3 ms·
> Using Thunderbird plus Enigmail for GnuPG, I can use any email provider, and be ~certain that they can't read my stuff. Yes but no one can either :( In the l
by askmike 8y ago
> Using Thunderbird plus Enigmail for GnuPG, I can use any email provider, and be ~certain that they can't read my stuff.
Yes but no one can either :( In the last 5 years I received 2 encrypted emails, and thousands of non encrypted emails. The problem with PGP is that almost no one is using it.
Maybe the people you email with do use it though.
- mirimir 8y agoAs I understand it, ProtonMail basically uses PGP. It just does it in Javascript or whatever. But whatever. The ability to use GnuPG serves as a filter ;)
- askmike 8y ago> As I understand it, ProtonMail basically uses PGP. It just does it in Javascript or whatever. This means that maybe now the private keys are on your device, at any point in time they can update their frontend javascript code to get your private key and read all your emails. > The ability to use GnuPG serves as a filter ;) Yes definitely, I wouldn't get any emails at all anymore. Works great for Inbox Zero I guess.
- mirimir 8y ago> This means that maybe now the private keys are on your device, at any point in time they can update their frontend javascript code to get your private key and read all your emails. That's the risk. By default, the filesystem isn't accessible to Javascript. But here, you've authorized key access for encryption and decryption. I suppose that Thunderbird and Enigmail could be modified to do much the same. But arguably that would be discovered quickly.
- askmike 8y agoThe difference is that Enigmail is maintained by an open source community, Thunderbird by Mozilla. Also the protocol your mail client uses to talk with your email server (POP or IMAP) don't really support the flexibility to send the keys over easily. As opposed to your clientside Protonmail client managed by javascript that can AJAX the keys to the mothership.