People want their email on their phone, on their laptop, and on their tablets. They want to keep those emails when they get a new phone, or lose their phone, or it gets smashed.
But most importantly, people want others to be able to know that others can read their email, and unless the people you are emailing know how to decrypt PGP encrypted email (or use the same client as you), they'll just get a mess, possibly with instructions on extra steps they need to take to decrypt it. And when you (in practice) are only able to email people using the same client, might as well just pivot the product into a secure messaging system like Signal or Telegram.
And that's not even getting into the amount of work and discipline something like PGP needs to work. Did you lose your master key? well you're fucked, might as well start over new and convince everyone you have ever talked to that you are still the same person.
People generally aren't against PGP because it doesn't work or the security isn't good enough, they are against it because it's complicated and difficult and punishes mistakes hard.
To most people, perfect security is useless if the average joe can't use it. Perfect security is useless if it requires constant diligence from users to prevent mistakes which in effect delete every bit of data you have. Perfect security is useless if you need to use out-of-band secure signaling in order to setup a secure channel.
That is why PGP is being dismissed. Because no matter how many coats of lipstick you put on that pig, at the end of the day it's a complicated, damn near user hostile program that punishes mistakes. And it's really fucking hard to make a "user friendly implementation" of something that will instantly and irrevocably destroy all of your communication the first time you lose your phone, or you have a house fire, or a theft, or any other number of things.
I have bad news for you. This is the entire foundation of https. Those root certs aren’t there by magic.
Since I've moved, every time I see PGP being dismissed as too hard to use, I feel like I'm back in some echo chamber where people just keep repeating that and start to believe it.
Did I read that correctly? PGP is popular in Germany?
If so, I'd love to hear more please!
So yes it's popular... in the security community. In the Netherlands, it was also used, but usually reluctantly when the other party asks for it and it cannot politely be refused.
I also used PGP to communicate with customers from Germany but it's not that every German customer of mine uses it.
I’ve been thinking a lot about secure, end-to-end encrypted email replacements and have grappled with many of the same questions that Open Whisper Systems (the makes of Signal) had to think about. A centralized solution favors convenience, and will likely bolster adoption, while a decentralized solution will probably be harder to use and so won’t build its critical mass of users.
The person who comes up with a distributed, decentralized, end-to-end encrypted email-killer receiving broad adoption deserves some kind of very prestigious award.
Which is not to say it's not too hard. As my parents age, I notice their capacity for understanding new things decreases. It's not just technology, also games with new logic that they haven't seen before takes a while to grasp. Sometimes I feel like I'm talking to a four year old except that they understand and remember everything that existed 20 years ago. How they are ever to understand the concept of encryption, I don't know, let alone find the buttons to import a key from key servers.
For people below ~50yo, however, enigmail shouldn't be beyond them. The issue is that they don't know why they should care and therefore don't take the time to learn what it is.