Skip to content

Using PGP encryption for email

Privacy
  • Hi,

    I wonder about othersā€™ opinions about PGP (Pretty Good Privacy) encryption in email inboxes. Or if others are concerned about the privacy of their email inboxes.

    I recently learned that emails are not meant to be confidential or encrypted. At least, during its inception. However, since many email servers/providers are trying to sell ā€œusā€ as a product, and additionally governmental surveillance programs are increasing day by day, I am more and more interested in encryption for my email inboxes. I am not interested in targeted ads or promotions.

    So the main aim is to decrease the amount of my data to be circulated between marketing companies.

    I wonder if this is a concern for others and how they solved these problems.

  • crazycellsundefined crazycells marked this topic as a regular topic on
  • @crazycells great topic. PGP has been around for years, and itā€™s predecessor (if memory serves me correctly) was World Secure. As Iā€™ve said countless times to many people, email is not a secure transport by default, therefore, unless youā€™ve taken steps to secure (encrypt) the traffic stream, you should not expect any level of privacy.

    PGP works well but requires Public Key Encryption in order to work. Using symmetric and asymmetric algorithms plus an array of proxying, there are no known ways of breaking it. However, PGP itself was acquired some time ago by Symantec, so if you want to go the truly open source (FOSS) route, youā€™ll need OpenPGP.

    The huge advantage of PGP is itā€™s ability to send a message without needing to share any form of keys, so if youā€™ve never met the recipient, you can still send a message and have it completely secured in transit.

    Being the huge privacy advocate that I am, Iā€™m a big supporter of anything like this.

    As a final note, Proton Mail is well worth a look, and with a paid subscription, you can incorporate your own domain email.

  • @phenomlab Yes. As you pointed out, I was talking about OpenPGP šŸ‘ Additionally, Proton Mail is one of the services I use.

    After Robinhood and T-mobile data breaches in the US, unfortunately, my ā€œgoodā€ email addresses are out there in the dark web. So, I was researching how I can re-structure my email inboxes, and several months ago I encountered with Simple Login app. It is an open-source project too. Have you heard of them? It is an email relay service with alias either in random or custom domains. And you can create unlimited alias and disable them very easily after they are breached.

    I actually bought the premium version 1 month ago and last week Simple Login company is bought by Proton Mail, so I believe this application will be around for a much longer time. It natively supports OpenPGP just like Proton Mail. I have already added my custom domains there for email.

    I was thinking maybe I can add these public PGP keys in Simple Login and open the emails with private PGP keys on my computer (I guess with Thunderbird? since it supports OpenPGP natively). So, emails are never read by the email servers.

    I wonder your opinion about this strategy. This will require to trust Simple Login servers, but I trust them more than I trust Gmail, Outlook, or GMX Servers šŸ˜„

  • @crazycells said in Using PGP encryption for email:

    Have you heard of them?

    I havenā€™t to be honest, but will certainly be taking a look

    @crazycells said in Using PGP encryption for email:

    I was thinking maybe I can add these public PGP keys in Simple Login and open the emails with private PGP keys on my computer (I guess with Thunderbird?

    Yes, I see no reason as to why not.

    @crazycells said in Using PGP encryption for email:

    I wonder your opinion about this strategy.

    Definitely a step in the right direction, and Iā€™m certainly interested in terms of progress.

  • @phenomlab said in Using PGP encryption for email:

    Definitely a step in the right direction, and Iā€™m certainly interested in terms of progress.

    Until I master PGP encryptions, I am only trying this using my outlook account. I added the Public PGP key to the simple login server and the Private PGP key to the Thunderbird app, and it works great so far.

    When I log in to the outlook web version, I cannot see any content of the email but encrypted files at the attachment, but when I open Thunderbird I can see the full email with no problem.

    Of course, the ideal situation would be encryption from one end to another; but I am happy with this method too šŸ˜„ at least none of the emails can be scanned in Gmail or Microsoft servers. I trust the Simple Login server more than I trust Gmail/Outlookā€¦

    I will update you about the progress. šŸ‘

  • @crazycells for webmail, youā€™d need to install and configure PGP there for that to work. Without it, the messages will be encrypted and unreadable

  • @phenomlab said in Using PGP encryption for email:

    @crazycells for webmail, youā€™d need to install and configure PGP there for that to work. Without it, the messages will be encrypted and unreadable

    I think the web version can stay like this. I do not mind this since I can reach emails from Thunderbird on my Desktop.

    Do you know how can I reach these encrypted emails from my phone (for Gmail and Outlook accounts)? I know protonmail is natively supporting PGP, so their app should be OK.

  • @crazycells using Proton Mail is probably going to be the easiest I think. I know extensions exist for browsers in terms of PGP but I donā€™t think they work on phones.

  • @crazycells have you seen this ?
    https://gnupg.org/

  • @phenomlab said in Using PGP encryption for email:

    @crazycells have you seen this ?
    https://gnupg.org/

    nope, I will check this out. I hope it is not an app that I have to copy-paste the text into it to decryption šŸ˜„

    Additionally, I have found this PGP-friendly email client for mobile:

    https://canarymail.io/

    I have not tried it yet though. I will update you after tryingā€¦

  • @crazycells looks really nice. Will check that out

    EDIT: Just had a quick look at this application, and it seems to take it upon itself to install the pro trial (see screenshot) which basically means you get used to all of the features then have them redacted if you choose to take the free version. This feels a little bit on the sneaky side to me

    Screenshot_2022-04-26-21-09-09-68_699716de98a669beaafcc70a3de4541f.jpg

    Iā€™ve uninstalled based on this. The reviews arenā€™t that great either - although there are not really enough to base a decision on.

  • @phenomlab thanks for pointing this out. I will look for alternatives.

  • @crazycells You might want to have a look at Fair Email - itā€™s one I use because it respects privacy - plus, if you want the pro version, itā€™s much cheaper.
    https://email.faircode.eu/

  • @phenomlab I think this is not available for IOS, I could not find it in App Store.

  • @crazycells Mmmm - yes, sadly, it is only Android (which I use). There are alternatives, but not sure what they are like
    https://www.topbestalternatives.com/fairemail/ios/


Related Topics
  • Best email provider?

    Solved Privacy
    4
    3 Votes
    4 Posts
    62 Views

    @JAC no problems.

  • Why Forums Are Still Relevant in 2024

    Blog
    3
    2 Votes
    3 Posts
    121 Views

    @JAC wow. Thanks for the great comments. They are truly appreciated.

    I tend to agree with the social media comments youā€™ve made. This is made all the more prominent in relation to recent events in Southport for example, and toxicity is a huge issue. Just look at some of the comments from trolls - they are truly disgusting, and the perpetrators seem to take great delight in the anonymity the Internet affords them.

    forums in general are much more subject focused, easier to moderate and users are less likely to be banned because they are there for a specific interest or reason, not to cause trouble.

    Agreed, although discussions can still get out of hand and quite often, these are left to run riot and quickly spiral out of control. A great example of that is here

    https://sudonix.org/topic/141/how-to-destroy-a-community-before-it-s-even-built

    thereā€™s something much more calming about coming to a specific page at your fancy, posting and taking part in healthy debates over the real mishmash of social media.

    Yes, I personally prefer the atmosphere of a forum against the backdrop of unwanted noise via social media.

  • 2 Votes
    4 Posts
    238 Views

    @DownPW This wonā€™t be the first time that Amazon and others like them are being bought to account. I recall seeing a documentary on the TV recently where they sent in a reporter with secret cameras to film the strict regimen and constant threat of being fired for not meeting targets that workers are placed under.

    The surveillance just takes this to a whole new level in my view and itā€™s like being placed under a microscope for constant scrutiny. This goes well beyond the surveillance placed on prisoners!

  • 4 Votes
    4 Posts
    317 Views

    @phenomlab said in TikTok fined Ā£12.7m for misusing childrenā€™s data:

    Just another reason not to use TikTok. Zero privacy, Zero respect for privacy, and Zero controls in place.

    https://news.sky.com/story/tiktok-fined-12-7m-for-data-protection-breaches-12849702

    The quote from this article says it all

    TikTok should have known better. TikTok should have done better

    They should have, but didnā€™t. Clearly the same distinct lack of core values as Facebook. Profit first, privacyā€¦ well, maybe.

    Wow, thatā€™s crazy! so glad I stayed away from it, rotten to the core.

  • 19 Votes
    30 Posts
    643 Views

    @phenomlab 100%.

  • iPhone Data and privacy

    Privacy
    2
    4 Votes
    2 Posts
    489 Views

    Hereā€™s a very useful video that will walk you through the privacy features of Android - mostly around the ones you should disable to get the most out of the experience

  • Google sued for unauthorised use of NHS data

    Privacy
    1
    1 Votes
    1 Posts
    211 Views
    No one has replied
  • Browsing without a VPN? Think Twice...

    Moved Security
    12
    2 Votes
    12 Posts
    1k Views

    And if you ever needed another reason to use a VPN, here it is.

    https://news.sky.com/story/google-blinks-first-in-11-month-privacy-showdown-with-uk-regulator-12479198