Edit: added word "outgoing" for pedant below. ;) Of course it'd be nice to get their public key too if you had to correspond back without going through say their https website.
Edit: added word "outgoing" for pedant below. ;) Of course it'd be nice to get their public key too if you had to correspond back without going through say their https website.
It needs some really good integration with an email client somewhere, where addresses are picked up from a public key server and automatically encrypted. I'm picturing an iMessage style thing where as you're typing someones email address, the keyserver is getting pinged and the address turns a different color and a lock icon appears by it. Now all your correspondence with that person is encrypted. PGP purists might not like it ("but you're automatically trusting some random key!! The web of trust, the web of trust!") but it would be a step in the right direction.
[1] Statistic I just made up.
https://en.wikipedia.org/wiki/Identity_based_encryption
[Edit: it pains me to say this, of course; I am not a fan of systems where some other party or coalition of parties can decrypt messages. However, it would be better than what we have now, and it is closer to the "putting a letter in an envelope" abstraction.]
gpg --auto-key-locate pka -ear mike(dot)cardwell(at)grepular(dot)com
gpg then automatically looks up the TXT record for "mike.cardwell._pka.grepular.com" in the DNS. Which gives it:
"v=pka1\;fpr=35BCAF1D3AA21F843DC3B0CF70A5F5120018461F\;uri=http://grepular.com/0018461F.pub.asc
It then automatically fetches my public key from the URL in that record, checks it matches the fingperint, and then imports it.
For extra goodness, the DNS for "grepular.com" is secured with DNSSEC also.
The technology exists for sharing public keys and using PGP. The major mail providers couldn't care less about providing user interfaces for it though.
We need a system that lets people encrypt messages without having to wait for the receiver to do anything. That's the point of IBE: your public key is your email address, you get your private key from the service of the sender's choice. The service clearly needs to do something to verify your identity, which is the weakness -- but it is still better than what we do now, and it does not require us to wait for everyone to upgrade their email clients.
I received one a couple of weeks ago and it works great. I also have an OpenPGP v2 smart card, a USB smart card reader, and a reader built into my Thinkpad.
Edit: ok your edit makes more sense now :)
I would like this, too. Internet, please get on that.
We may yet return to that stage.