I don't need the extra security provided by end-to-end encryption for the vast majority of emails I receive and send. I value that ability to search/filter these emails far more than I value the security. For the few emails I send where the value of the security provided exceeds the lost value due to being unable to search I can, using their extension, enable end-to-end encryption. This system suits my needs perfectl…
Agreed. The question is. Can you perfectly, always and with regard for potential future changes to what may be sensitive information decide which ones to encrypt? One email sent the wrong way when tired. One change in legislation (to e.g. retrospectively criminalise an activity or legalise a certain type of snooping). Now your company's IP is compromised. Or now your in jail. Or now you can be blackmailed. Furthermor…
Re:publica 15: Google Promotes Privacy, But Not Too Much
41–50 of 79 posts
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#42Does this surprise anyone? Google has contradictory interests when it comes to encryption and privacy. It has been at the forefront of pushing SMTP to SMTP encryption and HTTPS everywhere. Google has to spread (and perhaps seriously believes in) the idea that they transfer data securely, unreadable by the Five Eyes. Because the perception that Google is in bed with the NSA et al. is seriously undermining their reputa…
Plus they're encrypted so only they know it. Also, I'm not from the US so MY government doesn't have access to their data.
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#43Does this surprise anyone? Google has contradictory interests when it comes to encryption and privacy. It has been at the forefront of pushing SMTP to SMTP encryption and HTTPS everywhere. Google has to spread (and perhaps seriously believes in) the idea that they transfer data securely, unreadable by the Five Eyes. Because the perception that Google is in bed with the NSA et al. is seriously undermining their reputa…
FWIW, Wikipedia says Google has five million customers for the gmail-for-business product, each of which pays $50-60 per year per user. If you assume an average of two employees per customer that's a half-billion dollars per year. If you believe the numbers in e.g. http://www.quora.com/How-much-does-Google-earn-from-ads-per-... the ad-supported gmail revenue must be peanuts by comparison.
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#44Does this surprise anyone? Google has contradictory interests when it comes to encryption and privacy. It has been at the forefront of pushing SMTP to SMTP encryption and HTTPS everywhere. Google has to spread (and perhaps seriously believes in) the idea that they transfer data securely, unreadable by the Five Eyes. Because the perception that Google is in bed with the NSA et al. is seriously undermining their reputa…
Unfortunately their services are too convenient. I use them for almost everything I can, my reason being that they already know enough about me from my google searches, so I might as well use every other service they have. Plus they're encrypted so only they know it. Also, I'm not from the US so MY government doesn't have access to their data.
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#45Earlier quoted context omitted.
Agreed. The question is. Can you perfectly, always and with regard for potential future changes to what may be sensitive information decide which ones to encrypt? One email sent the wrong way when tired. One change in legislation (to e.g. retrospectively criminalise an activity or legalise a certain type of snooping). Now your company's IP is compromised. Or now your in jail. Or now you can be blackmailed. Furthermor…
What insane law system makes an action retrospectively criminal ? Does the US law system allows this ?
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#46https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html In case anybody hasn't read it yet, Philip Zimmermann's essay on why he wrote PGP is very relevant to this discussion. Google is effectively saying envelopes are not meant for common use. Did you send everything by postcard back in the snail-mail days, only using an envelope when the contents was very-important? If someone saw you mailing an envelope, did the…
Totally agree. The fact we happily send so much data around :/ clear text has always irked me. The only layer of protection is that there's probably no one interested enough to look
And then sell that to the highest bidder.
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#47Does this surprise anyone? Google has contradictory interests when it comes to encryption and privacy. It has been at the forefront of pushing SMTP to SMTP encryption and HTTPS everywhere. Google has to spread (and perhaps seriously believes in) the idea that they transfer data securely, unreadable by the Five Eyes. Because the perception that Google is in bed with the NSA et al. is seriously undermining their reputa…
Unfortunately their services are too convenient. I use them for almost everything I can, my reason being that they already know enough about me from my google searches, so I might as well use every other service they have. Plus they're encrypted so only they know it. Also, I'm not from the US so MY government doesn't have access to their data.
You could.. you know... change that.. https://duckduckgo.com
> Also, I'm not from the US so MY government doesn't have access to their data
Because the US doesn't have any allies that participate in data sharing, and definitely doesn't intercept data in transit over the greater internet and on Google's internal network...
Oh wait..
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#48Does this surprise anyone? Google has contradictory interests when it comes to encryption and privacy. It has been at the forefront of pushing SMTP to SMTP encryption and HTTPS everywhere. Google has to spread (and perhaps seriously believes in) the idea that they transfer data securely, unreadable by the Five Eyes. Because the perception that Google is in bed with the NSA et al. is seriously undermining their reputa…
Unfortunately their services are too convenient. I use them for almost everything I can, my reason being that they already know enough about me from my google searches, so I might as well use every other service they have. Plus they're encrypted so only they know it. Also, I'm not from the US so MY government doesn't have access to their data.
THAT's where Google's position, or at least this Google spokesman's position is wrong: I'll give up both some convenience and some money to get more privacy.
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#49I don't need the extra security provided by end-to-end encryption for the vast majority of emails I receive and send. I value that ability to search/filter these emails far more than I value the security. For the few emails I send where the value of the security provided exceeds the lost value due to being unable to search I can, using their extension, enable end-to-end encryption. This system suits my needs perfectl…
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#50Here is my concern with the WOT: it's not clear what signatures mean. It could mean "This guy can give out valid signatures" or "I verified that this guy's name is John Doe" or "This is the key used to sign Debian isos", but these are all implicit. Typically it's the first two which makes it hard to use PGP with pseudonyms. When you verify a signature in PGP you want the following chain:
o--I trust this guy's signatures-->o--I trust this guy's signatures-->o--I know this guy-->o
Other concerns: any way to rotate the master key would be nice. I wouldn't assume that my master key won't be compromised in the next 50 years .Then I would have to rebuild my whole WOT and revoke my previous master key (If I can). Key distributon should be decentralized.
Maybe I'm missing something, but this is my takeaway and I really tried to like PGP and gnupg. Maybe Google will solve some of these concerns on their interface but I wouldn't bet on it. I'm not surprised that PGP isn't widely used. I would really like a safe end-to-end encryption implementation that is easy to use.