Re: getross - email privacy /security of system
"RossARR" <[email protected]>
| Newsgroups | gmane.mail.pine.general |
|---|---|
| Message-ID | <[email protected]> |
Ryan Barrett wrote:
> On Sat, 4 Nov 2006, RossARR wrote:
>> As for secure emailing only with other computer literate People, as we
>> learn, we teach others, then they will follow - so we lead by example.
>> "If you build it they will come."
> i wish that was true! unfortunately, history would argue otherwise.
> encrypted email has been around for decades, but it hasn't caught on
> with the masses. most non-techies don't know that email is sent and
> stored in the clear. when they're told, it doesn't usually motivate
> them enough to jump through all through the PGP hoops, especially
> since none of their friends have it.
History is just that. As I said, lead by example, they will follow.
I think if I exposed the problem to those I know, many would start
asking me how to fix the problem. Paranoid is normal, especially with
the snoops & Govt today. And getting worse.
"A state of war only serves as an excuse for domestic tyranny." -
Aleksandr Solzhenitsyn
To fix the problem is what I am up to now, to create a transparent
system that works with little effort if any. No hoops for PGP & Pine.
> it's a couple of classic adoption problems:
> - first, users won't use it until their friends use it, and vice versa.
> - second, users likely won't use it unless it's bundled with their
> client and on by default, like SSL in browsers. the big clients -
> yahoo, microsoft (hotmail/outlook), google - won't add it until enough
> users demand it.
It so happens that Outlook Express & Mozilla, client software, & most
email client software possess encryption of some type now for several
years. Those clients are off the host email system. With a firewall,
that prevents the in-house compromise problem, & a point2point
encryption should work well.
Encryption is being used by many People, & I suspect PGP will be used
more soon. A built in system does help to make the operation transparent
- simple like SSL.
Webmail like Google, Yahoo, Hotmail, not being client software setup on
the users PC, will never be acceptable due to the in-house problem of
compromise. To encrypt there is worthless as was previously stated here
in a previous message. Yet there are times when encryption is not
required at all. Such as this communication we are having.
>> IBE by email address? Sounds interesting. If I send an email, the
>> receiver
>> uses their email address to unencrypt, by typing it in? Anybody that
>> intercepts the message could then type in the email address & breach
>> security. Maybe I am asleep here. I will followup on that, interesting in
> no, it's an asymmetric key system. the email address determines their
> *public*
> key, which is only used to encrypt email. they decrypt email with their
> *private* key, which they keep secret, like a password.
I really need to learn more about that to trust it - sounds good anyway.
Thanks.
--
RossARR
[email protected]
mrossarr.imapmail.org
---end-of-message---
--
http://www.fastmail.fm - Access all of your messages and folders
wherever you are
_______________________________________________
Pine-info mailing list
[email protected]
http://mailman1.u.washington.edu/mailman/listinfo/pine-info