GPGTools – OpenPGP Tools for Apple OS X
gpgtools.org
gpgtools.org
Does anyone know how they got around sandboxing, since that was the problem with Mountain Lion up until now?
I think it's worth defending because even though I was annoyed by it, I did read every letter! Maybe because it's because I'm slightly invested since I started using gpgtools a few days ago and was very impressed by the software, but still, getting people to read copy is a very desirable thing on any marketing site right?
Everything worked great, great enough for me to leave mutt behind and painstakingly move my email archives and everything else into a 21st-century gooified mail environment.
And then I upgraded OS X (I think to jag-wire, maybe?) and spent far too long being sad about non-working GPG. Of course to be honest, lagging GPGTools releases were only part of the reason Mail.app eventually came to be the most hated part of my Mac experience. But lagging GPGTools was the thing that stuck in my craw every time.
I used to be really good at email. I was organized and efficient working in it. But now I've totally given up and moved to GMail. My inbox grows like cancer, with a raft of features I don't use like stars and bayesian recommendations.
In anger, I tried mutt a while back. After hours of setup, I found the magic was gone... but at least GPG signing still worked without a hitch.
GPGTools is not alone with this problem. LibreOffice for example can't probably be installed by many users because the binary isn't signed Apple-style. Many users will get an error message by OS X and just forget about LibreOffice …
Apple implemented app signing by default in 10.8. Users can either turn this off in System Preferences (removing the error), or the LibreOffice team can pay the $100 annual fee to get a properly signed app.
Most users, however, won't know this workaround and it shouldn't be necessary to lessen the security of OS X just to use (or update) LibreOffice.
I'm sure the Document Foundation could afford the necessary app-signing.
At the same time, I assume that the developers are well aware of the delay issue. So what exactly causes the delay? Is there any way to support the GPGTools developers in this regard?
I believe they've patched it in this release though: http://support.gpgtools.org/discussions/everything/4323-cve-...
It's disappointing that their release notes don't mention this.
The point is to make encrypted/signed messages the norm rather than an outstanding event causing suspicion.
Latest MacGPG2 & Homebrew.