Live data from Hacker News

Email encryption on Android and iOS becomes easy with the open source app Tutanota

tutanota.de

21–27 of 27 posts

Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota

#23

I thought it was already easy on Android with K-9 and APG.

APG is discontinued. You should use OpenKeychain now instead - http://www.openkeychain.org - OpenKeychain does everything APG did, more, and has a much nicer interface. It even lets you use a Yubikey as a PGP smartcard over NFC so you don't have to store your PGP keys on your phone - https://grepular.com/An_NFC_PGP_SmartCard_For_Android

The one thing that K-9 misses, which is pretty major IMO, is PGP/MIME support. It only works with inline PGP.

Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota

#25
post #19

Earlier quoted context omitted.

Two things. Firstly, Android checks app signatures and as far as I know the market app doesn't have any ability to override that. It can do a few privileged things like skip showing the permissions screen, but I think the OS still wants to see correct signatures. So even if the app store was hacked the phone itself might reject a bogus upgrade. Secondly, that slide is more like some junior GCHQ guy noodling around, I…

The only way to change the signing key for an app (on an unrooted phone at least) is by completely uninstalling it (which deletes the main data directory) and then installing a new version. In fact, Google lost the key for their OTP authenticator app at one point, requiring all users to install the new app manually before they would receive updates again.

Have you got a link? I can't find any info on that happening

Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota

#26
post #19

Earlier quoted context omitted.

The only way to change the signing key for an app (on an unrooted phone at least) is by completely uninstalling it (which deletes the main data directory) and then installing a new version. In fact, Google lost the key for their OTP authenticator app at one point, requiring all users to install the new app manually before they would receive updates again.

Have you got a link? I can't find any info on that happening

Couldn't find the blog post I read way back when it happened. The closest thing I could find was an Android news site describing the problem. [1]

I'm 90% sure that a Google engineer admitted it on their official blog, but that was 2 years ago so I might be misremembering it.

[1] http://www.androidpolice.com/2012/03/22/psa-googles-authenti...

Re: Email encryption on Android and iOS becomes easy with the open source app Tutanota

#27

I thought it was already easy on Android with K-9 and APG.

APG is discontinued. You should use OpenKeychain now instead - http://www.openkeychain.org - OpenKeychain does everything APG did, more, and has a much nicer interface. It even lets you use a Yubikey as a PGP smartcard over NFC so you don't have to store your PGP keys on your phone - https://grepular.com/An_NFC_PGP_SmartCard_For_Android The one thing that K-9 misses, which is pretty major IMO, is PGP/MIME support. It…

Thanks for the information, I'll look into those.

Yeah, I don't like that PGP/MIME isn't supported, but I manage.

Post reply on HN