Re: secure email providers
Slavko <[email protected]> Sat, 2 Apr 2022 11:44:22 +0200
| Newsgroups | gmane.mail.sylpheed.claws.general |
|---|---|
| Message-ID | <[email protected]> |
--===============0123023998225074147== Content-Type: multipart/signed; boundary="Sig_/qqnYPEWu_EG9Ca28i_y23Wx"; protocol="application/pgp-signature"; micalg=pgp-sha256 --Sig_/qqnYPEWu_EG9Ca28i_y23Wx Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable D=C5=88a 2. apr=C3=ADla 2022 7:58:51 UTC pou=C5=BE=C3=ADvate=C4=BE Paul <pa= [email protected]> nap=C3=ADsal: >On Sat, 02 Apr 2022 05:41:22 +0000 >Bob Williams <[email protected]> wrote:=20 > >> I think they use PGP/GPG under the bonnet (or hood). > >But without your own keys, that's not so secure Sure, you are right. People often think, that encryption itself is enough, but any encryption is as secure as secure is used key only. And manage key in secure way is not as simple as most of people want. The key is secure only when it is accessible only by one authorized person, if there are more than one authorized person, problem the can happen. To ensure this in many OSs only the hardware key storege can accomplish this (Windows & MACs are known to upload your files to central storage, and it doesn't matter how they name it -- telemetry, backup, ...). But Linux, *BSD, ..., can be compromited too, of course ;-) The HW key teach us how to use key on different devices -- you simple cannot use it on multiple devices at once ;-) If you really want this, you need multiple HW keys (which can contains the same key data, but...) I didn't use HW key, i rely on password protection, and on secondary devices i use separate keys (eventually subkeys for decrypt system messages/alerts)... Yes, some messages i cannot see on all device, but i consider it as security price, as nothing comes withou price). The key management is IMO main reason, why OpenPGP or S/MIME are not widely used. No, not because it is hard, but because nobody can use key with webmail by secure way. Yes i am aware of some JavaScript implementation, but i will not name it secure by any mean. Thus problem is not key management itself, but webmail, which is used by most of people nowadays (and clients, which do not support encryption at all). If someone delegate its key to third party by any way, it can be convenient, but this already opens path to use that key by any (many) not authorised entities, which i consider even worse than not encrypt at all, as it provides false security feel. Managing and using OpenPGP is not hard, nor inconventient, it simple requires to do some extra step(s), which can be (relative) hard to understand why they are needed for not security focused people. But i was able to teach multiple (totally not IT) people to use OpenPGP, once they understand what privacy in network is. regards --=20 Slavko https://www.slavino.sk --Sig_/qqnYPEWu_EG9Ca28i_y23Wx Content-Type: application/pgp-signature Content-Description: Digitálny podpis OpenPGP -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEEwhNakIB2F5/fdXmSAQVZxpJoYkcFAmJIGvcACgkQAQVZxpJo Ykfg3wf8DqM2OjUAevHgUyz8OjR2diGrE///XwagqRE+h0OMoGZ3FHI+Wl1HRxoj uuY/79Q4T9EeJ8ckvAGpcR4jgelGOlgjTNbC24JvBpwgtTHAmhw7Z+XbyID5TaPp a76uf3bIfzu952lKeqdORY8rtXvi5lAQWr9+UmAGV/YwABp1WVhkDr89+s/p4vFU 8MnS7AuimF6plK/8qbIwTZhj0evYHlGOL/vJfhesSHxogTTOflF79h1zxagx307a P17leh/1+fRiwfeRL5+TSXYSs/O5N3ztlfF2hXaGS6+kdu91tHaeF8O3cknq6Fqd zaM+S8SvZWGOC6tJrtpvSunqpdAEIw== =Noa/ -----END PGP SIGNATURE----- --Sig_/qqnYPEWu_EG9Ca28i_y23Wx-- --===============0123023998225074147== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Users mailing list [email protected] https://lists.claws-mail.org/cgi-bin/mailman/listinfo/users --===============0123023998225074147==--