbird. There are other options, f…
Both have massive problems and are unstable though :(
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#53Earlier quoted context omitted.
Agreed - I'm using this setup and it works really well.
How do you treat PGP/MIME E-Mails? PGP-Inline is dead.
There's an open issue to add PPG/MIME: https://code.google.com/p/k9mail/issues/detail?id=5864
There's also an open bounty which can be contributed to: https://www.bountysource.com/issues/815255-pgp-mime
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#54Earlier quoted context omitted.
How do you treat PGP/MIME E-Mails? PGP-Inline is dead.
Good point - that's the only issue I have with K9 and AGP on Android. I'm happy to live with only being able to view encrypted attachments on the desktop at the moment. There's an open issue to add PPG/MIME: https://code.google.com/p/k9mail/issues/detail?id=5864 There's also an open bounty which can be contributed to: https://www.bountysource.com/issues/815255-pgp-mime
You can get the latest K9 Alpha from here: https://github.com/k9mail/k-9/releases/tag/4.904
..and should use OpenKeyChain instead of APG, since its no longer maintained. http://openkeychain.org/ (also available on F-Droid)
This at least removes the need to push decrypt on every Message although thee might be Bugs.
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#55Earlier quoted context omitted.
Good point - that's the only issue I have with K9 and AGP on Android. I'm happy to live with only being able to view encrypted attachments on the desktop at the moment. There's an open issue to add PPG/MIME: https://code.google.com/p/k9mail/issues/detail?id=5864 There's also an open bounty which can be contributed to: https://www.bountysource.com/issues/815255-pgp-mime
Small Update: You can get the latest K9 Alpha from here: https://github.com/k9mail/k-9/releases/tag/4.904 ..and should use OpenKeyChain instead of APG, since its no longer maintained. http://openkeychain.org/ (also available on F-Droid) This at least removes the need to push decrypt on every Message although thee might be Bugs.
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#56Earlier quoted context omitted.
Reminds me of an article I saw the other day from a guy who ran his own mail server realizing Google already has most of his email, even though he didn't have a Google account, because senders and/or recipients other than himself used Gmail.
You mean this one: ( http://mako.cc/copyrighteous/google-has-most-of-my-email-bec... )?
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#57Earlier quoted context omitted.
It seems like teaching people to use GPG for the authentication is probably the first step. Sending to someone who doesn't use GPG then is still readable, and if you want to push the point with a particular person then every time they email you call them and say "I got an email, I wanted to be sure it was from you, since there was no signature..." Once you can count on contacts using GPG, the path to encrypting is mu…
IMHO the problem is the NOT infrastructure per se, it's the theoretical part that is cumbersome. If you now why you are doing something, it's easy to understand why you should not save the 'key' in the "Keychain" or sign random emails. To use GnuPG correctly you need explain to average Joe concepts like: * PKI * Key signing * Web of trust * Revocation key The problem is that, as Einstein said: Everything should be ma…
People just cry out to the programmers to "just make it easier".
Well there's only so far you can go on the easy scale until you start sacrificing security and integrity.
People need to learn some of the fundamentals and basics you can't run away from it forever.
It's like someone saying "Mehh I don't like calculus ... why don't these mathematicians make it just easier? Why do I have to learn about differentiation? Make it so easy my grandma could differentiate this equation"
Instead we force every kid to take the pain a bit and learn some damn basics.
Same should go for computing. Schools could teach the kids the basics of protecting their communications on the internet. Give that 10 years and Public/Private key encryption is a piece of cake for every reasonably educated adult in the society and they are no longer buzzwords because everyone grew up with it and remembers their 8th grade when they learned all about it.
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#58The very first step, assuming you already have an email account, for all platform pages: >INSTALL THE ENIGMAIL PLUGIN FOR YOUR EMAIL PROGRAM I Googled Enigmail as I was not familiar with it. It is "a security extension to Mozilla Thunderbird and Seamonkey." This seems incredibly shortsighted. Tons of people out there are on Outlook, Apple Mail, Gmail, etc. and not interested in Thunderbird. There are other options, f…
For outlook users there's gpgOL and Outlook Privacy Plugin. Both have massive problems and are unstable though :(
Re: Email Self-Defense – a guide to fighting surveillance with GnuPG
#59Earlier quoted context omitted.
IMHO the problem is the NOT infrastructure per se, it's the theoretical part that is cumbersome. If you now why you are doing something, it's easy to understand why you should not save the 'key' in the "Keychain" or sign random emails. To use GnuPG correctly you need explain to average Joe concepts like: * PKI * Key signing * Web of trust * Revocation key The problem is that, as Einstein said: Everything should be ma…
I see what you're saying I think the same argument is being overly used to justify a lack of basic effort to learn anything about computing beyond 'click this shiny red button'. People just cry out to the programmers to "just make it easier". Well there's only so far you can go on the easy scale until you start sacrificing security and integrity. People need to learn some of the fundamentals and basics you can't run…
Actually, modern textbooks do exactly that: they try to find pedagogically better ways to teach this stuff.
And sometimes newer developments really simplify things.
All that apart from the simple fact that mathematics and the user interface and user interaction are not even in the same ballpark.
Your comment seems a bit lazy to me. Just not in a way you expected to.