Re: getross - email privacy /security of system

"RossARR" <[email protected]>
Newsgroups gmane.mail.pine.general
Message-ID <[email protected]>
Ryan Barrett wrote:
> On Sat, 4 Nov 2006, RossARR wrote:
>> As for secure emailing only with other computer literate People, as we
>> learn, we teach others, then they will follow - so we lead by example.
>> "If you build it they will come."

> i wish that was true! unfortunately, history would argue otherwise. 
> encrypted email has been around for decades, but it hasn't caught on
 > with the masses. most non-techies don't know that email is sent and
 > stored in the clear. when they're told, it doesn't usually motivate
 > them enough to jump through all through the PGP hoops, especially
 > since none of their friends have it.

History is just that. As I said, lead by example, they will follow. 
I think if I exposed the problem to those I know, many would start 
asking me how to fix the problem. Paranoid is normal, especially with 
the snoops & Govt today. And getting worse.

   "A state of war only serves as an excuse for domestic tyranny." -
     Aleksandr Solzhenitsyn

To fix the problem is what I am up to now, to create a transparent 
system that works with little effort if any. No hoops for PGP & Pine.

> it's a couple of classic adoption problems:
> - first, users won't use it until their friends use it, and vice versa.
> - second, users likely won't use it unless it's bundled with their 
> client and on by default, like SSL in browsers. the big clients - 
> yahoo, microsoft (hotmail/outlook), google - won't add it until enough 
> users demand it.

It so happens that Outlook Express & Mozilla, client software, & most 
email client software possess encryption of some type now for several
years. Those clients are off the host email system. With a firewall,
that prevents the in-house compromise problem, & a point2point
encryption should work well.

Encryption is being used by many People, & I suspect PGP will be used 
more soon. A built in system does help to make the operation transparent 
- simple like SSL. 

Webmail like Google, Yahoo, Hotmail, not being client software setup on
the users PC, will never be acceptable due to the in-house problem of
compromise. To encrypt there is worthless as was previously stated here
in a previous message. Yet there are times when encryption is not
required at all. Such as this communication we are having.

>> IBE by email address? Sounds interesting. If I send an email, the 
>> receiver
>> uses their email address to unencrypt, by typing it in? Anybody that
>> intercepts the message could then type in the email address & breach
>> security. Maybe I am asleep here. I will followup on that, interesting in

> no, it's an asymmetric key system. the email address determines their 
> *public*
> key, which is only used to encrypt email. they decrypt email with their
> *private* key, which they keep secret, like a password.

I really need to learn more about that to trust it - sounds good anyway.
Thanks.
--
RossARR
[email protected]
mrossarr.imapmail.org
---end-of-message---

-- 
http://www.fastmail.fm - Access all of your messages and folders
                          wherever you are

_______________________________________________
Pine-info mailing list
[email protected]
http://mailman1.u.washington.edu/mailman/listinfo/pine-info
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.