Most people want to continue using webmail though. That's why Mailvelope is so awesome. Continue using webmail, but just have an extra button added which opens up an editor with a bit "encrypt" button. Pretty easy, and pretty safe.
732 karma · joined April 24, 2009
[ my public key: https://keybase.io/barnaby_b; my proof: https://keybase.io/barnaby_b/sigs/Lv1lGdoU1TpEjkbnOYOqcb6R4kBpkDAigV3KPFE_miU ]
Most people want to continue using webmail though. That's why Mailvelope is so awesome. Continue using webmail, but just have an extra button added which opens up an editor with a bit "encrypt" button. Pretty easy, and pretty safe.
The problem with plugins though is that very few people go out of their way to install browser plugins. Having an integrated option is way more useful. So some people have to encrypt/decrypt in-browser using Javascript (like, how tutanota and protonmail do it, or like whiteout.io does, or like anybody can do now using the keynote.io API). I know it's not ideal, but it is way better than nothing. It won't stop the NSA, but it will stop hackers, email leakers, doxxers, and big-data email-mining algorithms.
I do know a team whom you should work with: keybase.io
Keybase.io have an early-level product which would help with your keyserver issue. It has a CORS-enabled API, a commandline tool, an online interface for encrypting, signing, verifying, etc. and a "ring of trust" tool that follows the modern social network model (where, you can "track" somebody and it auto-signs their keys each time they upgrade.
IRL if somebody intercepted all of your mail, opened the envelope and then put your private letters and bank statements in their own envelope to re-send it, then told you they were doing this to shape postage traffic because they physically cannot handle certain kinds of packages to your location, then you can both A) Believe them that they cannot handle such packages and B) worry about what goes on during the process of opening and repackaging your mail. You don't know the employees doing the repackaging and what if one of them moonlights as a thief. The post was about A, my response was about B. Sorry if it's off topic but you can and should take steps to protect yourself without interfering with their bandwidth shaping.
1) GoGo are blocking youtube in favor of their in-flight paid media services not just for badwidth
2) GoGo's MITM attack has little to do with media content but rather more about being able to read all the communications of passengers for "national security" purposes.
If they are decrypting and logging your traffic (including passwords) and communications, then I assume their scheme can be defeated by a VPN. If you want to send intimate messages to your lover, or discuss a political protest while in flight, without some nosy GoGo employee reading it, then probably using OTR (like Cryptocat or pidgin/adium), PGP (like mailvelope, enigmail), and ZRTP (Redphone/Signal) are a pretty good idea.
I wrote javascript before there were frameworks when it was just libraries like mootools and dojo and jQuery sitting on server-side templates. Today I write CORS apps with Backbone.js+Marionette.js+require.js+grunt+qunit and it solves all kinds of problems and I love it! I'd never go back to javascript without frameworks. As soon as this project is over I am gonna try AngularJS to see what the hype is about.
In this article mailpile worry about users who need an airgap. What worries me is whether creating features for airgap users makes anti-features for users like me who just use PGP when mailing with my parents, my wife, and some friends. We just want to avoid our secrets being part of "Big Data" and as a side benefit we resist passive surveillance. Mailvelope (which is "easy") is complicated enough for my parents, they would never add the complexity of an airgap. We just want easy encryption, even if it isn't totally NSA-proof.
Have you had issues getting OTR to connect sometimes? Myself and about 5 friends have been using OTR with ChatSecure on the phone and pidgin on the desktop. Sometimes the OTR connection just doesn't engage, and we suspect it's because there are multiple instances of the chat client signed in and it like "crosses the streams" or something. CryptoCat has similar issues. Is there a perscribed way of using OTR that won't give us these problems?
TextSecure hasn't given us any problems yet ... though, we never see the encrypted text messages in our SMS, even when we use textsecure over google voice. Does TextSecure just bypass actual SMS channels?
Bitcoin already has a better user experience than banks. Just give it another year or two, to the point where bitcoin will be invisible to users the same way that Linux is invisible (yet, the world runs on it). These services will be rewritten with bitcoin under the hood and nobody will even know or care.
While it's not a guarantee of privacy, open source does significantly increase the likelihood that invasions of privacy and security vulnerabilities can be discovered by enthusiasts and journalists. Right? Wouldn't that be preferable when selecting a privacy app?
I do own bitcoin, and I buy lots of stuff with it all the time. I can't recommend it enough.
1) Instead of waiting 3 days for a bank transfer to clear (or for a check to go through the mail), you could pay your rent through an app like this in seconds using bitcoin (and not pay 3% for the convenience of instant payment).
2) If you're working remotely in a different country then you could use this app with bitcoin to pay neither credit card fees nor SWIFT fees for international bank transfers.
3) If you're an early adopter and your bitcoin appreciate over time you'd effectively be paying tomorrows rent with a big percentage discount with todays BTC purchases if you could use this app with bitcoin.
etc. etc.
In all seriousness.
HUD + Unity (just like iOS before it) will simplify how to use menus on a tablet interface... especially once the speech-recognition part is added.
If you think that the pace of technological change is too fast, or if you think that the music is too loud and those young hooligans should get off your lawn... then please stay on XP; but don't hold back the rest o us who will move forward without you. I look forward to your similar rant against Windows 8 with it's hand-held interface design.
A lot of the really bad practices that hit us with long-term costs come from this era... and a lot of the misconceptions we have about programmers being nerdy anti-social types come from those personality tests, because they didn't test whether you'd be a good programmer... they tested whether you would sit in a production line and push buttons repetitively without talking to others.
So... no, I don't think that a return to the factory model is the solution. It's been tried and it really did not work. I think that software is big enough of a shift that it warrants removing the traditional business hierarchies and ceremonies of authority, and to create a new model that is not the old factory model.
Would anybody recommend any other unit-test frameworks for mocking stuff out?