Encrypt and Sign Gmail messages with FireGPG
Linux.com (Same owners as Slashdot) has a story up about FireGPG and says "Gmail may be an excellent Web-based email application, but there is no easy way to use it with privacy tools like GnuPG. The FireGPG extension for Firefox is designed to solve this problem. It integrates nicely into Gmail's interface and allows you...
Encrypt and sign Gmail messages with FireGPG
Encrypt and sign Gmail messages with FireGPG
For me, I just like to use it, to make people think I am doing something.
Keeps the snoops on their toes.
I thought their business model worked on the idea that they could datamine all your email and (among other things) offer you targeted email based on the content therein... this'll screw with that idea...
"BUY jjhHDJEy6786ERLKLXhdfeprERIOUPewoenOIhgshgrgeyrew now for a low price on Ebay.co.uk"
Nope. It's secret terrorist plots to overthrow the tyrannical American Government!
Oh, wait! I wasn't supposed to say that, was I?
My blog
-----BEGIN PGP MESSAGE-----8 f7hh4839h47f7e8 394g84953jgf84g erniguiregt980
Version: GNUPG v0.4.0 (GNU/Linux)
Comment: Wonderful
ewurnfi3u834j9few4jf9oewfqvi7y&H*&HAwr8hw78er7hfw
wf8943f89jw3r8j9fesajaejro5gvl;rhyklyfp[ult0h43jg
fnw98efj89324rtuerjgeiorgtjerilgtjireogniregunren
werj
-----END PGP MESSAGE-----
I have nothing more to add
liqbase
It is just that I don't want anybody to intrude my privacy. Do you close the envelope of a regular snail-mail letter? If so, do YOU have something to hide??
I don't actually use it for encryption; I use it for verification.
Besides encryption, GPG also allows you to sign messages, ensuring that the message is indeed from you, and hasn't been modified after you've signed it. In the Ubuntu Community, this is important for a) verifying messages from developers are real, b) verifying that uploaded packages were created by trusted developers, c) verifying signatures (such as signing the code of conduct).
While FireGPG is useful, it's not so useful for signing messages; gmail auto-wordwraps messages after you send them, and FireGPG doesn't take that into account. Therefore, unless you wordwrap it yourself, gmail's going to add line breaks, and your signature will be invalid. When I need to sign messages, I either word wrap myself so that gmail doesn't, or send it through Thunderbird using Enigmail.
No folly is more costly than the folly of intolerant idealism. - Winston Churchill
You are forgetting about authentication. Email is trivial to spoof. If you *always* sign your messages, then when some asshat, say, decides to send an explicitly detailed nastygram to your boss from 'you', it is easy to prove otherwise...
Or maybe from your secret lover, etc. You get the picture.
I generally close the envelope of snail mail so the mail doesn't fall out.
I use security envelopes to obscure the contents of my mail. You probably would want to use that as an analogy instead.
So if you "always" sign your messages, then you can tell off anyone you want as long as you don't sign it. Brilliant!
I haven't used gmail that much, but I was under the impression that it saved drafts of what's in the composition textbox at intervals.
That data would be all cleartext wouldn't it? Seems a tad risky to me.
Hey, your girlfriend called. She said she couldn't read the garbled message you sent. However, I passed on your "wanna...tonight" message to her and she said "yes" but I don't think your name came up. So...if you don't mind, I'd like to get out a little early tonight...
http://www.skullsecurity.org/blog/
Anonymous Coward is hoping to make a fortune on Patent #53892647956403765437856348756438756487563, "Method for tucking the flap inside the envelope".