Re: secure email providers

Slavko <[email protected]> Sat, 2 Apr 2022 11:44:22 +0200
Newsgroups gmane.mail.sylpheed.claws.general
Message-ID <[email protected]>
--===============0123023998225074147==
Content-Type: multipart/signed; boundary="Sig_/qqnYPEWu_EG9Ca28i_y23Wx";
 protocol="application/pgp-signature"; micalg=pgp-sha256

--Sig_/qqnYPEWu_EG9Ca28i_y23Wx
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

D=C5=88a 2. apr=C3=ADla 2022 7:58:51 UTC pou=C5=BE=C3=ADvate=C4=BE Paul <pa=
[email protected]>
nap=C3=ADsal:
>On Sat, 02 Apr 2022 05:41:22 +0000
>Bob Williams <[email protected]> wrote:=20
>
>> I think they use PGP/GPG under the bonnet (or hood).
>
>But without your own keys, that's not so secure

Sure, you are right.

People often think, that encryption itself is enough, but any
encryption is as secure as secure is used key only. And manage key in
secure way is not as simple as most of people want.

The key is secure only when it is accessible only by one authorized
person, if there are more than one authorized person, problem the can
happen. To ensure this in many OSs only the hardware key storege can
accomplish this (Windows & MACs are known to upload your files to
central storage, and it doesn't matter how they name it -- telemetry,
backup, ...). But Linux, *BSD, ..., can be compromited too, of course
;-)

The HW key teach us how to use key on different devices -- you simple
cannot use it on multiple devices at once ;-) If you really want this,
you need multiple HW keys (which can contains the same key data, but...)

I didn't use HW key, i rely on password protection, and on secondary
devices i use separate keys (eventually subkeys for decrypt system
messages/alerts)... Yes, some messages i cannot see on all device, but
i consider it as security price, as nothing comes withou price).

The key management is IMO main reason, why OpenPGP or S/MIME are not
widely used. No, not because it is hard, but because nobody can use key
with webmail by secure way. Yes i am aware of some JavaScript
implementation, but i will not name it secure by any mean. Thus problem
is not key management itself, but webmail, which is used by most of
people nowadays (and clients, which do not support encryption at all).

If someone delegate its key to third party by any way, it can be
convenient, but this already opens path to use that key by any (many)
not authorised entities, which i consider even worse than not encrypt
at all, as it provides false security feel.

Managing and using OpenPGP is not hard, nor inconventient, it simple
requires to do some extra step(s), which can be (relative) hard to
understand why they are needed for not security focused people. But i
was able to teach multiple (totally not IT) people to use OpenPGP, once
they understand what privacy in network is.

regards


--=20
Slavko
https://www.slavino.sk

--Sig_/qqnYPEWu_EG9Ca28i_y23Wx
Content-Type: application/pgp-signature
Content-Description: Digitálny podpis OpenPGP

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEwhNakIB2F5/fdXmSAQVZxpJoYkcFAmJIGvcACgkQAQVZxpJo
Ykfg3wf8DqM2OjUAevHgUyz8OjR2diGrE///XwagqRE+h0OMoGZ3FHI+Wl1HRxoj
uuY/79Q4T9EeJ8ckvAGpcR4jgelGOlgjTNbC24JvBpwgtTHAmhw7Z+XbyID5TaPp
a76uf3bIfzu952lKeqdORY8rtXvi5lAQWr9+UmAGV/YwABp1WVhkDr89+s/p4vFU
8MnS7AuimF6plK/8qbIwTZhj0evYHlGOL/vJfhesSHxogTTOflF79h1zxagx307a
P17leh/1+fRiwfeRL5+TSXYSs/O5N3ztlfF2hXaGS6+kdu91tHaeF8O3cknq6Fqd
zaM+S8SvZWGOC6tJrtpvSunqpdAEIw==
=Noa/
-----END PGP SIGNATURE-----

--Sig_/qqnYPEWu_EG9Ca28i_y23Wx--

--===============0123023998225074147==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Users mailing list
[email protected]
https://lists.claws-mail.org/cgi-bin/mailman/listinfo/users

--===============0123023998225074147==--