Getting things right, including disaster recovery, should be done correctly and silently by default.
Getting things right, including disaster recovery, should be done correctly and silently by default.
I think people should use GPG without any of the extra options, bells, and whistles. If they really need advanced usage stuff, they should use something better than PGP.
What happened to making the right thing to do the easiest thing to do?
Correct me if I'm wrong, but it seems like a lot of the issues are in implementing PGP in email, not in the cryptography itself. If you made a messaging app that automatically used best practices PGP without any of the email holes/workflow issues, would there still be something significantly better for data at rest?
The cloud service offering should be email and instant messaging, email, and some levels of sync (but not the private key).
It should be/do:
- Open source
- Generate a private key as part of the setup
- Upload your public key to the public key servers
- Access camera to read a key (qr code) from another device
- Display QR code of your private key (so you can sync it
to another device)
- Display a QR code of your public key (so someone you meet in
public can copy it and you can then trust that key)
- Show confidence levels based on how trusted a key is. Help bubbles can explain the confidence level.
- Import your contacts
- Periodically query public key server to see if your contacts have uploaded a public key.
Advanced options like importing your own key, adding "Trusted keys", and using your own email provider should also be a thing. I suppose keys could be exchanged using NFC as well, but I think that's still beyond most people.For the most part, this should be presented as a secure communication app/service. If you want to start communicating securely with someone, you ask them to install the app. You should be able to do it while grabbing lunch together(which results in trusted keys exchanged between the both of you). Or you can invite them to use the app, which results in them getting an encrypted email address and IM system.
Finally, encrypted emails and messages could be synchronized between devices, maintaining state.
The goal of the app and service is that Johnny will see this app as their secure communication. They will know that until the other person sets up their copy of the app, that they can't send a secure message to them. And since it relies on public gpg servers, if they come across an advanced person out there that setup GPG on their own, it will be able to email that person just as easily (and that advanced person can email the app user).
- Open source
- Generate a private key as part of the setup
- Upload your public key to the public key servers
- Access camera to read a key (qr code) from another device
- Display QR code of your private key (so you can sync it
to another device)
- Display a QR code of your public key (so someone you meet in
public can copy it and you can then trust that key)
^ Keybase [1] has a mobile app in the works that will theoretically be able to do all of this. I'll be curious to see how it comes along.- [1] https://keybase.io/
Projects like this are why I continue to use Fdroid, Cyanogen AOSP, and believe the open source movement on mobile is worth the hassle. Oh yea, that and Password Store.
- Dominik
Learning GPG is really really hard. Testing an assumption takes lots of thinking and many complex commands, undoing something is hard or impossible and it's never obvious how to do it, and doing something wrong can mean disaster. It's not so much "pgp is hard to use" but "pgp is hard to learn".
This article is a great example. I think I've got a pretty good understanding of how public-key crypto works, but there's no way I could have put together the steps myself, I'm just blindly following the words of the Great Ones, Keepers of the Source.
There really should be an easy-setup mode which defaults to the commonly recommended options. Give the user fewer options and they will make fewer mistakes. I am surprised there isn't such an option actually. Most things in the FOSS world have be streamlined/simplified over the past decade (for example look how difficult it used to be when partitioning a hard drive during a Linux install, now it is all done for you if you just want the defaults).