6 ms·
If you’re reading this thread, please leave a comment to say if you do or do not use PGP with email. I suspect few do.... it’s very very hard for ordinary users
by 4778468d 6y ago
If you’re reading this thread, please leave a comment to say if you do or do not use PGP with email. I suspect few do.... it’s very very hard for ordinary users to grasp.
- swaits 6y agoI sign every message I send. I like that I can reasonably prove exactly what I did or did not write. Can’t remember encrypting any other than the occasional test message. I gave up on Thunderbird with the release of 78. Previously Emigmail was just functional enough once I got its finicky settings all dialed in. Now I’ve gone all in on [MailMate](https://freron.com/ https://freron.com/) on macOS. Out of the box PGP support was only one of many pleasantries I found when I first tried this a few weeks ago. It’s dramatically changed my idea of how well a GUI MUA can actually work. Money well spent!
- dragonwriter 6y agoSigning let's you prove what you did write, it doesn't let you prove what you did not write, since all the signed emails in the world don't prove the nonexistence of unsigned emails from the same sender. Now, if you have a regular practice of signing emails, one without a valid signature that purports to be from you is pretty strong evidence that either you didn't send it or you anticipated the need for future repudiation, but it doesn't itself prove anything about which of those applies.
- tuwtuwtuwtuw 6y agoYou can't prove what you did not write.
- neilv 6y agoWhen I ended up casually using PGP for personal email, it was for encryption when emailing with some friends at other schools, expressly because not everyone at one site or the other was trusted not to snoop on other people's emails. Not that PGP alone would've been enough defense against a determined and knowledgeable systems person, but it did presumably offer some privacy (and also, just the principle of it). Then I fell out of the habit, so I'm curious in what kinds of scenarios you envision in which your habitual use of email signatures would help?
- JoachimS 6y agoI've just switched to Postbox. It is a polished version of T-bird. And works with Enigmail to integrate with gpg.
- m-p-3 6y agoI did but I stopped as soon as I noticed that most of my private communications could be handled as instant messages, so I use Signal more. I use my PGP key (on my Yubikey) for SSH now.
- libraryatnight 6y agoI do not. You should do a straw poll in a separate ask HN. I'm curious about this too.
- cpach 6y agoIn the past 20 years I’ve used PGP (for email) about... three or four times. It just isn’t worth it. There are better tools now, such as Signal.
- t0astbread 6y agoNo, not really. I have it set up, I attach my public key but I have yet to talk to someone who responds with an encrypted message. Then again, I'm not a heavy email user and I use other means of communication for regular contacts. If an online service (that has email functionality) supports it though (and I think more should) I'll gladly enable that.
- ximm 6y agoI work for an organization that sometimes receives sensitive data. We support PGP email (among other options). It s not used that much, but I think it is important to at least offer it. "be liberal in what you accept".
- tgv 6y agoI don't. It doesn't make sense for 99.9% of my communications. I'm also not sure my typical recipient would know how to handle signed emails.
- xiconfjs 6y agoI‘m using it very often in our conpany. The TB78 implementation would break many workflows and security aspects.
- sneak 6y agoI receive a fair number of PGP encrypted messages. I don't usually send them unless I am sending something that needs to remain private. This is largely due to the fact that my mail clients don't support PGP.
- inglor_cz 6y agoI have been using Thunderbird with Enigmail since 2010 at least (if not 2008) and we encrypt all e-mails in our workgroup by PGP. The new implementation is disastrous. I cannot read some e-mails encrypted by Symantec Encryption Desktop and UX needs some improvements too. Enigmail showed the cryptographic status of an e-mail with a conspicuous colored tab, this implementation indicates it somewhere on the edge of the screen in small letters.
- rstuart4133 6y agoI'm a very light user of the new Thunderbird + GPG signed emails. Getting the keys into it was of a novel experience, but hey there aren't many and thereafter it signs emails just fine. Verifying received email is more problematic. There are far more of them, it can't get them from the GPG database I trust, it can't get them from a key server and manually importing them is again ... novel. I understand the reasons for not wanting to use GPG to verify emails as they come from an untrusted source, not using it to sign emails could possibly be justified for forwarding emails from untrusted sources with attachments, not having nice way to import your trusted keys and keys from key servers I hope is only because this is version 1.
- lmm 6y agoI use it. I have Facebook configured to use OpenPGP for their emails to me, so I get a steady stream of encrypted messages from that, and a couple of friends occasionally encrypt their emails to me.
- JoachimS 6y agoI sign all mail. I use encryption for some conversations.
- aborsy 6y agoI use it frequently. In particular, institutional email is accessible to the company. I am conservative in my emails assuming that everyone sees the message. Some of us have PGP keys and feel better to gossip :) I use it for various other tasks too (exchanging API tokens, passwords, emailing myself documents, etc ).
- usrusr 6y agoI do. Not exchanging exciting messages with some secret group of revolutionaries but I've been getting encrypted real time notifications of any account movements from my bank for over a decade. And I'm a big victim to the note-taking pattern of "mail to self" and that gets a huge feature boost if you can do encrypted mail to self. I like it as my main secrets store because it's almost natural there to add a layer of mild obfuscation to your PINs and the few major passwords that get this treatment.
- padraic7a 6y agoI do not. I tried it a number of times and while I can get the hang of it it's a lt of bother when no-one else I know uses it either.
- wazoox 6y agoI do. In fact, all of my work emails are GPG-signed by default. But I never liked Thunderbird, I've been using claws-mail for more than 15 years.
- goldsteinq 6y agoI do not. People I write to don't have PGP configured in their client, and e-mail will never be secure anyway. https://latacora.micro.blog/2020/02/19/stop-using-encrypted.html https://latacora.micro.blog/2020/02/19/stop-using-encrypted....
- upofadown 6y agoThe article has many problems past the generally insulting tone. The most interesting one I saw on a quick scan was the implicit suggestion that anyone would be happy if their emails immediately disappeared after reading, so as to establish forward secrecy. The article doesn't bother to define exactly what is meant by email so it is hard to know exactly what they are proposing as an alternative past the bizarre mention of Signal.
- KptMarchewa 6y agoNever.