(Simple) Chrome plugin for GPG/PGP in GMail
thinkst.com
thinkst.com
1) You ask for all data on my personal computer and all data on all websites. What?! I imagine you might require local data access to get my GPG key and Chrome doesn't allow it more fine-grained than that (but forchrissakes tell me that on your site), but why all sites? Why not mail.google.com and gmail.com? Because of apps for your domain?
2) You're providing a crypto product. I want to see your source code, and don't tell me to unzip/tar/whatever your crx.
Direct Link: https://github.com/RC1140/cr-gpg
I am suspicious that that's not really sufficient password protection. What protection do you have from an attack that provides access to your machine's address space? (or chrome's address space)?
I'd like to see the source code before I use this. If that sounds paranoid, it's because if I'm using crypto, it's because I'm concerned about snoopers.
--- edit - source got posted. Thanks!
I'm guessing someone with that sort of threat model isn't using gmail for comms. (I guess even then, it could be useful to verify signatures (when gmail doesn't break the mail) without risking your private key)
This would also mean you don't have to reenter your password every time.
c.f. Zimmarman's Snake Oil essay & its comments today: http://news.ycombinator.com/item?id=2917384
Please grab the new version from http://thinkst.com/tools/cr-gpg/