Is there some simple guide?
edit: all I see here
https://github.com/google/end-to-end
is
We’re releasing this code to enable community review; it is not yet ready for general use
Basically, clone the Git repo then do:
./do.sh install_deps
./do.sh build_extension
This results in an extension folder that can be installed via Chrome's developer mode.Disclaimer: not affiliated in any way and never used it myself
http://googleonlinesecurity.blogspot.com/2014/06/making-end-...
[1] http://googleonlinesecurity.blogspot.com/2014/12/an-update-t...
Wonder what they thougt there? Windows is where the majority of users are, it's where the people who can't (or don't want to) use command line tools for encryption are.
Why would you even approach this from a Linux-first angle? I'd understand if it was because the developers are typically Linux users and they want it thuroughly tested before shipping a user friendly version (i.e chrome ext for windows).
So long as the server has access to your plaintext as you compose it, the security is compromised and a third party has it. And then if the recipient views the plaintext from a browser...
If you want the email to be secret, it must be in it's encrypted form before the browser even knows about it ... but at that point, why not just use a different, well vetted client program for email?
Anyone have any names?
Now, of course, you have to get used to Mutt first :)
Most people want to continue using webmail though. That's why Mailvelope is so awesome. Continue using webmail, but just have an extra button added which opens up an editor with a bit "encrypt" button. Pretty easy, and pretty safe.
I thought that the google thing would be implemented along the lines of the above service. I didn't realise the server still has access to the plaintext as it it composed?
More than that if the third-party service is compromised they can MiTM your encrypted communications anyways.
You're also relying that the third-party extension used for encryption hasn't been tampered with on their end.
For the points you bring up, at least in the current nerfed extension they aren't really an issue. Key exchange does not happen through the extension or through yahoo, it has to happen out of band. In addition, since this is just the developer preview, AFAIK there is no extension distribution except through github (and so no updates to auto-download). You have to build and install the extension yourself.
Key exchange and extension verification are still two difficult remaining problems, but they are hopefully not insurmountable.
(please read about things before taking it on yourself to educate others...)
It just seems like an unnecessary and avoidable risk.
Security is subject to browser exploits, that's true, but that has nothing to do with what you were saying above.