A friend and I were discussing this over dinner and couldn't really pin point the reason. Both of us came across ideas around what could be done to make the situation better but were drawing somewhat of a blank on the question of "why is this not already done?".
Ask HN: Why is PGP not used widely?
1–10 of 74 posts
Re: Ask HN: Why is PGP not used widely?
#2Re: Ask HN: Why is PGP not used widely?
#3Simple and secure mail is an unsolved problem.
Re: Ask HN: Why is PGP not used widely?
#4Re: Ask HN: Why is PGP not used widely?
#5Re: Ask HN: Why is PGP not used widely?
#6Even people who have taken the time to install and use PGP, and who seem to want privacy, make weird mistakes such as "Messages encrypted to public keys, to passwords and passphrases, and PGP messages not encrypted at all!"
http://ritter.vg/blog-deanonymizing_amm.html
Usability of Security: A Case Study of PGP 5.0 User Interface http://reports-archive.adm.cs.cmu.edu/anon/1998/abstracts/98...
"Why Johnny Can't Encrypt" http://www.cs.berkeley.edu/~tygar/papers/Why_Johnny_Cant_Enc...
Re: Ask HN: Why is PGP not used widely?
#7Moreover, it's certainly not in SV's vested interests (regardless of recent protestations to the contrary by google, facebook, etc) to see secure mail become the standard, and by extension to broadly educate and move the consuming public to a mindset of security first.
All of that said, the average end-user is/would be befuddled figuring out the use of shared pub keys, the web of trust concept, and in moreover, PKI in the bigger picture.
And even if you could get broad use of pgp going for message payload privacy/security, you don't solve the problem of metadata if you are using the current email protocol.
It's long past time for a new persistent messaging protocol that addresses metadata leakage and payload security comprehensively. There are people working on this now. Hopefully that will drive some positive steps forward on this issue.
Re: Ask HN: Why is PGP not used widely?
#82. Encryption is extra risk for your data. If you lose the keys, you lose the data. People are bad at backing up their data, why they would be better at managing their keys? Being sloppy with your keys means that somebody can impersonate you with more credibility (what if banks would accepting PGP singed orders in email)
3. Value from widely used PGP happens mostly in society level. Encrypting any particular piece of data has negative expected value in most cases.
4. Using PGP requires understanding the basic concepts and using it well is not that easy (lots of pest practices). People don't know any of this stuff. Even public and private key is far out concept for most people.
Re: Ask HN: Why is PGP not used widely?
#9- Lacking GPG support on iOS devices, the available apps are not integrated with Mail.app (iOS).
- GPG support on OS X devices is usable with Mail.app and GPG Tools ((https://gpgtools.org/) but encrypted mails are not searchable. I use folders etc. but it is still often a pain do browse manually through mail after mail until you find the one you've been looking for …
- Webmail, for example Gmail or Outlook.com, and GPG don't fit together well – if at all.
- The public keychain is not made for use on more than one device, i.e., it's not sync-ready.
- Key verification is bothersome, i.e., you have to attend key signing parties etc.
- There are political issues, e.g., should you upload your keys to key server? If so, with or without signatures? If you upload signatures, you create not only a web of trust but you also expose at least parts of your address book.
- Key servers store long invalid keys and there is no way to remove such keys. The PGP.com key server removes keys if you don't confirm them by mail from time to time. On the other hand, the PGP.com key server only accepts one key per mail address.
- Etc.
Re: Ask HN: Why is PGP not used widely?
#10PGP is great. Everybody in tech has the skills to use it. But for non tech people it is still to difficult. But since the NSA affairs many crypto parties happened, specially in Germany. On this crypto parties tech people are teaching non tech people how to crypt emails with PGP. I think that is a good start and I hope we will see more crypto parties in future.