Encryption and Identity Verification

From Guardian Project Wiki

Jump to: navigation, search

Using QR Codes and camera QR code readers, the mobile phone can be the easiest tool for managing PGP signatures for building a web of trust.

Contents

PGP implementations

gnupg-for-java
STEED
APG
Didisoft OpenPGP Library for Java

PGP Featureset Assessment

Feature Description OpenPGP APG Usage
Frequency
Strategic
Value
Key Generation*
Checkmark.png
Questionmark.png
Low High
Encrypting / Signing



Standalone files
Checkmark.png
Checkmark.png
Low Low
Email body
Checkmark.png
Checkmark.png
High High
Email attachments
Checkmark.png
Redx.png
High High
Keyserver Integration



Upload public key
Checkmark.png
Redx.png
Low High
Search / download public key
Checkmark.png
Checkmark.png
Medium High
Upload/download signature
certifications
Checkmark.png
Redx.png
Medium Med
Key revocation
Checkmark.png
Redx.png
Low High
Key Management



View / delete third party keys
Checkmark.png
Checkmark.png
High High
Import / Export sub-keys
Redx.png
Redx.png
Low High
Trust Management



Key signature viewing
Checkmark.png
Redx.png
Med Med
Visible chain of trust
Redx.png
Redx.png
High High

/*APG describes key generation feature as "still kind of beta"

PGP data and meta data

Anonymous Web of Trust

While the PGP public infrastructure is very useful and easy to use, it also provides complete social graphs to the public. For many people, this will put them at high risk, so we should use techniques for an anonymous web of trust. Or at least not making the social graph available to people outside of that social graph.

CAcert Certificate Authority Infrastructure


PGP master key with sub keys for daily use


OTR syncing


Handling Verification Signatures

Converting OTR formats

Personal tools
Namespaces
Variants
Actions
Navigation
Projects
Toolbox