<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>danielmiessler.com - Latest Comments in Updated PGP Information</title><link>http://drm.disqus.com/</link><description>https://danielmiessler.com/about/</description><atom:link href="https://drm.disqus.com/updated_pgp_information/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Wed, 01 Jul 2009 20:44:24 -0000</lastBuildDate><item><title>Re: Updated PGP Information</title><link>https://danielmiessler.com/blog/updated-pgp-information#comment-12012580</link><description>&lt;p&gt;I suspect the demand for its use isn't there simply because most people's e-conversation are 1) not deemed sensitive enough to require privacy, 2) Average Joe isn't going to understand the concept of signing especially if you try and relate what private / public keys are, and 3) folks probably expect e-mail messages to be already private, just like they expect phone conversations to be so, even if they somehow know that phone lines can be tapped because unlike physical messages (such as on paper) you can't "see" network transmissions unless you've heard of the term "packet sniffer."&lt;/p&gt;&lt;p&gt;This kind of rolls into the same thing with PKI.  Many browsers (until recently) didn't do automatic CRL checks.  Almost all users blindly click "accept" when they see a server certificate that's self-signed or signed by an untrusted authority.  One could argue the old "user education" rhetoric, but the average person's expectation of security is grossly over-simplified when it comes to things like this to make it practical, IMO.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Doc Rice</dc:creator><pubDate>Wed, 01 Jul 2009 20:44:24 -0000</pubDate></item><item><title>Re: Updated PGP Information</title><link>https://danielmiessler.com/blog/updated-pgp-information#comment-12010178</link><description>&lt;p&gt;I think the main problem with PGP signing and encryption (for email, anyway) is that in the vast majority of cases it's a solution looking for a problem.&lt;/p&gt;&lt;p&gt;I want to have to use it, because it's cool, and it satisfies some sort of OCD / neatness thing for me to have everything signed that I send. But if you really look at it, how often are there challenges to email that isn't signed? When is the last time you heard from a friend that they wish your message was signed?&lt;/p&gt;&lt;p&gt;Right, probably never. Same here. So I'm less interested in the technology than I wish I was. It just doesn't seem as necessary as it is cool.&lt;/p&gt;&lt;p&gt;To me it's best use is for software developers who are putting out releases to be consumed by the masses. At that point the signature becomes crucial rather than just a novelty--although even then I wonder how many people even check the signature for downloads.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Daniel Miessler</dc:creator><pubDate>Wed, 01 Jul 2009 19:37:54 -0000</pubDate></item><item><title>Re: Updated PGP Information</title><link>https://danielmiessler.com/blog/updated-pgp-information#comment-12009782</link><description>&lt;p&gt;My problem is that almost everyone I correspond with don't know what encryption is and wouldn't be bothered to use it even if they did.  They probably figure that since their web-based mail interface is running with "the yellow lock icon," their messages are transmitted securely.  Well, we know how that goes...&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Doc Rice</dc:creator><pubDate>Wed, 01 Jul 2009 19:18:10 -0000</pubDate></item><item><title>Re: Updated PGP Information</title><link>https://danielmiessler.com/blog/updated-pgp-information#comment-11936120</link><description>&lt;p&gt;I used it regularly for about a month, and then lost interest. Too much work given that hardly anything I send out or receive via email is worth reading. &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">PI</dc:creator><pubDate>Tue, 30 Jun 2009 11:27:16 -0000</pubDate></item><item><title>Re: Updated PGP Information</title><link>https://danielmiessler.com/blog/updated-pgp-information#comment-11933622</link><description>&lt;p&gt;I do what I must because I can.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Pirate Jack</dc:creator><pubDate>Tue, 30 Jun 2009 10:17:20 -0000</pubDate></item><item><title>Re: Updated PGP Information</title><link>https://danielmiessler.com/blog/updated-pgp-information#comment-11929080</link><description>&lt;p&gt;I use PGP to encrypt files and (not very often) e-mail. Or at least sign them!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Xavier</dc:creator><pubDate>Tue, 30 Jun 2009 06:25:12 -0000</pubDate></item><item><title>Re: Updated PGP Information</title><link>https://danielmiessler.com/blog/updated-pgp-information#comment-11928805</link><description>&lt;p&gt;I use it to sign and encrypt documents more than I use it for e-mail.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Sean</dc:creator><pubDate>Tue, 30 Jun 2009 05:58:38 -0000</pubDate></item></channel></rss>