No Photo

Happy Mutant Profile

tomschlenkhoff

HOWTO encrypt your Gmail

May 19, 2008 12:47am

Why not think differently on Gmail security:

We need to develop a plugin for e.g. Firefox that works with templates for URLs and provides a simple way to store keys. Now, if you are using Gmail and have that plugin enabled, and have one or more symmetric keys in store and type an email, the body-text and subject of the email gets scrambled before it is submitted to the site.
Scrambling could either mean, really messy encryption, where no one would be able to read anything at all - but full-text search would not work either. Or scrambling could mean keeping the words but messing up the order of the words - so advertising (fair enough) and full-text search (at least with words, not phrases) would still work but no one would be able to get the meaning of the message.
Now, when I am sending a mail to my wife the message gets encrypted with her/our key. It could even be practical to simply share one key in a small group of friends (=family). We are not talking high security here, it is about applied security that makes it not worthwhile snooping through your messages.
Key exchange is done physically (in security lingo - via a secure channel aka USB-stick) - no Public Key Infrastructure with all the inherent complexity is needed imho.

What do you think? Anybody? Any solutions available already that I am missing?

No friends yet.