Between email phishing attacks, Dropbox and everyone else on HIBP, I honestly don’t know what advice to give non-technical users besides put it on a USB drive and drop it off. I can think of security pitfalls with literally any other file transmission technology that is easily accessible to non-technical users. If anyone has a suggestion I’m all ears.
Edit: Another is you need to manually enable the checkmark to 'encrypt file names'. Otherwise all file names are in the clear.
You could recommend to those non-technical people to either:
- Use Signal
- Sign up to two free ProtonMail accounts and use those to exchange with one another. That way they’re both e2e and don’t leave the eco-system. And no setting up of PGP keys and such like, and a nice web UI.
If they’re non-technical I wouldn’t suggest PGP IMHO. It’s actually easier to setup S/MIME for non-technical people (I’ve had some success there myself).
Of course part of this is that no one has solved the UX and usability and that it never reached mainstream in most ‘typical’ email clients. To set it all up you have to be fairly technical. When it should just work out of the box - like Signal.
Such as?
It seems the answer is Brian Warner's magic-wormhole. You're gonna see lots of file transfer sites with wormhole in their name, but if you want security you should use the original one, which is BW's m-w.
It is implemented in Python [1], so it's hard to install.
So someone made a Go version of it [2] that has binaries for windows, Mac, Linux, BSD etc. But it's command line so maybe not suitable for lay people.
So another person made a GUI for it that also has binaries for all OS [3].
Also there is an android app [4]. Someone needs to implement an iOS one.
[1] https://github.com/magic-wormhole/magic-wormhole/
[2] https://github.com/psanford/wormhole-william/
[3] https://github.com/Jacalz/wormhole-gui/
[4] https://github.com/psanford/wormhole-william-mobile/
TLDR: ask them to install [5] and [6].
[5] https://github.com/Jacalz/wormhole-gui/releases/
(click on 'Assets' under 'Latest release' and download the zip or tar.gz for your OS)
[6] https://play.google.com/store/apps/details?id=io.sanford.wor...
Try it, it's usage is cute and really feels like magic.
. .
Edit: Discussion from few days ago. The creator is in the comments.
gpg -c secretfile.zip
Not sure it can get much easier? To decrypt: gpg secretfile.zip.gpg
The point is that gpg is a tool that most people either already have or can install in a trusted way without downloading binaries from public web pages. Even more common to have installed is openssl: openssl enc -aes256 -in secretfile.zip -out secretfile.zip.enc
openssl enc -d -aes256 -in secretfile.zip.enc -out secretfile.zip
Using these tools are perfectly secure for all practical attacks. The hard part is transmitting the password over a secure channel.Public key encryption is even more useful, but requires a little more knowledge on the end user's part on key pairs, signing keys, publishing them etc. Should an end user just wish to transmit an encrypted file then symmetric encryption is easier to understand.
I don't think it's even the case that the OpenSSL project wants you to be using their code this way. It's just that Unix nerds (hey: it me) find things like this and adopt them, then write things about how they're "perfectly secure" in message board slapfights. It's a microcosm of the whole problem.
What specific tasks have you found difficult?
However most people complaining about PGP's UI go on to explain that this is why you should use Telegram or WhatsApp. That line of reasoning is just bogus.
Which is why age has gone nowhere, and pretty much everyone keeps using PGP.