Re: [Endymail] Another view of the problem and what the IETF could do

Werner Koch <wk@gnupg.org> Tue, 02 September 2014 08:11 UTC

Return-Path: <wk@gnupg.org>
X-Original-To: endymail@ietfa.amsl.com
Delivered-To: endymail@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2BF381A00F5 for <endymail@ietfa.amsl.com>; Tue, 2 Sep 2014 01:11:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -8.9
X-Spam-Level:
X-Spam-Status: No, score=-8.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, GB_I_LETTER=-2, RCVD_IN_DNSWL_HI=-5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ECgCHyQfvN6o for <endymail@ietfa.amsl.com>; Tue, 2 Sep 2014 01:11:46 -0700 (PDT)
Received: from kerckhoffs.g10code.com (kerckhoffs.g10code.com [217.69.77.222]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A317A1A797C for <endymail@ietf.org>; Tue, 2 Sep 2014 01:11:45 -0700 (PDT)
Received: from uucp by kerckhoffs.g10code.com with local-rmail (Exim 4.80 #2 (Debian)) id 1XOjBo-0003ZW-3e for <endymail@ietf.org>; Tue, 02 Sep 2014 10:11:44 +0200
Received: from wk by vigenere.g10code.de with local (Exim 4.82 #3 (Debian)) id 1XOj7l-0007cF-Pm; Tue, 02 Sep 2014 10:07:33 +0200
From: Werner Koch <wk@gnupg.org>
To: Eliot Lear <lear@cisco.com>
References: <CAHBU6iuxfqs9RszSaJLaTV_obKBCJ9Pzii+t9XANN3q+bJm-3Q@mail.gmail.com> <5404A3A3.9050506@cisco.com>
Organisation: g10 Code GmbH
X-message-flag: Mails containing HTML will not be read! Please send only plain text.
OpenPGP: id=1E42B367; url=finger:wk@g10code.com
Date: Tue, 02 Sep 2014 10:07:33 +0200
In-Reply-To: <5404A3A3.9050506@cisco.com> (Eliot Lear's message of "Mon, 01 Sep 2014 18:49:39 +0200")
Message-ID: <87tx4qla2i.fsf@vigenere.g10code.de>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Archived-At: http://mailarchive.ietf.org/arch/msg/endymail/W9kXDgJBuld7K71YUknYbkXg-ZA
Cc: Tim Bray <tbray@textuality.com>, endymail@ietf.org
Subject: Re: [Endymail] Another view of the problem and what the IETF could do
X-BeenThere: endymail@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <endymail.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/endymail>, <mailto:endymail-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/endymail/>
List-Post: <mailto:endymail@ietf.org>
List-Help: <mailto:endymail-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/endymail>, <mailto:endymail-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Sep 2014 08:11:53 -0000

On Mon,  1 Sep 2014 18:49, lear@cisco.com said:

> BTW, it all has to happen without asking for matching keys.  Enigmail
> does a pretty good job of that already.  That's a pretty good model for
> UI (I hazard a guess), and so stay focused on how to get it to function

It has been told so often in all kind of media that Enigmail is the best
tool to use.  I suggested its use myself up until I helped out at a
crypto party and figured that the UI is still made for geeks and not for
users.  For example, one participant assumed that he had decrypted a
mail after having entered his passphrase 3 times.  Then wondered why
there was only this BEGIN PGP MESSAGE and some rubbish.  He didn't
realized that he entered the wrong passphrase 3 times in a row.  The fix
would be obvious: Print the "wrong passphrase" in bold and red letters
and after the 3 tries show an explanations what happened in the content
window.

But how can we expect to get things better with only two spare time
developers for Enigmail and just me taking care of the backend stuff?
Business models around solid encryption have always failed.

> to scale.  It may make sense to use some form of OTR for end-to-end
> transit.  But again I wouldn't want to count on OTR for data at rest.

I fully agree.


Shalom-Salam,

   Werner

-- 
Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.