3 ms·
I am working on a messaging & email encryption platform (for the reason you mentioned) which will finally make encryption easy to use for non tech savvy people.
by yousifa 10y ago
I am working on a messaging & email encryption platform (for the reason you mentioned) which will finally make encryption easy to use for non tech savvy people. It is based on PGP, source will be available. If anyone is interested in helping, giving feedback or learning more send me an email (in my bio or my username at gmail.com)
- luxpir 10y agoCan you tell us all more here?
- yousifa 10y agoSure, Situation: Us "techies" know or easily can learn how to set up encryption and protect ourselves, the general public will not. Everyone needs encryption but most will only use it if: -their friends are using it -it is so easy a cave man can do it -it is beautiful Complication: Current products are hard to use and are built for hackers. Encryption products need to build in vitality and understand the use cases of most users. To be successful this must be built with usability and UX first, not security methods first. Sormthing pretty decent that people use is much better than a great system that most people don't use. Solution: Browser plugins that act like they are a part of the current email experience. Beautiful phone apps that give users the same functionality that they are used to having with much better security. More info below, this is my current thought process and work, not perfect I'm sure, would love input. UX: Most users use email via browsers and default phone app. Initial plan is browser plugins + standalone phone app. Browser plugins exist for pgp but are too complex for the general public to understand and set up and require a user to get the recipient's key. We streamline the process by just having the user click "encrypt", enter a passphrase (will get to this in tech section), and click send. We take care of setting up the recipient with their account if they don't have one to be able to view their message. As for mobile messaging, users will enter their passphrase when launching the app and then be able to freely message, call, video chat until the switch to another app or exit. Tech: Encryption using private/public key pairs according to pgp spec, of which implementation is gpg. Encryption/decryption happens on device or browser. We host last known good info for user public keys to prevent MITM attacks and will only use other sources if we don't have info of a user. Private keys are stored on our platform for cross device compatibility and so they are not stored on the users device. However these keys will be encrypted/decrypted on the users device using symmetric key encryption implemented as a complex passphrase.
- yoasif_ 10y agoHave you looked at what Pretty Easy Privacy is doing? https://www.prettyeasyprivacy.com/ https://www.prettyeasyprivacy.com/ They have iOS and Android clients, along with a subscription available for Outlook (Windows), and planned desktop versions for Apple Mail, Thunderbird and Web Browsers (Safari, Mozilla, Chrome and IE).