Email Encryption for Everyone - Hak5 1410.1

Поделиться
HTML-код
  • Опубликовано: 1 ноя 2024

Комментарии • 72

  • @pudelz
    @pudelz 11 лет назад

    Great Segment for me to share with family and friends! I want to suggest that everyone should wait for the popup before they start typing. I doubt Google keeps the autosaves after you send the message but then again...

  • @shimmikins
    @shimmikins 11 лет назад

    im glad im not the only one who remembers IDSPISPOPD

  • @TheMrMorphling
    @TheMrMorphling 11 лет назад +1

    I doubt it, but depending on what you are sending you can use password protected compressions or straight up attach truecrypt partition or have a adress with username and password to a private FTP server for sharing files.

  • @Maoilmhenaigh
    @Maoilmhenaigh 10 лет назад

    Thanks so much for this! I set up my own encryption using the program you recommend. First rate work!

  • @tannewton
    @tannewton 9 лет назад +1

    I've been using mailvelope for a short while, and I think it's a pretty good tool. Unfortunately, nobody else in my family, or anyone of my friends would use it too. So, in the end I'm the only person who I would send encrypted messages to :). My closest friends are not such security freaks like me. Most of my families and friends wouldn't care about securing messages at all because encryption requires you to memorize long and complicated passwords, and a few steps for decryption.

  • @ewookiis
    @ewookiis 11 лет назад

    FYI's
    - Asymmetric encryption is the "public and private key".
    - Symmetric encryption is the ' one passphrase to rule it all".
    A keyring contains private and public portions of keys.
    PGP relies as asymmetric encryption upon key servers, keyserver.pgp.com is still alive even after symantecs buy of PGP Corp as an option.
    Since this equals to simply encrypting the body of the mail, of course the mail header and everything else inbetween will be in cleartext.

  • @lanesmerge
    @lanesmerge 11 лет назад

    This is great! There is a Firefox add on called Encrypted Communication 1.3 it allows you to encrypt text and supposedly uses AES 256... It seems to work fine in gmail BUT I was wondering what the HAK5 gurus thought of it.

  • @lelandweathers4749
    @lelandweathers4749 11 лет назад

    Only if you didn't use a passphrase - read the docs. The passphrase is the key to a symmetric algorithm which encrypts your private key.

  • @PontusWelin
    @PontusWelin 11 лет назад

    Now all we need is a plugin that will do all that automatically. And some easy to use way to send and recieve the public keys. Something that my parents wouldn't mind using.
    Then we might actually get this to become a thing for everyone!

  • @MykhailoKadenko
    @MykhailoKadenko Год назад

    Biggest drawback is losing your key chain. Imagine, not being able to read your nostalgic email from 2005 anymore ; __ ;

  • @MrDuncanhall
    @MrDuncanhall 11 лет назад +5

    Nice, so your final email is encrypted. Now, what about all those drafts of the email that are automatically saved, unencrypted, to Google's servers?

  • @jamegumb7298
    @jamegumb7298 11 лет назад

    Delete any mail you dont really need. Archive the rest and encrypt it, delete remote copy.
    Or run your own mailserver. €12,99 a year for the domain, any e-mail you like as many as you like. Takes one hour of reading and will run on a Raspberry Pi, Alix or Soekris board.

  • @lanceseidman
    @lanceseidman 11 лет назад

    Darren, if I am not mistaken. You use BOA for Banking? Do you generate your own CC#'s?

  • @msven
    @msven 11 лет назад

    Great ep! Thanks.

  • @sh4rkbyt3
    @sh4rkbyt3 11 лет назад +1

    Why are you talking about PGP and then having to use JavaScript as a plug in?

  • @TheMrMorphling
    @TheMrMorphling 11 лет назад

    Well, just from using mailvelope: No, your private key isn't store in your gmail, it's stored inside the plugin, but if you are using Chrome then in theory; yes if you believe in the "Chrome is a botnet" theory.

  • @xXSARS48Xx
    @xXSARS48Xx 11 лет назад +1

    won't google now have your key?

  • @Jawazable
    @Jawazable 9 лет назад

    Doom codes lol. Remembered all three.

  • @victormedina8191
    @victormedina8191 11 лет назад

    you both are Awesome :D

  • @trevblum650
    @trevblum650 7 лет назад

    Craxy how far we've come in opsec since 2013. If someone told me today that they stored their pgp private keys in their browser I would gasp and immediately show them TAILS. Also crazy that even still today we are still using Thunderbird successfully.....interesting

  • @TechGuard0
    @TechGuard0 11 лет назад

    with the public key, you can only encrypt the message for the recipient, and then with the private key you can decrypt the message to read it.

  • @tonychalmers8716
    @tonychalmers8716 7 лет назад

    Hi! Can you show how to encrypt an attachment when your sending an email. Thanks

  • @drazticksec
    @drazticksec 11 лет назад

    Darren, where do you get all of your shirts??

  • @williampolinchak
    @williampolinchak 9 лет назад

    Very cool. Thanks.

  • @MrLeidonanam
    @MrLeidonanam 10 лет назад

    when you tying on gmail, server saved draft, please encrypted and paste into mail and send .

  • @TheMrMorphling
    @TheMrMorphling 11 лет назад

    It probably won't happen, considering that everyone would have to be using the plugin, I've been thinking about a email service that did PGP by default by checking the MIT crypto database if the receiver has PGP public key and alerting the sender if no public key was found (so that you know you are sending to "unsecure" address), I guess a plugin could do the same, but sometimes I don't trust Google...

  • @the-real-zpero
    @the-real-zpero 4 года назад

    Encrypted email, accessed through google chrome, and with a public key shared through gmail
    LMAO

  • @ChadLeeP51
    @ChadLeeP51 11 лет назад

    The only key they may have is your public key. So if they want to encrypt a message to you they can. They wouldn't, but they could.

  • @spaideri
    @spaideri 9 лет назад

    Wow you look so much younger though it's not recorded not that long ago. Or maybe it's just the picture quality.

  • @StingJia
    @StingJia 9 лет назад

    Does the mailvelope server keep my private key? If no it won't be convenient when I switch to another computer, If yes my security relays on mailvelope.

  • @farhan00
    @farhan00 11 лет назад

    If PGP will eventually be cracked, why don't we switch to 8,192-bit or 16,384-bit encryption?

  • @bitogre
    @bitogre 11 лет назад

    Question: Is there a similar solution that is just as easy for use on Android devices?

  • @TheMrMorphling
    @TheMrMorphling 11 лет назад

    That's not really an issue, I mean sure it won't do anything on the server side, but your browser still "sees" it.

  • @demiurgetheartisan
    @demiurgetheartisan 11 лет назад

    Question.
    can the attachements sent with an email be encrypted as well? like if I send photos with an email as an attachement. will the photos be encrypted along with the email?

  • @ChadLeeP51
    @ChadLeeP51 11 лет назад

    Every encryption will be cracked eventually. The number of bits has less to do with the quality of encryption as does the math behind it. RSA 256 was the encryption to use and was replaces with AES 128, which was for superior. I might of mixed up the RSA and AES, but the bit size is correct.

  • @keifus1
    @keifus1 11 лет назад

    Thank you....

  • @Knight8365
    @Knight8365 11 лет назад

    Shannon lost her box to stand on?

  • @uzzipy
    @uzzipy 11 лет назад

    please tell me about: Personal Email Certificate and digital signature etc? what is this?... Is this encryption? too!!?

  • @iungerich1
    @iungerich1 11 лет назад

    this is great and all, but what about start phones? i dont know about you but all my emails also go to my phone. is there a way we can do this on ios ( already jail broke if that helps )

  • @silviucc
    @silviucc 11 лет назад

    Key exchange should be done face 2 face if possible or by other secure means not by email because that can bee snooped and defeats the point of the exercise.

  • @KEEVVY
    @KEEVVY 11 лет назад

    If any one spams you make him an account on those advertise sites.

  • @shanecasey404
    @shanecasey404 7 лет назад

    I got a message from mailvelope to verify my key. Is this a hack or do I have to.

  • @treebeard3190
    @treebeard3190 10 лет назад

    I set up the program via ggl then mailed someone telling them about it (including the link to this video) and then got a a c c o u n t s u s p e n d e d d o m a i n notice! Does that mean that ggl &/or our uncle does not want us sharing this on the net! What to do, now?

  • @surplusdriller1
    @surplusdriller1 11 лет назад +2

    Edward Snowden sendt me here

  • @TechGuard0
    @TechGuard0 11 лет назад

    only the public key... and that is whole point of it. It's public, it doesn't matter.

  • @LCFTW93
    @LCFTW93 11 лет назад

    the public key, not private, so they can send them messages but not decrypt their messages

  • @johnallen2067
    @johnallen2067 11 лет назад

    Is it true: "Mailvelope is fine until you discover that your private key is stored locally in an unencrypted SQLite Database."

  • @3rdshift_3
    @3rdshift_3 11 лет назад

    +1 for Enigmail

  • @yokonsetsu
    @yokonsetsu 11 лет назад

    If you have a Google account you have no privacy, welcome to the Patriot Act!

  • @redtrash6093
    @redtrash6093 5 лет назад

    don't add js of anything, if it can re-write script do not load it. JS = most dangerous +> hackers paradise. btw cloud- internet same thing.

  • @laurie7251
    @laurie7251 9 лет назад

    Galaxkey is free and so much easier to use. And it lets you do free file storage as well!

  • @NedTheDread
    @NedTheDread 11 лет назад

    I know that Domain.com is your sponsor and they give you money, but they suck... You can't even change the TTL values of the DNS records, major buzz kill when I found that out...

  • @ajhiggins1
    @ajhiggins1 11 лет назад

    Does it encrypt attachments?

  • @rogueangel2k
    @rogueangel2k 8 лет назад

    IDKFA FTW!

  • @Laguy211
    @Laguy211 11 лет назад

    I love Linux = )

  • @techgeek_
    @techgeek_ 11 лет назад

    Not available in firefox yet :(

  • @CompletelyCovered3
    @CompletelyCovered3 11 лет назад

    Done.

  • @TheeVideoGameHunter
    @TheeVideoGameHunter 7 лет назад

    Is this still relevant in 2017?

    • @NevaehBeatez
      @NevaehBeatez 7 лет назад

      So far there has not been any significant advancements in cracking modern encryption methods. So yes, still very relevant. Even when this method is cracked however, this software will probably add the option for a new method.

    • @counterculturecocks
      @counterculturecocks 6 лет назад

      Thunderbird+enigmail

  • @1pqpq
    @1pqpq 11 лет назад

    lol "i totally just used lolz irl"
    well you also just used irl irl. lolz!

  • @10xTnTRevolutionofficial
    @10xTnTRevolutionofficial 9 лет назад

    You Rock I Really liked your clip! I would love to be Duel subscribers when are you making more Videos? #10xTnTrevolution

  • @MoldyKock
    @MoldyKock 11 лет назад

    its only the public key

  • @BradDux
    @BradDux 11 лет назад

    I have to recommend mymail-crypt. It uses OpenPGP.js and supports signing.

  • @Muny
    @Muny 11 лет назад

    epic

  • @usergroupX
    @usergroupX 11 лет назад

    Hi guys, just got a few proDUCKts from your site , thnx.
    One question: I know how to use an alfa as wlan1 BUT, what if I want to turn off my internal card (wlan0) and use wlan1 (alfa ) instead . How do i do that on linux?

  • @felixxavier5054
    @felixxavier5054 7 лет назад

    lol idclip idbehold