Live data from Hacker News

End-To-End – OpenPGP Chrome extension from Google

code.google.com

1–10 of 173 posts

Re: End-To-End – OpenPGP Chrome extension from Google

#4
"Please note that enabling Chrome’s "Automatically send usage statistics and crash reports to Google" means that, in the event of a crash, parts of memory containing private key material might be sent to Google."

I hope that has more than a FAQ warning when they release it to the Chrome Store. Otherwise....:/

It isn't perfect but it is probably the best in-browser option given the constraints available.

Re: End-To-End – OpenPGP Chrome extension from Google

#5
post #4

"Please note that enabling Chrome’s "Automatically send usage statistics and crash reports to Google" means that, in the event of a crash, parts of memory containing private key material might be sent to Google." I hope that has more than a FAQ warning when they release it to the Chrome Store. Otherwise....:/ It isn't perfect but it is probably the best in-browser option given the constraints available.

That makes it largely unusable even to test for a few users, I guess.

Re: End-To-End – OpenPGP Chrome extension from Google

#6
post #4

"Please note that enabling Chrome’s "Automatically send usage statistics and crash reports to Google" means that, in the event of a crash, parts of memory containing private key material might be sent to Google." I hope that has more than a FAQ warning when they release it to the Chrome Store. Otherwise....:/ It isn't perfect but it is probably the best in-browser option given the constraints available.

That makes it largely unusable even to test for a few users, I guess.

simple, just turn that feature off.

Re: End-To-End – OpenPGP Chrome extension from Google

#7

This is really great news. But even better would it be if they'd incorporate it directly in gmail with a polished user interface.

No it wouldn't be better. You'd just have yet another LavaBit that claims ultimate security but has no teeth. The private keys must never touch the DOM, whether it comes from Google's servers or put there by an extension, otherwise it's vulnerable to someone hijacking/NSL-ing the gmail session.

Therefore something must be installed on the local computer, whether that means a Chrome extension that has access to localStorage (like this project) or some standalone app.

If you're worried about UX, it looks like this project is meant to interface with gmail specifically, and extensions are able to alter the experience so I imagine it will be reasonably easy to use.

Re: End-To-End – OpenPGP Chrome extension from Google

#9

Earlier quoted context omitted.

That makes it largely unusable even to test for a few users, I guess.

simple, just turn that feature off.

If you wanted this to be available for the general public then it could be slightly more troublesome.

Re: End-To-End – OpenPGP Chrome extension from Google

#10
Isn't this contrary to Google's goals as an advertising business? If people are using end-to-end encryption, they won't have cleartext emails to mine, &c. I need to wonder what the catch is, because there is definitely one: does Google own all the keys, or does Google secretly own all the keys?
Post reply on HN