Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…
Where would the private keys be stored? How do you handle the use-case of a non-technical user losing their laptop?
Encrypt your Google chats and make the NSA sad
101–110 of 195 posts
Re: Encrypt your Google chats and make the NSA sad
#102Earlier quoted context omitted.
This doesn't make sense to me. There are two main stages to having your data analysed by such an organisation. In the first stage everybody's data is run through, let's call it, pattern matching, to narrow down a very specific number of cases that have the highest likelihood of doing, having done or planning "something". In the second stage, you might apply more resources to gather more data from your suspects, for e…
I was wondering the opposite: How do you get as many people as possible to trigger the match so that it becomes a losing proposition to do this sort of traffic monitoring.
Re: Encrypt your Google chats and make the NSA sad
#103Earlier quoted context omitted.
Partisan towards... what? He is a very strong civil libertarian.
Here's Glenn either being intellectually dishonest or intellectually incompetent. http://www.samharris.org/blog/item/dear-fellow-liberal2
That said, he might just have an irrational us vs. them "liberals vs. racists" complex and be able to speak sensibly on other matters.
Re: Encrypt your Google chats and make the NSA sad
#104Re: Encrypt your Google chats and make the NSA sad
#105Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…
Most people aren't going to get themselves into webs of trust - and certificate authorities and webmail servers and the like can be compromised. The only thing you can vest any significant trust in, with NSLs and so on flying around, is what's on your computer. And, if you want to be really sure, what's on a computer with no radio protected by an airgap into which you never insert removable media....
Re: Encrypt your Google chats and make the NSA sad
#106Still waiting for Google to implement OTR and ZRTP in Hangouts by default... especially now after all this.
Probably not gonna happened, but it would solve so many problems with public key crypto. Key distribution? No problem, tie your public key to your gmail account. Need to communicate with someone? Just send them your public key. Goole would verify that key X belongs to mail Y, another problem solved. Mix it together with some javascript library (source code available by design) and you have almost perfect and simple t…
Public key cryptography is great for this, because it means if you match one person to a key, you've then reliably matched every message they sent and have fairly strong proof it's the same person.
Re: Encrypt your Google chats and make the NSA sad
#107Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…
this would make "intercepts" far more difficult Yup, Google is doubtless completely in cahoots with the NSA. ... Really? Is that what you are thinking? Apply some rational thinking here. It's simpler than that. Google advertises to you based on the contents of your email. It is not in Google's interests to prevent themselves from being able to read your email, and if they can read it so can the NSA.
The implementation I'm referring to doesn't preclude Gmail from reading emails it has of yours. It just means that only Gmail can read them, because only Gmail has your private key, a private key that's associated with two-factor authentication, and a private key you could optionally use elsewhere, too.
Re: Encrypt your Google chats and make the NSA sad
#108Earlier quoted context omitted.
For Android, see the Guardian Project's work, especially Gibberbot: https://guardianproject.info/apps/gibber/ For iOS, you could try ChatSecure: http://chrisballinger.info/apps/chatsecure/ If you want to use the same key on both clients (which carries some additional risks if, say, your phone gets stolen, given that key is stored in plaintext) you may find the Guardian Project's documentation of different OTR key fil…
Thanks! I'll take a look at Gibberbot.
Re: Encrypt your Google chats and make the NSA sad
#109Why doesn't Google up the security in its own apps? The government may "force" them to provide access, but can it "force" them to remove safeguards like encrypting email/chats/etc? Even if they just gave us the option to check a box, and it wasn't on by default. The problem I'm seeing with all these solutions is that they're very specific to two users, they both need to have everything set up. Well, great, the NSA wi…
Re: Encrypt your Google chats and make the NSA sad
#110Why doesn't Google up the security in its own apps? The government may "force" them to provide access, but can it "force" them to remove safeguards like encrypting email/chats/etc? Even if they just gave us the option to check a box, and it wasn't on by default. The problem I'm seeing with all these solutions is that they're very specific to two users, they both need to have everything set up. Well, great, the NSA wi…