3 ms·
I've been using GPG since a while now, to sign my outgoing mail. I don't encrypt it as I don't know anyone who uses GPG. I'm still happy to use it, to get used
by rogeryu 11y ago
I've been using GPG since a while now, to sign my outgoing mail. I don't encrypt it as I don't know anyone who uses GPG. I'm still happy to use it, to get used to it, and to see alternative uses. Signing is in my view a big improvement, to make sure nobody has messed with the messages. I always use HTML, so the receiver gets an attachment with the signing hash in it, and no strange text in the mail. I use a signature with a link to my public key and a link to the PGP page on Wikipedia. Everybody can read my mail, and if they want they can validate it.
- awqrre 11y agoGetting a strange attachment is better then getting a few strange lines of text at the end of the email?
- Freak_NL 11y agoDefinitely! With PGP/Mime email clients that don't understand OpenPGP simply show a small attachment. Without PGP/Mime (the old way) you get funky delimiters in your mail body that look scary to non-technical users. I started with the old way (because it appears to be more compatible with legacy email clients) until a colleague worriedly asked me about the weirdness in my mails, so I switched to PGP/Mime. As far as I can tell only really old Outlook versions can't handle PGP/Mime, and you can use plain text mails as well as HTML.
- kobayashi 11y agoThe idea of including a link to your public key and a link the wiki on PGP is great! I'm going to do this as well. Would you mind showing me how you link to the above mentioned?
- Borating 11y agoMine http://www.explainxkcd.com/wiki/index.php/1553:_Public_Key http://www.explainxkcd.com/wiki/index.php/1553:_Public_Key
- rogeryu 11y agoHere's the code that I used in Thunderbird. I make it small and light in color. <div style="font-size: 10px; color: #666;">This message is signed using <a href="https://en.wikipedia.org/wiki/Pretty_Good_Privacy">PGP</a> https://en.wikipedia.org/wiki/Pretty_Good_Privacy">PGP</a>. Public key: <a href="https://pgp.mit.edu/pks/lookup?op=get&search=0xBE5D1E31ABCD1234"> https://pgp.mit.edu/pks/lookup?op=get&search=0xBE5D1E31ABCD1... ABCD1234</a> </div> I see the link in the code is not closed properly, so you need to fix this.
- RegW 11y agoSo if the way the receiver gets hold of your public key is by a link in the signed email, what's to stop an attacker changing the link to a fake key and re-signing the email? Hmm. Why don't we have a standard place on our domains for public keys? For example for myname@mydomain.com the public key could be https://key.mydomain.com/myname https://key.mydomain.com/myname.
- 102030485868 11y agoSome part of a key exchange needs to be out-of-band. Alice communicating to Bob what the hash of her public key is over the phone, in person, or otherwise is good enough. Doing that allows Bob to verify whether or not a specific public key belongs to Alice. The problem with hosting a key on a website is that it only really works if the domain has an extended validation certificate, i.e. someone proved their identity to their domain registrar. Then things just become a question of how much you trust the CA.