Whiteout.io is a chrome app for email, plus an android app with key-synch between the two. It's still early stages, so it has some issues (like indexing all your emails, since forever, and overheating your computer). But it's very promising.
Most people want to continue using webmail though. That's why Mailvelope is so awesome. Continue using webmail, but just have an extra button added which opens up an editor with a bit "encrypt" button. Pretty easy, and pretty safe.
Yeah, I use mailvelope with my close friends and family. It's not yet easy enough for my parents generation to "get it" but if it's set up for them they can muster through it.
The problem with plugins though is that very few people go out of their way to install browser plugins. Having an integrated option is way more useful. So some people have to encrypt/decrypt in-browser using Javascript (like, how tutanota and protonmail do it, or like whiteout.io does, or like anybody can do now using the keynote.io API). I know it's not ideal, but it is way better than nothing. It won't stop the NSA, but it will stop hackers, email leakers, doxxers, and big-data email-mining algorithms.
I do know a team whom you should work with: keybase.io
Keybase.io have an early-level product which would help with your keyserver issue. It has a CORS-enabled API, a commandline tool, an online interface for encrypting, signing, verifying, etc. and a "ring of trust" tool that follows the modern social network model (where, you can "track" somebody and it auto-signs their keys each time they upgrade.
Fair point. It's most likely nothing nefarious, but who knows, maybe they log everything and will one day face a data breach like Sony? Maybe they data mine it?
IRL if somebody intercepted all of your mail, opened the envelope and then put your private letters and bank statements in their own envelope to re-send it, then told you they were doing this to shape postage traffic because they physically cannot handle certain kinds of packages to your location, then you can both A) Believe them that they cannot handle such packages and B) worry about what goes on during the process of opening and repackaging your mail. You don't know the employees doing the repackaging and what if one of them moonlights as a thief. The post was about A, my response was about B. Sorry if it's off topic but you can and should take steps to protect yourself without interfering with their bandwidth shaping.
This post assumes that GoGo are doing a MITM simply to block YouTube in order to prevent their network from being congested. My assumptions would be that
1) GoGo are blocking youtube in favor of their in-flight paid media services not just for badwidth
2) GoGo's MITM attack has little to do with media content but rather more about being able to read all the communications of passengers for "national security" purposes.
If they are decrypting and logging your traffic (including passwords) and communications, then I assume their scheme can be defeated by a VPN. If you want to send intimate messages to your lover, or discuss a political protest while in flight, without some nosy GoGo employee reading it, then probably using OTR (like Cryptocat or pidgin/adium), PGP (like mailvelope, enigmail), and ZRTP (Redphone/Signal) are a pretty good idea.
I remember when people used to make these arguments with Java and PHP. "You don't need a framework, just write your JSP templates to have database calls with SQL and tons of Java code". BLEH! I'm glad Struts, then Spring, the Play, came out and made life more sane.
I wrote javascript before there were frameworks when it was just libraries like mootools and dojo and jQuery sitting on server-side templates. Today I write CORS apps with Backbone.js+Marionette.js+require.js+grunt+qunit and it solves all kinds of problems and I love it! I'd never go back to javascript without frameworks. As soon as this project is over I am gonna try AngularJS to see what the hype is about.
Good article. I wonder why Mailpile are targeting difficult use-cases such as activists, journalists, etc. It feels like every PGP provider aims for this, but OTR encryption tools aim for a much easier use case: average users who just want to hide their private conversations from big data algorithms which then sell their secrets publicly. OTR is much easier as a result, but it can't do email (that I know of). :-(
In this article mailpile worry about users who need an airgap. What worries me is whether creating features for airgap users makes anti-features for users like me who just use PGP when mailing with my parents, my wife, and some friends. We just want to avoid our secrets being part of "Big Data" and as a side benefit we resist passive surveillance. Mailvelope (which is "easy") is complicated enough for my parents, they would never add the complexity of an airgap. We just want easy encryption, even if it isn't totally NSA-proof.
>> But still. OTR (and the enhanced/modified version of it TextSecure is using) is probably the easiest to use way to communicate in a reasonably secure fashion, and it'd would be fantastic to see it used by hundreds of millions of users all of a sudden -- even if it's sitting on top of insecure mobile operating systems and untrusted-yet-privileged hardware.
Have you had issues getting OTR to connect sometimes?
Myself and about 5 friends have been using OTR with ChatSecure on the phone and pidgin on the desktop. Sometimes the OTR connection just doesn't engage, and we suspect it's because there are multiple instances of the chat client signed in and it like "crosses the streams" or something. CryptoCat has similar issues. Is there a perscribed way of using OTR that won't give us these problems?
TextSecure hasn't given us any problems yet ... though, we never see the encrypted text messages in our SMS, even when we use textsecure over google voice. Does TextSecure just bypass actual SMS channels?
Agreed. Going from a NZ bank to another country's bank isn't that simple anymore. Using an international currency makes it equally simple anywhere in the world.
Bitcoin already has a better user experience than banks. Just give it another year or two, to the point where bitcoin will be invisible to users the same way that Linux is invisible (yet, the world runs on it). These services will be rewritten with bitcoin under the hood and nobody will even know or care.
I assume any "no fees" clause means that they're not taking fees at this time. It doesn't mean "no fees anywhere in the system". So there very likely is a 3% fee to the user, just not from snapchat.
Aren't Open Source privacy apps more preferable? Shouldn't we all be talking about ChatSecure, Redphone, Textsecure, Mailvelope, Cryptocat, GPG, EnigMail, etc.? And about the companies that offer these programs as a service?
While it's not a guarantee of privacy, open source does significantly increase the likelihood that invasions of privacy and security vulnerabilities can be discovered by enthusiasts and journalists. Right? Wouldn't that be preferable when selecting a privacy app?
To the people who said that Bitcoin is a failure because it can't scale, reading this must be beautiful. Bitcoin will scale to "Visa network" levels in no time.
A veritable explosion of innovation is coming our way. This decentralized stock exchange is just a hint of what is to come. Technologies using bitcoin, and technologies built on bitcoin, are the next thing that will change the world. Don't get me wrong, I'm happy we're also democratizing taxi services, but democratizing finance makes me so much more excited.
:-) Well said. I read this after I posted elsewhere on this thread about how the price drop is caused by adoption so in fact we are buying _utility_ with the value that we lost. Once we've bought enough utility the price trend will likely reverse.
I do own bitcoin, and I buy lots of stuff with it all the time. I can't recommend it enough.
Bitcoin has lost some value recently, yes, but what it's bought with that loss is increased merchant adoption. Currently merchants instantly sell bitcoin which causes the downwards pressure on the price you've been seeing. However, as the utility continues to grow this trend will very likely reverse.
Most people want to continue using webmail though. That's why Mailvelope is so awesome. Continue using webmail, but just have an extra button added which opens up an editor with a bit "encrypt" button. Pretty easy, and pretty safe.