[146372] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

[Cryptography] Good private email

daemon@ATHENA.MIT.EDU (Richard Salz)
Mon Aug 26 12:33:54 2013

X-Original-To: cryptography@metzdowd.com
Date: Mon, 26 Aug 2013 07:12:21 -0400
From: Richard Salz <rich.salz@gmail.com>
To: cryptography@metzdowd.com
Errors-To: cryptography-bounces+crypto.discuss=bloom-picayune.mit.edu@metzdowd.com

I don't think you need all that much to get good secure private email.
 You need a client that can make PEM pretty seamless; reduce it to a
button that says "encrypt when possible."  You need the client to be
able to generate a keypair, upload the public half, and pull down
(seamlessly) recipient public keys.  You need a server to store and
return those keys. You need an installed base to kickstart the network
effect.

Who has that?  Apple certainly; Microsoft could; Google perhaps
(although not reading email is against their business model). Maybe
even the FB API.

It's not perfect -- seems to me the biggest weakness is (a) the client
could double-encrypt for TLA's to read, or (b) it could give you the
wrong key so your mail only goes to the bad guy -- but it's a hell of
a lot better than we have now and I'd say it's more than good enough.

Thoughts?
_______________________________________________
The cryptography mailing list
cryptography@metzdowd.com
http://www.metzdowd.com/mailman/listinfo/cryptography

home help back first fref pref prev next nref lref last post