2 ms·
I'm not sure if you mean what's so hard for a "linux evangelist" or in general. Linux probably has the best and easiest GPG integration. In general, encrypted m
by jmccree 13y ago
I'm not sure if you mean what's so hard for a "linux evangelist" or in general. Linux probably has the best and easiest GPG integration. In general, encrypted mail is practically useless for every day communication and provides little real benefit. Unless you only communicate with linux experts, 90%+ of the people you're talking to likely don't even know what a "MUA" is. I use gpg for transferring sensitive data (passwords, api keys) occasionally to the rare few clients that have gpg, but the rest of our emails are still sent unencrypted. Why?
Encryption requires everyone in the thread to support it. Need to CC in the C-Level exec on something? Good luck getting them to setup it up in their outlook and use it properly. Even with my help, it took a good 30 mins to set my dad up with GPG on Windows/thunderbird. Have to figure out which software you need, the nomenclature for key generation etc is different in each program.
Encryption breaks search, at least in thunderbird. You can't search through the encrypted messages and they aren't indexed. This makes sense if you're sending very sensitive data perhaps, but for general business correspondence it's reduces productivity. There's an open bug in EnigMail by a user who saves every email in plain text to use regular file search tools. That's useless.
There's the aforementioned webmail. Tons of people only use webmail, and there's no way to interact with them. More importantly in my book, encryption breaks mobile access. Sure, there are addons for gpg on android, but I don't trust my private key on my phone. In the near future there may be some way to use a yubikey with NFC for passing in the private key, but that brings in it's own set of problems.
Lastly, it's the cost/benefit that really keeps encryption use from being wide spread. It costs you time in getting each contact you use to use it, time dealing with being unable to search, time setting up your phone to securely access mail, unable to use webmail at all, and for all this you really only get two benefits: Prevention of e-mail interception by intelligence agencies or internet backbones and access to your mail by your e-mail provider. If I'm not concerned about these, just using proper TLS access for IMAP/SMTP prevents anyone I'm actually worried about (wifi interceptor, bad ISPs) from reading the mail. For mail inside an organization with their own mail server, mails are never anywhere unencrypted than company owned equipment, TLS in transit.
Doing encryption right is hard, for 99% of email the threat model just doesn't justify the expense in time and headaches so the NSA doesn't know there's a conference call at 11am tomorrow or that you should call grandma tomorrow because it's her birthday.