Bitcoin Forum
May 09, 2024, 04:02:01 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: CryptUP: Simple PGP for Gmail / Ethereum public key database / feedback  (Read 1612 times)
geri (OP)
Member
**
Offline Offline

Activity: 77
Merit: 10


View Profile WWW
December 09, 2016, 08:35:38 PM
Last edit: December 12, 2016, 01:23:23 AM by geri
 #1

Who am I
I co-founded BitOasis as a (former) CTO. As far as I know we were the first wallet to use multisig with keys distributed among different entities (us/co-signer/backup) without bothering the user to store a private key. Our open sourced multisig wallet: multisig-core and multisig-recovery.

See my PyCoin contributions here.

Why most PGP solutions suck
We used PGP at BitOasis to encrypt sensitive email. For most people, PGP is a pain in the ass.
Non-critical info would often go unencrypted because you don't want to bother the other guy by encrypting it.
If we didn't use PGP for MOST email, it's no wonder others don't use PGP for ANY email. It's too cumbersome.

What I've done about it
I made PGP work just the same as normal email, so that non-technical people can use it. I released my child a few days ago as CryptUP. It's a Chrome plugin and works with Gmail, because that's what I (and a lot of people) use. It's compatible with any other PGP solution though.

Where I need your feedback - improving decade old pains with PGP

Public key management
I'll use Ethereum as a pubkey database for CryptUP users, under the hood. Users' pubkey fingerprints will get submitted to Ethereum blockchain, instead of outdated systems like http://pgp.mit.edu/. Ethereum blockchain can then be queried with DNSChain eliminating man-in-the-middle attacks on exchange of key fingerprints.

The users don't need to know about the Ethereum stuff. It'll just work and I'll pay for the fees, it's a few cents per user.

Public key fingerprint verification
Security of PGP relies on this, but NOBODY does this. Without knowing you talk to the right person, PGP is a placebo. I'll implement fingerprint-to-image converter, where instead of comparing letters and numbers (which nobody will do), I will be displaying a set of icons for contact you talk to. Imagine 4-5 icons per fingerprint, eg: horse, frog, car, sun. It's much easier for humans to notice a discrepancy in icons then "0D5688EBF3102BE7".

Let me know what you think
As is, I think (and people tell me) CryptUP is the easiest to use PGP plugin. Setup, conversations, attachments, it just does what you expect your standard email to do, plus encrypted.

Let me know your thoughts, it's available here:
https://chrome.google.com/webstore/detail/cryptup-encrypt-gmail-wit/bnjglocicdkmhmoohhfkfkbbkejdhdgc

And the source code is here:
https://github.com/tomholub/cryptup-chrome
1715227321
Hero Member
*
Offline Offline

Posts: 1715227321

View Profile Personal Message (Offline)

Ignore
1715227321
Reply with quote  #2

1715227321
Report to moderator
1715227321
Hero Member
*
Offline Offline

Posts: 1715227321

View Profile Personal Message (Offline)

Ignore
1715227321
Reply with quote  #2

1715227321
Report to moderator
There are several different types of Bitcoin clients. The most secure are full nodes like Bitcoin Core, which will follow the rules of the network no matter what miners do. Even if every miner decided to create 1000 bitcoins per block, full nodes would stick to the rules and reject those blocks.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715227321
Hero Member
*
Offline Offline

Posts: 1715227321

View Profile Personal Message (Offline)

Ignore
1715227321
Reply with quote  #2

1715227321
Report to moderator
1715227321
Hero Member
*
Offline Offline

Posts: 1715227321

View Profile Personal Message (Offline)

Ignore
1715227321
Reply with quote  #2

1715227321
Report to moderator
1715227321
Hero Member
*
Offline Offline

Posts: 1715227321

View Profile Personal Message (Offline)

Ignore
1715227321
Reply with quote  #2

1715227321
Report to moderator
intover_Q
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
March 21, 2017, 10:32:26 PM
 #2

Most useful chrome plugin ever  Grin searching for something like that for years, let me know if I can help you to further develop the tool
geri (OP)
Member
**
Offline Offline

Activity: 77
Merit: 10


View Profile WWW
March 22, 2017, 02:03:26 AM
 #3

You can chat me up at tom@cryptup.org
eduncan911
Member
**
Offline Offline

Activity: 101
Merit: 10

Miner / Engineer


View Profile WWW
March 24, 2017, 03:29:24 PM
 #4

I just installed it and it is working ok.

Though, people who send me pgp emails as attachments doesn't seem to decrypt.  Will reach out to Tom and find out more.  Smiley


BTC: 131Zt92zoA7XUfkLhm1p2FwSP3tAxE43vf
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!