Live data from Hacker News

Encrypt your Google chats and make the NSA sad

github.com

91–100 of 195 posts

Re: Encrypt your Google chats and make the NSA sad

#91
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

Where would the private keys be stored? How do you handle the use-case of a non-technical user losing their laptop?

Re: Encrypt your Google chats and make the NSA sad

#92
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

Where would the private keys be stored? How do you handle the use-case of a non-technical user losing their laptop?

Re: Encrypt your Google chats and make the NSA sad

#93
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

Where would the private keys be stored? How do you handle the use-case of a non-technical user losing their laptop?

Re: Encrypt your Google chats and make the NSA sad

#94
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

Where would the private keys be stored? How do you handle the use-case of a non-technical user losing their laptop?

Re: Encrypt your Google chats and make the NSA sad

#95
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

Where would the private keys be stored? How do you handle the use-case of a non-technical user losing their laptop?

Re: Encrypt your Google chats and make the NSA sad

#96
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

Where would the private keys be stored? How do you handle the use-case of a non-technical user losing their laptop?

Re: Encrypt your Google chats and make the NSA sad

#97
post #47

Earlier quoted context omitted.

This is not my area, so excuse the ignorance, but this statement: A: "The NSA has built an infrastructure that allows it to intercept almost everything. With this capability, the vast majority of human communications are automatically ingested without targeting. If I wanted to see your emails or your wife's phone, all I have to do is use intercepts. I can get your emails, passwords, phone records, credit cards." Spec…

Intercept could also mean man-in-the-middle.

Which would be trivial if they had agreements with the various mostly US providers to quickly get man-in-the-middle signed keys from their CA's.

Although this seems like it would be quick to spot since if you were watching certificate fingerprints change then you'd see the switchover and switchback.

Re: Encrypt your Google chats and make the NSA sad

#98
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

This will only work for average email users if you can pull it off without ever using any of the industry language, or requiring anybody to ever actually do anything with a key. Find other descriptive language to use, and make it require zero extra effort, and you've got a winner.

We learn all the time how to do complicated things on the internet. Facebook isn't instantly trivial to use (though it seems that way now that we know how to use it). Neither is Google+.

The whole problem with PGP is that it's not worth learning to use because it depends necessarily on network effects. If Gmail deployed it, the network effects problem would immediately disappear. At first it would only work within the online webclient, obviously, and enabling it would have big consequences for how/whether client-based access (IMAP and POP) worked.

Re: Encrypt your Google chats and make the NSA sad

#99
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

this would make "intercepts" far more difficult

Yup, Google is doubtless completely in cahoots with the NSA.

... Really? Is that what you are thinking? Apply some rational thinking here. It's simpler than that. Google advertises to you based on the contents of your email. It is not in Google's interests to prevent themselves from being able to read your email, and if they can read it so can the NSA.

Re: Encrypt your Google chats and make the NSA sad

#100

Earlier quoted context omitted.

While it's a bit tinfoil hat, it's not impossible that there could be hardware backdoors in processors or other hardware triggered by a very specific sequences of packets.

What would be hard is also making sure that packet sniffers in the middle wouldn't be able to detect it. Specially with all the varieties of router hardware. Are we going to have a backdoor in all of them that prevents passing on that data?

And you know, given the tens of thousands of people involved in chip design, are we to think that absolutely no one, anywhere, would've leaked that there was some anomalous circuitry in the chip designs which they were told not to worry about it?
Post reply on HN