4 ms·
Hey HN, I'm one of the authors on this paper. I'd be happy to answer any questions.
by bluegate010 11y ago
Hey HN, I'm one of the authors on this paper. I'd be happy to answer any questions.
- diafygi 11y ago> While our results are disheartening, we also discuss several ways that participant experiences and responses indicate how PGP could be improved. Have you approached the developers of both Mailvelope and Gmail to discuss these improvements? How did they respond? Also, have you participated in usability discussion with the OpenPGP developer community at large? Any insights? I ask because it seems like everyone who isn't very active in the OpenPGP developer community thinks that usability is a high priority. But, in my experience, when you start to bring up the topic of user-friendliness in the mailing lists, you get resistance or apathy. It seems like this is a problem of culture and incentives. How can those issues be addressed?
- bluegate010 11y agoWe haven't reached out to Mailvelope/Gmail developers, nor have we opened a usability dialogue with the OpenPGP community. We're still in the process of getting these results published. Your experience with that community is interesting though.
- Natanael_L 11y agoPlease talk to the OpenKeychain developers. That's the best PGP implementation I know of. Also keybase.io.
- bhickey 11y agoGiven the usability and technical problems with PGP, do you think it's worth saving?
- nickpsecurity 11y agoIt's one of only 2 or 3 techs mentioned in Snowden leaks as capable of blocking NSA. GPG specifically. That's enough reason to build on and around it until we have a usable solution just as strong.
- bluegate010 11y agoFor those who value security enough to take the pains to learn the system, yes, it's useful. For your average netizen, we feel a progressive approach would be more effective. Start out with a key escrow service and if the user wants more security, they can ratchet up to PGP.