The situation today is even less conducive to getting the people I email to use encryption than it was 10 years ago. In the past there was maybe a chance I could convince people to install a plugin, or in the case of family members I could set it up myself when visiting. But now everyone uses Gmail, and often uses it from multiple devices, which makes that difficult. There are browser plugins that will try to do GPG in Javascript, but they seem to break routinely with Gmail changes, and the one that used to be most used (FireGPG) was discontinued. And the Gmail app on mobile devices doesn't support such extensions anyway.
The webmail problem is probably the biggest barrier to PGP adoption right now, even above the issues with understanding PGP itself.
I, for example, am capable of encrypting my email but I actively don't care to. I'm in the "I don't, because the content of my email is just not that important." on the poll.
Webmail's prevalence may make PGP adoption more difficult, but I want more webmail prevalence and I don't care about PGP adoption and I'm pretty confident that's the way the world's going to go. Someday there will be something webmail-like which has encryption anyway and that might catch on - I'd even use it. In the meantime? People who need it can use special tools.
NB: Just to be absolutely clear, I'm not picking on you specifically (and I suspect there are many people who hold the same opinion as you). I'm just trying to point out what I see as a problem with the "my email isn't important" argument.
People who need encrypted email will figure out how to do it and I think that's enough for now. I don't think lamenting how slow PGP adoption is makes sense, though - it will never, in its current form, be mainstream.
Unfortunately, the best solution I've found for Windows is the commercial PGP product[2]. It's not free or open source but it does work and it configures itself for opportunistic encryption, so that's a plus.
[0]: https://www.gpg4win.org/ [1]: https://code.google.com/p/outlook-privacy-plugin/ [2]: https://www.symantec.com/desktop-email-encryption
User studies of PGP:
Why Johnny Can’t Encrypt: A Usability Evaluation of PGP 5.0 (http://www.gaudior.net/alma/johnny.pdf)
Why Johnny Still Can't Encrypt: Evaluating the Usability of Email Encryption Software (http://cups.cs.cmu.edu/soups/2006/posters/sheng-poster_abstr...)
On Android you can use K9 Mail [1] with your email and it will automatically decrypt PGP messages using keys within APG [2].
Also, APG it's self still lacks a bunch of features, and it seems to have been abandoned.
I want a Firefox OS phone, but until there is an email client which supports PGP, it will be useless to me.
Mobile PGP. So frustrating.
It should be easy to do such things using Substrate. (I'd even argue easier than via JavaScript, as backend logic code and variables cannot be hidden and protected inside of closures.)
(Put another way: I'm more embarrassed about the subreddits I browse than the emails I send.)
That is probably true for a lot of people. I hope reddit admins shed some light on this: how long are the logs identifying users stored for? What is the chance that they can be stolen, or given up en masse to the authorities? Roughly what number of IP's have been requested by the authorities -- hundreds of them? thousands? Or?
Overused analogy: if a burglar wants to break into your {car,house,...} bad enough, they eventually will. Do you make it easier on them by leaving your windows open and doors unlocked?
i.e with message signing, a third party can prove that a message was sent by you. Whereas with an unsigned email, you'd at least be able to plausibly deny that you sent it. You could claim it was forged.
But then again, with secret and silent data collection systems you're not really in a position to deny anything anyway. I have a feeling you'd have a hard time denying an unsigned email with your name on it to a court if it came to that.
unfortunately a lot of my mails got deleted by the recipients, because there were "some very strange things" (the signature) at the end of my mails and they were afraid of malware like viruses or trojans.
i wanted to increase the level of trust in my messages and achieved the complete opposite.
i stopped signing my mails a couple of weeks later, after a clients secretary phoned me to inform me "i had a virus on my computer".
If you don't want to confuse people when you sign your e-mail, make sure you're using PGP/MIME not inline signing. I've been signing my mail for years and had almost zero problems doing this.
The bottom line is this: the user interface of GPG is awful--among the worst this side of Git. "Barely usable" is the briefest way I can describe it.
And it's not the key exchange that makes it so bad; exchanging keys is the easy part. My gripe is with the routine UI clunkiness of GPG. For example, it's not possible to paste into or use Keepass' "auto-type" feature to type my passphrase into the GPG dialog. So I have to manually type my sequence of 50 random letters, numbers, and symbols nearly every time I receive an encrypted e-mail. It's so bad that unless an encrypted e-mail is urgent, I'll defer it until I'm in the mood to look up and type my passphrase.
Note: it's possible to hack in a pinentry program that is compatible with "what you want" (pretty sure it's doable for keepass). Easier than emulating gpg-agent and/or more convenient than using a smartcard.
I'd use encryption and try to convince others to as well, but I rely on email search too much. I'm sure a lot of people don't bother to 'tag' or 'label' their email, but instead rely on search to find messages with certain content in them. Maybe I'm wrong, but I don't see a way to have both with the server being unable to read the contents of the email to build a search index.
This way attacker could only recover unordered list of dictionary words that were in the message and the list would contain false positives (they could tell whether you write love letters or bomb threats, but couldn't get your password reset URLs).
I also can't use S/MIME even though I got a certificate, I don't know how to use it.
As we've seen recently, this kind of metadata is often just as revealing as the content.
Encryption for email is probably giving you a false sense of security. If you care about privacy, email feels inappropriate to me.
So then the question is, what is the alternative? Honest question—I feel kind of helpless about it.
steganography[1], anonymous remailers[2] (particularly the Mixminion[3] type), the Paranoid Security Guide[4] (which was on HN today[5]), and a nice talk on privacy and anonymity options[6][7]
There were also a couple of lists of darknets on HN recently, but I can't find them right now.
[1] - https://en.wikipedia.org/wiki/Steganography
[2] - https://en.wikipedia.org/wiki/Anonymous_remailers
[3] - https://en.wikipedia.org/wiki/Mixminion
[4] - http://crunchbang.org/forums/viewtopic.php?id=24722
[5] - https://news.ycombinator.com/item?id=6040381
[6] - Part 1 - http://www.youtube.com/watch?v=HHoJ9pQ0cn8
[7] - Part 2 - http://www.youtube.com/watch?v=s9fByRmAHgU
Also, is there any serious steganography product that correctly hides plain text? (I know there are many proof-of-concepts and experiments and toys)
- it's extremely buggy between software (e.g. Jitsi + Gibberbot)
- it's a huge hassle to use on multiple devices
Then PRISM came out and... they didn't care.
Email is the same way: give me a way to, without spending much extra time, use encrypted email on my phone and any computer I come across, and I'll use it. Otherwise, it doesn't seem worth it.
The best thing I can come up with is js based encryption, where the server stores my private key, encrypted. For widespread adoption, though, you'd still need an Android app, an iPhone app, and a Windows 8 app, and it goes without saying that browser-based encryption in js is subject to a myriad of attacks.
I feel about as strongly about encrypting email as I do (did) about encrypting snail mail - not at all.
So, I encrypt my email whenever I'm sending to someone with a key. I sign important emails.
i've tried, and you seriously have a snowflake's chance in hell of convincing any "regular" users of email to bother with encryption, they always look at me like i'm some kind of tinfoil hat nutter.
The only people I email back and forth with that have a GPG key are privacy aware people. Even in light of recent events; it's still very hard to convince people that they should be using encryption to protect their communications!
Email encryption, I think, has the social stigma of being associated with a paranoid state of mind when it really should be associated with the human right to privacy and protection people feel when they lock the door at night or set their house alarm system.
http://arstechnica.com/apple/2011/10/secure-your-e-mail-unde...
You can get a free cert from COMODO:
http://www.comodo.com/home/email-security/free-email-certifi...
What make s/mime easy to use is that those who receive the smime attachment on compatible software can see and validate signatures even without setting up their own s/mime identity. They can also accept your public key so when they do setup s/mime they are ready to encrypt message to you just using the signature attachment on one of your messages.
So s/mime at least has an intermediate value even if you are the only one of your friends using it. You can sign things and they can confirm your signature.
Also gpgtools (https://gpgtools.org) just released a new version that has a plugin for the latest Mail.app. However, public key infrastructure is a little more complicated process, and you'll have to explicitly acquire each person's key, and a signatures can not be validated until the recipient also has gpgtools installed.
As an ex cypherpunk, s/mime seems to have a number of security issues with it. First is how it is generated. When I got my cert from COMODO as outlined above the file was saved from the web browser to my downloads file. This struck me as odd. Does this mean they could have copy of my cert? This is convenient, but keys should be generated securely by the user on their own machine.
Also there is the issue of security in terms of how does the signature work. Does it sign then encrypt, or encrypt then sign, or sign then encrypt then sign again? See the non accepted answer by Adam Liss for a discussion of the security issues of this here:
http://stackoverflow.com/questions/13512026/how-to-check-if-...
Nevertheless s/mime works well in many tools and on iOS devices, and is not nearly as hard as most people think. Someone who wants to sell certs could make a video that even grandma could follow.
There are client-side APIs (e.g. Blob+<a download> or FileSaver.js) for saving locally generated files from JS, though I have no idea if COMODO uses them.
PGP gives you end-to-end encryption, which starts from your computer and ends at the computer of the recipient.
It will be a wonderful day when the RFCs are updated to require TLS for SMTP.
http://www.postfix.org/TLS_README.html#client_tls_encrypt
Depending on your environment you could also do the same thing and require DANE:
http://www.postfix.org/TLS_README.html#client_tls_dane
I am sure exim has an equivalent setting (maybe not for DANE).
The benefits of encrypting the message as well as the transport are mostly for dealing with that fact.
I use PGP infrequently, but for sensitive things; for anything routine and sensitive (passwords), OTR over XMPP chat is easier to set up with most people.
I guess in this poll that's "regularly encrypt most but not all of my email"?
All of the email servers I operate support STARTTLS. Transport-layer security is just as important to me as message integrity/confidentiality/authenticity. If I could get away with it, I would force all SMTP traffic over TLS, just like I already do with my web sites (even my intranet sites are HTTPS-only). As with my human correspondents, many of the MTAs out there don't support SMTP encryption.
I sign every email I send from my computer, thanks to my client's use of smartcards for employee badges. Windows and Outlook both make this really easy to do. Mac OS X, BSD Unix, and Linux? Not a great user experience there. And smartphones? I don't know if accessing a smartcard is even possible. I wouldn't mind putting certificates on my phone as long as accessing them would still require a PIN, but my client's enrollment process doesn't encompass smartphones yet, plus I sincerely doubt that they are as difficult to compromise as my smartcard.
Unfortunately, there were tons of mailing lists and clients that would choke even on the signed messages, plus renewing the certificate and all that was too time consuming.
To echo some of the comments here, I think the main factors making this (PGP, GPG usage) unfeasible at the moment is:
1) Too hard for casual users (=others don't use it)
2) PGP/GPG is ridiculously difficult when using webmail or mobile email clients.
3) Your email usabiliy suffers. With this I'm referring to your ability to search your emails. Once you are using encryption, you can't find anything in it, unless the email is decrypted and saved plain in your email storage.
The usability part is actually forgotten quite a few times in discussion, but I think it's a big problem. If you opt to decrypt and save it, this would be ok, if it happens on your client (local db), but not stored remotely (eg. webmail/imap box). This problem comes with a whole lot of issues attached.
I think it comes down to a combination of how few people use it and how much more work is required. The only people I know who use it are exactly the ones you'd expect: those who do things like go to DEFCON every year.
That's not to say that my other friends aren't sometimes cautious with some of their data, they just go to the length of doing face-to-face sharing of physical media and not having intensely private/personal conversations over the phone. Basically they (we?) all just assume that there's no way to protect it once it's on the wire, so "why bother?".
I can't stress enough how important holding/going-to a CryptoParty (or similar) is.
In my personal life, I haven't used mail encryption since my college days with some crypto geek friends. I do have an OpenGPG card and public key published, but I mostly use it to encrypt data at rest on cloud storage platforms or USB keys.
Even if you think that your email is unimportant and you've got nothing to hide, you probably still don't want people being able to use your email account to take over your other accounts (password reminders) if they get access to it.
However, I do encrypt attachments or drop-box blobs from time to time. E.g., I might make a self-extracting PGP archive of a directory of tax info encrypted with a symmetric key, put it on Google Drive, and send the link to my accountant, having shared the key out of band.
At least Thunderbird and Evolution are being steadily developed now![I jest!]