Archive for Security

04.12.06

GnuPG, PGP and email

Posted in Security at 1:46 am by are

As you all know (or should know), sending an email is like sending a postcard. The contents is easily read by anyone without you ever knowing.
So we of course want to do something about that! The mail RFC does not have any security built in, so we must rely on 3rd party plugins to do the work.
Luckily we have GnuPG or the commersial version PGP.

I use GnuPG on my KDE desktop, and Enigmail plugin in ThunderBird.
I sign all my emails digitally using PGP/MIME. Any mailclient can still read the mail, and at the same time any PGP enabled client will automaticly verify the email. Using Enigmail I can also encrypt any message as long as I have the PGP key for the recipient.

I can also encrypt messages to myself, thus storing info in my mailbox that only I can read. Very handy for passwords etc.
(remember that only the body of the email is encrypted, the subject can still be read by anyone)

Get GnuPG at www.gnupg.org
Get Enigmail at http://enigmail.mozdev.org/
Get Outlook plugin at http://www3.gdata.de/gpg/download.html (I have not tested this)

My PGP/GnuPG Key ID: 0×3E41B6F5, or use pgp_key.asc