Discussion:
Small future for PGP/ GnuPG?
o***@gmail.com
2014-04-11 17:58:52 UTC
Permalink
PRELIMINARIES

In the '90 (I am old!) I was a moderated evangelist of the universal use of PGP (and later GPG) and public key infrastructure (web of trust) in order to achieve acceptable universal privacy and trust in email communication.

At the time I have a good comprehension of the principles involved. Although I am physicsÂŽs PhD, I have also been a computer buff since the '70 and almost all my work involve and has always involved a lot of mathematics, computers and all sort of information technologies.

At that time most of the people, using email, did that through an email client (that was usually also a news - remember usenet - client ) using the POP (POP3) and latter IMAP and IMAP4. protocols.

HOWEVER

The idea never took off, despite the internet users, at that time, were quite well-informed about the technicalities of the technology they used.

I still maintain a neat pair of public-private keys, with an insanely complex password, and keeping the private key itself inside a password manager utility (keePass) together with more mundane passwords.

(Once in a while I use my public key to encode sensitive documents, that I may or may not, send as email attachments).

FAST FORWARD

Nowadays most people use web-mail (gmail, yahoo, hotmail, outlook.com, etc), not pop mail, and understand almost nothing of computer science (rare web-mail providers let you use POP/IMAP, most times under conditions).

And in a very next future they will be using iOS, android, ChromeOS (all, in any of the
available versions) just to mention the more popular ones at the moment, that not even use (E)SMTP, I think.

Facing those facts I concluded that the idea of private email for the masses is not feasible in the near future.

Write a document->encrypt with public key->send as an email attachmente (better as compressed RAR) is the only option I found useful yet.

ANY COMMENT?

Is useless to refer magic software in test that will solve everything, but is not going to materialize ever.
Robert J. Hansen
2014-04-11 18:38:53 UTC
Permalink
Post by o***@gmail.com
ANY COMMENT?
Yes. John Clizbe and I maintain a list of academic papers related to
usability issues in PGP and what prevents people from adopting it.
They're good reading. Thanks go out to Kristen Fiskerstrand for giving
us a heads-up on one of these papers.


Gaw, S., Felten, E. W., and Fernandez-Kelly, P. 2006.
Secrecy, flagging, and paranoia: adoption criteria in encrypted email.
In Proceedings of the SIGCHI Conference on Human Factors in Computing
Systems (Montreal, Quebec, Canada, April 22 - 27, 2006).
R. Grinter, T. Rodden, P. Aoki, E. Cutrell, R. Jeffries, and
G. Olson, Eds. CHI '06. ACM, New York, NY, 591-600.
DOI= http://doi.acm.org/10.1145/1054972.1055069

Available at: http://www.soe.ucsc.edu/classes/cmps223/Spring09/Gaw%2006.pdf



Garfinkel, S. L., Margrave, D., Schiller, J. I., Nordlander, E.,
and Miller, R. C. 2005. How to make secure email easier to use.
In _Proceedings of the SIGCHI Conference on Human Factors in Computing
Systems_ (Portland, Oregon, USA, April 02 - 07, 2005).
CHI '05. ACM, New York, NY, 701-710.
DOI= http://doi.acm.org/10.1145/1054972.1055069

Available at: http://simson.net/ref/2004/chi2005_smime_submitted.pdf



Steve Sheng, Levi Broderick, Colleen Alison Koranda, and Jeremy J.
Hyland. Why Johnny Still Can’t Encrypt: Evaluating the Usability of
Email Encryption Software. Poster session, 2006 Symposium On Usable
Privacy and Security, Pittsburgh, PA, July 2006.

Available at:
http://cups.cs.cmu.edu/soups/2006/posters/sheng-poster_abstract.pdf



Alma Whitten and J.D. Tygar. Why Johnny Can’t Encrypt: A Usability
Evaluation of PGP 5.0. In Proceedings of the 8th USENIX Security
Symposium, Washington, DC, August 1999.

Available at: http://bit.ly/OaEeTD



Usability of Security: A Case Study. Alma Whitten and J. D. Tygar.
Carnegie Mellon University Computer Science technical report
CMU-CS-98-155, December 1998.

Available at:
http://oai.dtic.mil/oai/oai?verb=getRecord&metadataPrefix=html&identifier=ADA361032


------------------------------------

______________________________________________________________
Archives: http://groups.yahoo.com/group/PGP-Basics/messages
OT List: http://groups.yahoo.com/group/PGP-Basics-OT
OT Subscribe: mailto:PGP-Basics-OT-***@yahoogroups.com
Gossamer Spider Web of Trust http://www.gswot.org

Yahoo Groups Links

<*> To visit your group on the web, go to:
http://groups.yahoo.com/group/PGP-Basics/

<*> Your email settings:
Individual Email | Traditional

<*> To change settings online go to:
http://groups.yahoo.com/group/PGP-Basics/join
(Yahoo! ID required)

<*> To change settings via email:
PGP-Basics-***@yahoogroups.com
PGP-Basics-***@yahoogroups.com

<*> To unsubscribe from this group, send an email to:
PGP-Basics-***@yahoogroups.com

<*> Your use of Yahoo Groups is subject to:
https://info.yahoo.com/legal/us/yahoo/utos/terms/

Loading...