GPG is awesome; GPG is terrible
blog.setec.io
blog.setec.io
I dream of a day when secure communications is simple and usable by all.
If you want the masses using encrypted email the key distribution needs to be as seamless as possible. Right now it is the opposite of that. Key management in GPG is a straight up nightmare of dozens of keystores and downloading text files and arcane commandlines. Public key distribution is the elephant in the room with encrypted email. Well, that and the fact that so many people use webmail now and all major webmail providers have completely given up on encryption. I've even seen arguments that since Javascript can never be fully trusted that webmail will never support encryption. Those arguments feel a bit like the "if it can't be perfect it is useless" argument you see a lot in crypto circles that keeps people using entirely unsafe technologies instead of safer partial solutions.
I suspect that people would gladly accept the ability to send and receive encrypted, signed emails, but the hassle factor of getting set up is simply too high.
In the computer tech world, we do rank ourselves. We post w3c validation badges on our page, we run our sites through ssllabs.com for a security report card. We work towards being an IPv6 Sage from he.net. So why not a GPG contest? Keybase might be a good site to organize such things.
Generate a key and upload it to a keyserver is a basic level. You key can be graded based on bits (1024 vs 2048 vs 4096) and algorithm chosen. Send an encrypted email awards more points. Send a signed message for more points. Receive an encrypted message (and respond with the unencrypted text) is more points. Receive 3 emails and reply to the one that is properly signed for more points.
At some point in your journey you can start socializing. Advertise on your blog/github/keybase/social media that you are participating in a gpg contact contest. People can send you signed messages, you can send to them. You both sign and forward the message to keybase, who uses the signature to validate both of you exchanged messages with gpg. Keybase could even provide uuid/tokens to hand out (encrypted) and further validate. The more gpg contacts you accumulate, the higher your score. The "worked all states" from ham radio could be an achievement in gpg contesting as well.
I've been looking at truly peer to peer communication systems to use on an amateur radio mesh network with no internet access. The best solutions have encryption baked in. I would have to get a major project going to rip the encryption aspect out in order to use them on amateur frequencies/amateur power levels.
What's great about this guide and approach, is that it works in any text field, including webmail.
Should I add a small thumbnail photo of myself in my key? Or is that generally frowned upon?
Finally, are there good sources on how I would create a 4096 bit master key, and then add a 2048 bit subkeys for signing and encryption that I can add to my smart card which only allows for keys up to 2048? Would generating 2048 subkeys allow me to still decrypt gpg encrypted emails sent to me encrypted with my 4096 bit master key?
Still trying to figure this all out after picking up some YubiKeys
The photo question is an interesting one - some people frown on it, some people like it. Personally, I lean towards not adding them, just because the number of times I've actually checked it is so low (maybe once, ever.) That being said, I don't think people feel so strongly that they'd refuse to use or sign your key over it; they might just not sign that particular uid. (The photo is stored the same way an alternate email is, basically.)
Properly setting up an offline subkey involves some rather archaic incantations; even more so when you are burning them into a smart card. Specifically, I would probably use some combination of the above instructions (to get my gpg.conf into the correct state), and then something like this guide: https://gist.github.com/abeluck/3383449
Specifically, I would look for a guide that instructs you to have a master key that is valid only for certification. I have a personal dislike for allowing your "master" key to be used for encryption, because it incentivizes you to do things that are not best-practice: specifically, using it. In the ideal world, your master key is kept, encrypted, on one (or more) USB drives that are all kept in various safes, and are never plugged into a computer that has an internet connection. Bonus points if the computer isn't used for anything else either. This is because your master key is the Thing That Must Not Be Compromised -- or you need to revoke the entire key and can never use it again. If a "working" subkey gets compromised, you can revoke it without losing all of the certification effort you've put into validating your identity in the web of trust.
I don't consider myself an expert, and the guide is compiled from synthesizing several other guides. If anyone has tips on how to improve the guide, or spots any errors, please do let me know so I can update it.
GPG requires a deep understanding of things it's based on: web of trust, public key, private key, revokation key, keys repository structure etc. And these things are really really hard.
It's not the easiest tool in the world, but it's not that much harder than, say, using a nonstandard compression tool.
Another issue common people don't think about: How do you backup your key and actually restore it in such a way that you can read your old mails again?
Oh, and how long was GpgOL not working for the current Outlook version? Another big stone that lies in your way.
And I wish tech-savvy people would just "allow" the workflow you described above.
I have encountered too many discussions where people got scared off, because "the web of trust is the only acceptable way", and "check your government-issued ID cards! Yes, even if he's your best friend since kindergarten and he gave you the key in person!".
Nerds love playing the key party game. They love calling some first-level support and asking to recite the key's fingerprint. They love showing how goddamn smart they are. And that puts everyone else off.
It's another expression of the "security is binary" mindset that also hinders opportunistic encryption. Because there is something better we must not use this.
Lose the web of trust (and "marginal trust" is something only techies can come up with...), have a nice UI with only four or five buttons, make it work with all Outlook versions and make it work with webmail (at least GMail) and you may have a winner.
The last one is the big one and nearly impossible for anyone else, but Google seems to be working it (end-to-end for Chrome).
Which is actually two issues. One, the interface; there's a GPG thingy for GMail, but it's kind of junk. Two, and no less important: how do I search my archive?
(Did you just say "download it"? You lose. Did you just say "don't use webmail"? You lose again.)
This is a community thing. You need to give to get them to give. And you're not giving.
The workflow you described is easy and usually good enough and can be achieved with thunderbird + enigmail alone.
Why not have sane defaults instead of asking for all these parameters?
There are apps that use crypto which have a much nicer interface. Telegram and Schildbach Bitcoin Wallet come to mind. Even BitMessage is easier to use.
If you can use Thunderbird I see no reason why you can't use GPG
(I loved EnigMail, back when I was using it)
If you want secure email then use an email client that doesn't suck at it?
(That said, the key management part of GPG doesn't become easier just because you use Thunderbird)
Only because of some irrational dislike in the Open Source community do we even have this discussion. Self-signed X.509 certificates would have done more for the cause of "secure email" than all GnuPG advocacy ever did.
Uh, nope, nope, nope. You can't even revoke those things AFAIK. Also I'm not sure how those are any easier than using PGP.
Mail clients should automatically query keyservers for all of the addresses on the TO: line and automatically import the keys they find. Instead they assume you're going to pass keys around on USB sticks or some such nonsense and import them into GPG by hand using some arcane syntax. It's ridiculous.
https://github.com/Spark-Innovations/SC4
Runs in a browser. Modern crypto (elliptic curves instead of RSA). Audited code. Open source.