Encrypt and Sign Gmail messages with FireGPG
Linux.com (Same owners as Slashdot) has a story up about FireGPG and says "Gmail may be an excellent Web-based email application, but there is no easy way to use it with privacy tools like GnuPG. The FireGPG extension for Firefox is designed to solve this problem. It integrates nicely into Gmail's interface and allows you...
Encrypt and sign Gmail messages with FireGPG
Encrypt and sign Gmail messages with FireGPG
For me, I just like to use it, to make people think I am doing something.
Keeps the snoops on their toes.
"Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
I thought their business model worked on the idea that they could datamine all your email and (among other things) offer you targeted email based on the content therein... this'll screw with that idea...
"BUY jjhHDJEy6786ERLKLXhdfeprERIOUPewoenOIhgshgrgeyrew now for a low price on Ebay.co.uk"
Nope. It's secret terrorist plots to overthrow the tyrannical American Government!
Oh, wait! I wasn't supposed to say that, was I?
My blog
-----BEGIN PGP MESSAGE-----8 f7hh4839h47f7e8 394g84953jgf84g erniguiregt980
Version: GNUPG v0.4.0 (GNU/Linux)
Comment: Wonderful
ewurnfi3u834j9few4jf9oewfqvi7y&H*&HAwr8hw78er7hfw
wf8943f89jw3r8j9fesajaejro5gvl;rhyklyfp[ult0h43jg
fnw98efj89324rtuerjgeiorgtjerilgtjireogniregunren
werj
-----END PGP MESSAGE-----
I have nothing more to add
liqbase
It is just that I don't want anybody to intrude my privacy. Do you close the envelope of a regular snail-mail letter? If so, do YOU have something to hide??
I thought, their ability to automatically parse the messages — so as to show users the relevant advertisements, was the reason, I am getting an unlimited mailbox with nice interface for free.
If all/most of my messages are encrypted, how will they know, what to peddle to me? Can't do much on Subjects alone... Or can they?
In Soviet Washington the swamp drains you.
I don't actually use it for encryption; I use it for verification.
Besides encryption, GPG also allows you to sign messages, ensuring that the message is indeed from you, and hasn't been modified after you've signed it. In the Ubuntu Community, this is important for a) verifying messages from developers are real, b) verifying that uploaded packages were created by trusted developers, c) verifying signatures (such as signing the code of conduct).
While FireGPG is useful, it's not so useful for signing messages; gmail auto-wordwraps messages after you send them, and FireGPG doesn't take that into account. Therefore, unless you wordwrap it yourself, gmail's going to add line breaks, and your signature will be invalid. When I need to sign messages, I either word wrap myself so that gmail doesn't, or send it through Thunderbird using Enigmail.
This extension seems very cool, and I plan to try it out when I get home. When I first read the summary I thought to myself, "A firefox extension and gmail, how much simpler could it get!" But, unfortunately this is not point & click encryption. It requires an additional external program (GnuPG) to function. Even this small, relatively trivial step is too much for beginning to average computer users. Encrypted email is great and all, but I can only send it to other people with encryption-enabled email clients.
Where is the it-just-works email encrytion for dummies?
I welcome our new 99% overlords.
OTR is miles better than the gaim-encryption/pidgin-encrypt. Honestly, I don't understand why they won't just kill it and move to OTR for good; it's a fundamentally better security model for something transient like instant messages.
Particularly since having two mutually-incompatible encryption packages is a pretty crummy state of affairs; it just means that the few users who do use encryption, are going to be fragmented between incompatible systems.
OTR probably has the greatest market penetration of any IM-encryption system, outside of corporate clients (Sametime, I think, uses encryption by default, although I don't think it's end-to-end, only client-server, because there they want the ability to intercept on the server), because it's built into the fairly popular OS X Adium client. So there's already quite a few users out there who have software that supports it. If only some of the other IM clients would start building it in by default, rather than making it an optional addon, I think it would quickly gain traction as a de facto standard. (And that would be a good thing, since it's a good system and open source.)
"Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."
You are forgetting about authentication. Email is trivial to spoof. If you *always* sign your messages, then when some asshat, say, decides to send an explicitly detailed nastygram to your boss from 'you', it is easy to prove otherwise...
Or maybe from your secret lover, etc. You get the picture.
Psh, Lynx. Get with the times, man, everyone is using links2 (perhaps links2 -g if they want to be on the bleeding edge).
Anyone else think the comments just weren't rendering right before they turned off ABP and saw ads?
perhaps because i'd like to send an email from work to my GF with something like "hey wanna fuck tonight?" and i'm not particularly keen on the network guys reading that.
I've been using the S/MIME plugin for Firefox. and it's great. I'm not sure I like the way you have to apply for a certificate from Thawte, but it works and it's very painless.
This is not painless and easy, and IMHO S/MIME is alot nicer implemented than PGP signatures.
I'm more concerned about the letter (or worse, a check) falling out.
While the site says only Gmail is supported, could this be made to work with other web apps? It'd be neat to have something like this for webmail on my own domains, forum-based messages, and so on.
Slashdot Burying Stories About Slashdot Media Owned
Clever. Hiding your kiddie porn encoded in anarchist rants! I'm onto you, buddy!
I generally close the envelope of snail mail so the mail doesn't fall out.
I use security envelopes to obscure the contents of my mail. You probably would want to use that as an analogy instead.
So if you "always" sign your messages, then you can tell off anyone you want as long as you don't sign it. Brilliant!
I haven't used gmail that much, but I was under the impression that it saved drafts of what's in the composition textbox at intervals.
That data would be all cleartext wouldn't it? Seems a tad risky to me.
This is not painless and easy, and IMHO S/MIME is alot nicer implemented than PGP signatures.
S/MIME is oftentimes more slickly implemented, because it tends to get more use on the corporate side, but I think that it's unsuited for wide use because of its reliance on centralized certificate authorities. The whole certificate-based infrastructure isn't anything that most people want to have to deal with.
For 90% of all communications, what people want is an email (or IM, or whatever) version of PGPfone -- they just want the data secured in transit, with the actual user authentication done via some side-channel (calling them up on the phone and exchanging key fingerprints, etc.).
If people have to get and install certificates, they're not going to use the system.
"Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."
Hey, your girlfriend called. She said she couldn't read the garbled message you sent. However, I passed on your "wanna...tonight" message to her and she said "yes" but I don't think your name came up. So...if you don't mind, I'd like to get out a little early tonight...
FireGPG is great, I suppose, but doesn't help those of us who only use GMail via POP3/SMTP, both to avoid advertising and have mail archives under our own direct control.
In fact, FireGPG actually benefits Google and its advertising goals, since it only functions via Firefox and Google's ad-infested Web interface.
This is your boss. The network guys tell me you've just used the Company's network to write "hey wanna fuck tonight?" on a public website. You're fired.
Slashdot Burying Stories About Slashdot Media Owned
http://www.skullsecurity.org/blog/
I use FireGPG along with It's All Text! plugin, which I can edit a textfield with an external editor such as Vim. Vim handles wordwrap for me. The only problem I have is that Gmail automatically makes links for URLs or email addresses, which breaks the signature.
I understand that in some countries, you are legally compelled to provide the keys to access files encrypted with PGP, GPG, etc. if the authorities demand access. If you refuse to produce a working key, or claim to be unable to do so, a judge is able to assume that you are deliberately hiding something.
Firstly, I wondered if anyone could confirm this? I have heard that it is the case for Britain at least, although I don't see how it can possibly be legally compatible with the presumption of innocence.
Secondly, I wanted to suggest that perhaps this is a reason not to use PGP, because PGP encrypted information can always be decrypted using the recipient's key - even many years after the message was originally sent. So law enforcement officers will be able to get old PGP-encrypted documents from your email account (probably even if you delete them, thanks to backup tapes). They'll then be able to force you to decrypt them, and if you don't, they can assume you are witholding the key because the files are full of terrorist plans or whatever.
I suggest that people should only use cryptosystems where the session keys are destroyed immediately after use, such as SSH and (possibly) some secure instant messaging services. Even if law enforcement officers use a wiretap to record everything sent by you over an SSH connection, and then seize your computers, they still can't recover the plaintext because the session keys have already been deleted. It's impossible for you, the suspect, to produce the keys, which should help your legal defense. Here's a way to chat securely by SSH.. if you need to transfer files, you can use SFTP.
>north
You're an immobile computer, remember?
I've been using Freenigma (http://www.freenigma.com) way before I even heard of FireGPG, and they've had a Firefox extension since then too.
Anonymous Coward is hoping to make a fortune on Patent #53892647956403765437856348756438756487563, "Method for tucking the flap inside the envelope".
Not to be too nit-picky, but usually when talking about encryption, the parties are Alice and Bob (the two legitimate users), and Eve (the person who is either 'evil' or 'eavesdropping'). I don't think I've ever heard 'Cathy' used as one of the parties...
Methinks thou dost protest too much. In other words, you may want to calm down a bit, you're sounding a little anxious (or jealous?).
http://xkcd.com/c177.html
As always, XKCD is so relevent, it's not even funny, except it is, and so are chair dancing on the heads of penguins.
// file: mice.h
#include "frickin_lasers.h"
The third participant in the conversation is usually Carol.
Unfortunately wrap, htmlization and all that marlaky is a general problem when it comes to signing via web interfaces, be it gmail or some generic php webforum. I came across the same issue when I made a few comments in relation to the now stillborn EnigWeb project.
Perhaps it's time for a GPG-wide standard for 'verification-lite', aimed at web-traffic. The idea being to trade a small amount of security for method robustness. Rather than signing a bit-for-bit copy, sign a version where anything other than the main visible characters are ignored. New lines, carriage returns, tabs, multiple consecutive spaces, rare symbols that might by mangled by php scripts: all are ignored. So rather singing:
The cat sat on
the mat.
, you sign instead: 'Thecatsatonthemat.'.
Obviously, greater minds than mine need to sit down and assess the pros, cons and risks (more freedom to try and create collisions), but it strikes me as an idea worth considering.
then just write the address and add the stamp on the letter/cheque itself, don't bother with the envelope. You can saves trees at the same time!
They use programs to determine who is using high level encryption. Afterwards, they plant a keylogger with burst transmitter in your keyboard. By doing it that way, they don't have to spend anytime decrypting. You can any program or level of encryption you want and it won't do any good since you are compromised at a lower level.
Cogito, ergo sig.
hey guess what? fuck you.