Email Self-Defense – a guide to fighting surveillance with GnuPG
emailselfdefense.fsf.org
emailselfdefense.fsf.org
>INSTALL THE ENIGMAIL PLUGIN FOR YOUR EMAIL PROGRAM
I Googled Enigmail as I was not familiar with it. It is "a security extension to Mozilla Thunderbird and Seamonkey." This seems incredibly shortsighted. Tons of people out there are on Outlook, Apple Mail, Gmail, etc. and not interested in Thunderbird.
There are other options, for example the surprisingly EXCELLENT gpgtools.org installer for Mac, which makes it super-easy to add signing and encrypt/decrypt and key management to OS X and Apple Mail. A quick Google reveals the nicely packaged gpg4win.org (I haven't used it). There's also Google's new Gmail GPG plugin (although yes it's beta) https://code.google.com/p/end-to-end/
I know this is the FSF, but I'd hope in the interest of defeating the surveillance state they could set aside dogma.
(Also, that page shouldn't default to the Linux options when I'm visiting from a Mac browser.)
But I thought I'd do things the "right" way. Use master/sub keys, linked identities, with masters kept offline... The friction was _immense_, especially managing the identities, mucking with the keyring files, then deleting the master key from the online keyring, and so on.
I still have my off-site db secure, but I don't look forward at all to opening it again. I don't want to remember the precise series of steps involved before everything worked correctly.
How can I solve this? I just want to manage a few identities (personal, as a citizen, work account, "stuff", etc.), some of them trusting each other.
Common sense makes me think I'm way over-complicating. But I was always told that any other way wouldn't really be secure. I though I would just be very pro-active with key revocation and that would eliminate most of the problem...
But again, that's because I wanted to use WoT. If you want PKI, no need to install anything.
Apple mail also already support encrypting and signing mail (https://support.apple.com/kb/PH11790). In the interest of defeating the surveillance state, one might start by fixing mail programs that do not already natively support encryption?
Both have massive problems and are unstable though :(
1. It's probably better to remain civil in your discourse if you want people to take you seriously, and not just dismiss you as a troll. If you really do feel so strongly about your position, then you're probably doing more harm than good to your cause by firing off such remarks.
2. I doubt that you personally communicate with everyone using encrypted email. If you do, your world is probably fairly insular (and you should probably consider expanding your experience to include communicating with people outside of your comfort-zone).
3. The most constructive response to the parent post would probably be a suggested plan of action. I'm sure that many here would be all-ears to even a decent framework for convincing the average person to use encrypted email.
Once you can count on contacts using GPG, the path to encrypting is much easier.
To use GnuPG correctly you need explain to average Joe concepts like:
* PKI
* Key signing
* Web of trust
* Revocation key
The problem is that, as Einstein said: Everything should be made as simple as possible, but no simple.Same problem I can't talk bitcoin with most of my real-life friends. They are incredibly smart people, but they are not familiar with key concepts about BTC and don't wanna wrap their minds around it when we're hanging out having fun.
People just cry out to the programmers to "just make it easier".
Well there's only so far you can go on the easy scale until you start sacrificing security and integrity.
People need to learn some of the fundamentals and basics you can't run away from it forever.
It's like someone saying "Mehh I don't like calculus ... why don't these mathematicians make it just easier? Why do I have to learn about differentiation? Make it so easy my grandma could differentiate this equation"
Instead we force every kid to take the pain a bit and learn some damn basics.
Same should go for computing. Schools could teach the kids the basics of protecting their communications on the internet. Give that 10 years and Public/Private key encryption is a piece of cake for every reasonably educated adult in the society and they are no longer buzzwords because everyone grew up with it and remembers their 8th grade when they learned all about it.
Actually, modern textbooks do exactly that: they try to find pedagogically better ways to teach this stuff.
And sometimes newer developments really simplify things.
All that apart from the simple fact that mathematics and the user interface and user interaction are not even in the same ballpark.
Your comment seems a bit lazy to me. Just not in a way you expected to.
Unfortunately, all the glamour and the money and the code seems to track vanity crypto projects, and not so much of it goes to projects that make GPG more usable for normal people. Kudos to Google for taking a stab at correcting this.
The idea that you go to the store, pick up a small box, and it will do all the security for you is the stated goal of freedom box (https://freedomboxfoundation.org/). Once transparent end-to-end encryption that avg joe can use get traction, mail encryption will hopefully become default.
Except for the part where they want you to upload your private key to them. But that is optional.
They still don't really care, but at least my communication with them is encrypted.
Also, they see that using encryption is not hard (once set up), except that they have to type in a password from time to time.
It was a fairly smooth workflow except for having to type in your passphrase in for everything.
Recommended use is with Thunderbird and Enigmail on desktop, where you should also have your mail filters sorting your mail to the IMAP folders.
To install use F-Droid. F-Droid ist the Open Software Repository for Android. https://f-droid.org/
This is/feels like the recommended way to use PGP at the moment or at least the most useable.
There's an open issue to add PPG/MIME: https://code.google.com/p/k9mail/issues/detail?id=5864
There's also an open bounty which can be contributed to: https://www.bountysource.com/issues/815255-pgp-mime
You can get the latest K9 Alpha from here: https://github.com/k9mail/k-9/releases/tag/4.904
..and should use OpenKeyChain instead of APG, since its no longer maintained. http://openkeychain.org/ (also available on F-Droid)
This at least removes the need to push decrypt on every Message although thee might be Bugs.
http://manual.mailmate-app.com/preferences#openpgp_and_smime
I can't speak to any shortcomings in its PGP support, as it's not something I personally use, but I've been using it as a MacMail/Thunderbird replacement since last September and have been quite satisfied.
If you were concerned about what was being sent and to where, you would probably be better off to capture all traffic originating from your computer and verify that nothing extra is being sent, and that the destination is appropriate. Whether it was sent by open or closed source software is utterly irrelevant
FireGPG was super easy to use with Gmail (that said, I suppose Google would have grabbed the cleartext in the interim draft state anyway)
Google's initiative seems like a good idea of course. The command line utility itself could use some MAJOR love tho.
And even the best GUI clients are very confusing for new users. When I explain the concepts behind the trust model they get it. When they have to use the UI they dont find what they need.