Slightly OT, but what's the likelihood of Apple/Google integrating PGP natively into the OS? I know iPhone has S/MINE - but is PGP too much to ask?
Email encryption on Android and iOS becomes easy with the open source app Tutanota
11–20 of 27 posts
Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota
#12The NSA Planned to Hijack Google App Store to Hack Smartphones [1] Given that software updates are automatic (unless you manually turn them off etc), how can you trust an app if you can't trust the platform? 1. https://firstlook.org/theintercept/2015/05/21/nsa-five-eyes-...
Firstly, Android checks app signatures and as far as I know the market app doesn't have any ability to override that. It can do a few privileged things like skip showing the permissions screen, but I think the OS still wants to see correct signatures. So even if the app store was hacked the phone itself might reject a bogus upgrade.
Secondly, that slide is more like some junior GCHQ guy noodling around, I think. It is old and dates from a time before Google used SSL for everything. I doubt it's possible to do via purely technical attacks now.
Thirdly, it'd almost certainly be easier to attack the developer laptop/workstation to steal the signing keys directly than attack Android head on. I plan to do some research this summer into splitting the RSA signing keys used by Android apps to allow for threshold signed online updates for Android and maybe iOS.
Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota
#13I have to be honest, I have given up on pgp. From what I know there is no way to have encrypted communications between more than two people. So why even bother pursuing the dream of everyone using it if there is such a roadblock in the way of common communication habits.
Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota
#14Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota
#15The NSA Planned to Hijack Google App Store to Hack Smartphones [1] Given that software updates are automatic (unless you manually turn them off etc), how can you trust an app if you can't trust the platform? 1. https://firstlook.org/theintercept/2015/05/21/nsa-five-eyes-...
Two things. Firstly, Android checks app signatures and as far as I know the market app doesn't have any ability to override that. It can do a few privileged things like skip showing the permissions screen, but I think the OS still wants to see correct signatures. So even if the app store was hacked the phone itself might reject a bogus upgrade. Secondly, that slide is more like some junior GCHQ guy noodling around, I…
Their budget is $52.6 billion and (as you say, the slides are old) they have lead time too. Let that sit for a moment.
Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota
#16I have to be honest, I have given up on pgp. From what I know there is no way to have encrypted communications between more than two people. So why even bother pursuing the dream of everyone using it if there is such a roadblock in the way of common communication habits.
Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota
#17Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota
#18Slightly OT, but what's the likelihood of Apple/Google integrating PGP natively into the OS? I know iPhone has S/MINE - but is PGP too much to ask?
Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota
#19The NSA Planned to Hijack Google App Store to Hack Smartphones [1] Given that software updates are automatic (unless you manually turn them off etc), how can you trust an app if you can't trust the platform? 1. https://firstlook.org/theintercept/2015/05/21/nsa-five-eyes-...
Two things. Firstly, Android checks app signatures and as far as I know the market app doesn't have any ability to override that. It can do a few privileged things like skip showing the permissions screen, but I think the OS still wants to see correct signatures. So even if the app store was hacked the phone itself might reject a bogus upgrade. Secondly, that slide is more like some junior GCHQ guy noodling around, I…
Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota
#20I have to be honest, I have given up on pgp. From what I know there is no way to have encrypted communications between more than two people. So why even bother pursuing the dream of everyone using it if there is such a roadblock in the way of common communication habits.
I believe PGP does support multiple recipients. The symmetric key is encrypted and included for every recipient.