4 ms·
Thanks for the PDF, looks like a good read. First let me disclaim that I am by no means a crypto expert, and perhaps I am actually way off base here. I'm not
by koanarc 17y ago
Thanks for the PDF, looks like a good read.
First let me disclaim that I am by no means a crypto expert, and perhaps I am actually way off base here.
I'm not suggesting that Gmail could revolutionize popular use of encryption overnight. What I AM suggesting is that by storing and making it simple to send and receive public keys, Gmail could very easily and transparently facilitate the growth of such webs of trust. Simple example (what TFA seemed to be):
1) Alice, a crypto-savvy non-gmail user, sends Bob, a non-crypto-savvy gmail user, her public key. (Or, better, Alice gives Bob a thumbdrive with her public key on it for upload to Gmail.)
2) Gmail stores it.
3) Alice later sends signed mail to Bob.
4) Gmail verifies it, and prominently notifies Bob whether it is a valid or invalid signature. Perhaps it even presents a link for Bob to learn more about how it knows this, and how his mail from Alice is different from un-signed mail.
So with extremely little forced interaction on Bob's part (nothing to install, nothing much to learn, no key generation), there is now some added security between the two of them, even if it is unidirectional. From this point, Bob could then quickly learn enough to be able to encrypt the email that he sends to Alice from within Gmail, and Alice, using PGP in her mail client, would be able to decrypt it.
It certainly doesn't cover every angle, but it would improve relative security and it would allow those who ARE familiar and experienced with public-key cryptography to bring up basic concepts with their friends/family/coworkers (among the ~150 million monthly Gmail users, anyway).
Edit: wonky formatting