4 ms·
I think of it like this: usability can be a security feature. If you build a "perfectly secure" piece of software, but it takes a very high level of skill to u
by squidlogic 11y ago
I think of it like this: usability can be a security feature.
If you build a "perfectly secure" piece of software, but it takes a very high level of skill to use it, your users will use something else that is easier to use, but less secure. And then how has your ideologically perfect piece of software helped improve their security?
If you make tradeoffs for usability, you will raise the bar because people will actually use what you make.
- x5n1 11y agoFork Thunderbird or some such client, also make a web client available. Make a new service which offers only encrypted e-mail by default (with a new e-mail address that includes e-mail hosting for your own domain) and provides the key server and everything else. Advertise it as something different from e-mail like encrypted e-mail. Set a new precedent, create a new industry.
- munin 11y agoso like hushmail?
- x5n1 11y agoNo you need to provide a desktop client, open source, by default with everything configured in addition to the service. I guess you should also let users use other IMAP servers but the client should always encrypt all mails it sends out. Hushmail was always open to court order attack, a desktop client, an open source one, is much less so. It should always put the name of the client in the subject line or send some unencrypted text along with each message on where they can get a client to view the message. And the client should be able to configure itself with minimal input, sort of like Thunderbird does right now with most e-mail services. And generate, transmit, and store your public key to anyone upon request.
- munin 11y agooh ok. this is actually harder to solve than just 'here have thunderbird'. how do you replicate keys across computers? how do you send e-mail from a new computer when you don't have access to your old computer (it turns out the answer is you don't). how do you back up your keys? where do you store them? there are some high security answers like "ship our users HSMs" but those are very brittle to common failure modes like "i lost it". I think you'll discover that if you try to create something that is both resilient to average negligent use but still encrypted, you'll wind up with something that is basically hushmail.
- joosters 11y agoBut who would use it? This study is all about getting the average computer user to use PGP. Most people with webmail accounts won't want to switch back to a desktop client and possibly have to change their email address in order to send & receive secure mail. Besides which, 'make a new client' doesn't answer the main issue, which is how to write a usable client. There are plenty of existing unpleasant PGP clients out there, unless you can detail what makes your new attempt better, it will most likely fail as well.
- x5n1 11y agoIt has to be an all-in-one solution that you download that has to pretty much do everything for you so your mother can download a file and just go. With a simple wizard that lets you register a new e-mail address and potentially allows you to invite other users via their e-mail addresses... imported from Gmail or something like that. I would not worry too much about compatibility with existing mail solutions or what not. It's a new service which is completely different from e-mail as far as the user is concerned. More advanced users can use it as e-mail if they want. Who would use it? Anyone who does not want all their mail to be a public spectacle. Plenty of paranoid Americans out there right now that might be willing to give it a try.
- rakoo 11y agoTutanota (https://tutanota.com/ https://tutanota.com/) does that, and even has compatibility with the existing SMTP network. It seems to be web-only at the moment though. I'm pretty sure other systems exist, unfortunately as long as we stay with SMTP nothing will change.
- mike-cardwell 11y agoUnless they can check their email on their phones, it wont take off. Mobile email clients are much more important than desktop nowadays IMO.
- gozo 11y agoMost "users" don't care about end-to-end encryption and instant messaging has already become the "better e-mail" on phones. The only way I see of breaking into this space is to make something for companies, because they still have reasons for a "better e-mail" and value encryption.
- anonbanker 11y ago> also make a web client available. Make a new service which offers only encrypted e-mail by default rainloop[1] already does this. 1. http://www.rainloop.net/ http://www.rainloop.net/
- bluegate010 11y agoThat's the exact line of thinking our lab has been on. Security<-->usability is a tradeoff, and PGP seems to sit too far on the secure end of the spectrum to be useful to most users. We're working on a way to deliver progressively enhanced security, while onboarding less technical users with more usable features.
- joosters 11y agoWhile mostly true, it's not so clear-cut. While some improvements to usability would reduce the security, there are also things that can be done to make software easier to use and still keep it as secure (for example, in-app help)
- greggarious 11y agoThere is actually a whole paper about this by Roger Dingldine: http://www.freehaven.net/anonbib/cache/usability:weis2006.pdf http://www.freehaven.net/anonbib/cache/usability:weis2006.pd... Basically, you're more anonymous the more people use Tor, so increasing Tor's usability increases it's security.
- bsdetector 11y agoFor instance, Apple's fingerprint reader is not secure because with enough work you can make a mold of somebody's print and fool it. Except now virtually everybody with an iPhone has it set up so that in practice nobody else can access their phone. Another thing is key generation. Encryption people demand perfect randomness for the key generation, and that means the key is this crucial piece of data that must be perfectly protected and copied about. That's unusable for most people. Instead, pick the key from 1 billion derived from a user's password. If they use a different computer, or reinstall their OS, or whatever reason then the software just takes a while to try each billion until it finds the one that works. Or encrypted email. For perfect security you need a safe way to exchange keys beforehand and all kinds of trouble. No. Just have software attach your public key in unencrypted email to recipients. If you receive an email with somebody else's public key then the software starts encrypting to them using it. It's insecure in so many ways, but it would mean the majority of email being encrypted and if done right with almost no impact to the user (password-derived keys, password change automatically sending yourself a new-key-encrypted email with the old key, etc). Security people need to stop seeing things in black and white. Something can be insecure and "broken", yet still raise the overall level security.