3 ms·
This person stored their PGP private key on Google Drive, which they use "to encrypt" emails. I'm glad the author is security-conscious enough to know what PGP
by acobster 9y ago
This person stored their PGP private key on Google Drive, which they use "to encrypt" emails. I'm glad the author is security-conscious enough to know what PGP is, I guess. And that they deleted it from Drive (didn't say why, hopefully they came to their senses about the more-than-usual amount of trust they were placing in Google).
Is there a valid use case for "encrypting" email with a private key? I guess signing a message is technically encryption, but it's not typically called that, right? I'm hoping their use of "encrypt" in this context is just an error, and that tech reporters at the Guardian understand how key pairs work...
- gowld 9y agoOne of PGP's functions is to encrypt email. Why would you expect someone be savvy enough to understand how PGP works but not be savvy enough to use its main function? https://en.wikipedia.org/wiki/Pretty_Good_Privacy https://en.wikipedia.org/wiki/Pretty_Good_Privacy
- eindiran 9y agoWhen you encrypt an email with PGP, you use the public key of the individual you are writing to, not your own private key. You should only use your private key to read the mail encrypted with your public key, or to sign messages.
- croon 9y agoI came here to ctrl+f "pgp" in the comments, but because he stored it on Drive. Having your private key in a non-client-side-encrypted cloud is like keeping a vector representation of your hand signature on your website.
- nzp 9y agoWho says he was using it to encrypt Gmail email (how would the key being on Google Drive even help with that)? The key may have just been in transit. For example, moving a subkey to smartphone in order to import it into a PGP app on the phone, and Drive just happened to be the most convenient way to do it. If the (sub)key is encrypted with a strong password, as it should be, it's fine.