5 ms·
I started using GPG seriously once the "easypg" integration landed in Emacs 23. When you open a .gpg file it prompts for your passphrase and decrypts transparen
by technomancy 13y ago
I started using GPG seriously once the "easypg" integration landed in Emacs 23. When you open a .gpg file it prompts for your passphrase and decrypts transparently, and when saving a new .gpg file it prompts you with a list from which you can select recipients to encrypt to.
The integration with Emacs mail clients is fantastic too; just M-x mml-secure-sign or M-x mml-secure-encrypt when composing, and incoming messages with signatures are typically checked for you.
This totally changed the way I used GPG. (from "not at all" to "every day")
- stinkytaco 13y agoI'm working through the irony of your finding GPG easier to use once it landed in emacs. I mean... Emacs for God's sake. In all honesty, however, part of the "difficulty" of GPG is really by design. You need to be deliberate about signing and encrypting because security should be a careful and deliberate act. If you're hoping for the program to take care of it transparently, you're probably not being safe enough. At least Emacs requires you to go through an explicit process. As you have to do with everything in Emacs.
- velis_vel 13y ago> You need to be deliberate about signing and encrypting because security should be a careful and deliberate act. Why? You don't have to be 'deliberate' about encrypting when you're using SSH or HTTPS.
- stinkytaco 13y agoTrue, but we're putting a lot of trust in third parties in that situation, no? HTTPS requires us to say "sure Verisign [or insert authority here], I believe you." If I'm doing that, why not just trust Google? Why use email encryption at all? SSH is more in our control, but it's still trusting a third party (a server) and it still requires a deliberate act to set up and use (unlike HTTPS).