orbitalflower

The problem with PGP, part 4

Posted in Opinion on

Recently, a tutorial titled Mutt, Gmail and GPG advised users to take radically different steps to most other guides, including the standard GPG documentation.

When two guides offer completely opposite advice and there’s no general consensus on which is right, it’s a big problem. PGP is complex and most users aren’t able to make sufficiently informed choices about the secure way to use it.

Some of the guide’s advice deserves criticism:

This is a general problem with PGP: guides on its use radically disagree, and even the official documentation isn’t completely authoritative on basic aspects of its use.

But further, even the software that supports it, such as Mutt, is likewise difficult to use and takes work to configure into something with strong security. Comms software needs straightforward usability if it is to be popular, and needs to be popular in order to be useful.

See also