3 ms·
This paper is very popular / influential in the area of usable security. It's interesting to note that though it's possible to securely exchange e-mail, most pe
by thejo 16y ago
This paper is very popular / influential in the area of usable security. It's interesting to note that though it's possible to securely exchange e-mail, most people don't. I took a course offered by Prof. Tygar (co-author of the paper) last year and we evaluated how easy it is to send encrypted mail using Thunderbird+Enigmail+GnuPG. While the usability of the software has improved in the 10 years since the paper was written, it is nowhere near the level required to make this a mainstream technology. Maybe it is inherent to the process itself. I don't see how you can simplify key exchange to make it very easy for the average user. I guess the price you pay for security is to go through the pain of figuring out how it works. Of course, most people will not / cannot do that even if it is in their best interest.
I'd loved to hear the thoughts of the security gurus on HN about this...
- unaccountable 16y agothejo, good to see you here : ). Yes, i was in Tygar's class with you. good times. -nat
- patio11 16y agoI don't see how you can simplify key exchange to make it very easy for the average user. Google/Microsoft/Yahoo posts a blog post containing the following: "PGP keys for all addresses can be found at https://keys.example.com/k/foo%27example.com https://keys.example.com/k/foo%27example.com . This is recorded in a TXT record in our DNS in the following easy to understand format. We invite other mail providers to adopt this standard. We will periodically check your DNS records prior to sending mail and, if set up properly, transparently encrypt all mail sent to you." Essentially, solve key exchange like HTTPS solves key exchange: the user never has to worry about it.