Picture of Encrypt your Gmail Email!
If you want to be sure that your email can be read by no one but you, then it needs to be encrypted. You'd be surprised to find out who might want to read your email. I was.

One of the best encryption systems is called GPG encryption which is an open-source version of PGP encryption. PGP stand for Pretty Good Privacy and is actually an understatement made by a programmer who didn't want to be too optimistic about how secure it is. However, as it turns out, PGP is has actually proven itself to be extremely good. It's been around for many years, being maintained by the best coders in the world and it hasn't been cracked.

In this Instructable, I'll walk you through the simple process of setting up GPG and then installing a Firefox plugin that will make it easy to encrypt your Gmail.

Step 1: How it works

Picture of How it works
The principle behind GPG encryption is easy. Anyone who wants to play creates a public key and a private key. Your public key is the part of the encryption that you make public. Your private key is the part of the encryption that you never share with anyone under any circumstance.

The two keys work together so that you need both to decrypt anything. To send an encrypted message to someone you lock the message with their public key and when they get it, they can unlock it with their private key. If they want to respond, then they encode the message with your public key and you can read it with your private key.

Of course, this only works so long as you can trust that you have been given the right public key and that you know who you are talking to. One of doing this is by having a key signing party with your close friends. You all show up at a given location at a given time and exchange public keys. Then you have a list of trusted public keys with which you can communicate. This is often referred to as a web of trust.
« Previous41-72 of 72
gumper1 Lampoon5 years ago
Thanks for that link Lampoon. If I install Gpg4win as the website says, can I send it to someone on a Mac to decrypt it or would I need to install a different product or encryption engine?
Also does this also encrypt images, attachments or do I need to do something separate for that?
It isn't much different... Find the GPG software for your operating system;
(see http://gnupg.org)
install the software (instructions on the GnuPG site)
install the Firefox plug-in
create your key-pair
send your public key to your friends and/or conspiratos
keep your pass phrase Long and Private

that is about it.

When your friends send their keys open it with GPG or save it to a file and double-click to install
REAL66 years ago
The easy way to Encrypt your gmail is this:

WHen you are on your gmail account, in the address bar, where it says http, type an S after http. now its encrypted.

so it would look like this

juno2800 REAL65 years ago
Hey, yeah, chumby32 (below) has it right. There are two kinds of encryption at work here. Using httpS will encrypt the connection between your web browser and gmail's servers. This is good! It means nobody on the network can see what you are looking at or typing while you are logged in to gmail. This is especially good if you are checking your email from somewhere public like a cafe. However, once the email leaves your outbox it is still sent in the clear over the internet (through intermediate email servers, routers, etc.) until it reaches its destination. This means it is possibly stored on other servers too. All of the computers that handle the message en route see your email plain as day, and it could be read by anyone with access.

PGP uses encryption slightly differently - it scrambles the actual contents of your message. This means that when you scramble a message all of the intermediate servers transmit the scrambled version as well. The only person (hopefully!) that can see the unscrambled message is the recipient at the end who decodes it using their key.

Don't get me wrong - HTTPS is good and you should use it! But it only encrypts your current connection, not all of your emails.

I believe there is a setting inside your gmail preferences to always turn on HTTPS.
chumby32 REAL66 years ago
What you are suggesting as a solution does not encrypt the email. It only encrypts one's connection to the gmail website.

Using your method, any server that stands between gmail and the email's recipient can read the email you sent.

The point of the Instructable is to prevent anyone except for the recipient from reading the email.
Guanabana6 years ago
This might sound like a stupid question ...but does the encryption work for the Gmail chat as well? If not, please tell me what is the best way to encrypt gmail chats?
To encrypt chats check out the "Off The Record" (OTR) plugin for Pidgin. Pidgin works on linux, mac, and windows, and lets you use all of your other types of chat accounts - msn, google talk, etc. It's cool!

dawcee7 years ago
what about the terrrists? like: im in ur airport 'kriptin up my emailz. this 'ible along with the pneumatic sniper rifle 'ible is bound to cause a terror chain reaction unravelling democracy as we know it. I mean I'm with Jorge Arbusto, there must be some WMD's out there somewhere. Oh wait, this is probably just for sending the illegal kind of porn to illegal-porn-lovin' friends. Also I'll probably try it out for myself ;) thanks w1n5t0n (Thw1n5t0n).
markf dawcee7 years ago
That's probably why encryption software (like GPG) is classified as weaponry under US federal law. That way it can, hypothetically, be regulated the same way that guns are. If an American sends a copy of GPG to a buddy in another country, they are breaking the law by illegally exporting "firearms". More reason than ever to support the ACLU, EFF, and NRA.
DeepWater markf6 years ago
When they pry my private key from my cold dead fingers...
barf_malak6 years ago
this will not work on my computer!!! i am running xp and ubuntu! plz helppp
orken6 years ago
Nice guide. But, it might be worth to point out that you really don't need anything else than the GPG software itself and FireGPG if all you're gonna do is encrypt your GMail (at least on Windows, not sure how that works out on Mac and Linux). Also, if you're a Thunderbird user, do check out the excellent Enigmail plugin which removes pretty much all of the annoyance that comes with managing the keys for your contacts everytime you send or receive a mail.
fotoflo6 years ago
Hey, Check out gwebs' new MailCloak, www.getmailcloak.com. Much easier then firegpg, also works on yahoo, MSN, etc.
DELTAWOLF057 years ago
WOW thanks for the info! i m still copy pasting mine into an encryption program. this looks a lot eraser.
A lot eraser?
I must be missing something. Why is it necessary to have an "anonymous" Gmail account? What if I want to be able to send GPG-encrypted messages from my regular Gmail account, for instance? Is that somehow insecure because it's not "anonymous"? Apologies if I've got the wrong end of the stick; I just want to be sure my understanding's correct.
There is nothing stopping someone from using their real email address. This is actually encouraged if you want to use encryption for professional purposes or if you want to grow your "web of trust". A PGP signed message is digitally signed and can therefore be traced back to you, unless of course you do not use your real name when you create your keys. You could do that if you wanted to go by a unique nickname. Doing so opens the (theoretical) possibility of someone impersonating you because it becomes impossible to verify your identity. If you live in an area of the world where your messages could get you arrested by the government or even killed then the anonymous account is definitely the way to go. Otherwise, it's probably not necessary, but it may be fun.
Thought so. Thanks for the clarification!
sudont7 years ago
I already know how to encrypt my e-mail. Tell me how to get my lazy friends to start encrypting theirs, and decrypting mine.
Blattman sudont7 years ago
Hahaha thats great!
Biotele7 years ago
You might want to add one simple additional security element ... SSL. When you sign on to GMail, it does establish an SSL (Secure Sockets Layer) connection for the sign-on, but then drops back to HTTP in the clear. If you want to have your entire GMail session secured against eavesdropping, then be sure to sign on to HTTPS://mail.google.com This way your entire email session will remain encrypted from your PC through the net up to GMail's servers.
Just get the Better GMail add-on from Lifehacker, and check the "Force encrypted connection" box. Good stuff.
This is great. Can you use this in IE?
Rectifier7 years ago
Personally, I read my Gmail with Evolution via IMAP. Evolution is a linux email program which has built-in support for pgp signing and encryption using the local gpg keys on your machine. I consider a local program that calls GPG directly to be more secure than a firefox extension. You can also use commandline programs like mutt, which support encryption very well. I SSH to my personal server and use mutt to check email on the go, rather than webmail interfaces. By the way, why is everyone always concerned about encrypted things being untraceable? When I sign my email (I rarely encrypt mail, but almost always sign it) I usually sign it with a key using my real name, to prove it was sent by *me*, and not modified, not to make it untraceable...
I think so far, all your Instructables have been featured.
I think they've all been featured because w1n5t0n is *probably* one of Cory Doctorow's pen names. Not sure if you know this, but he's kinda a big deal on the interwebs, not to mention well connected. Clever marketing for his new book I'd say. If by some chance it's not Doctorow posting these, the fact that they get exposure through boingboing.net and Cory's blog craphound.com would raise their profile significantly. Also hi Cory, I'm a big fan.
Adiventure7 years ago
I'm kinda confused on step 4, why can't the gmail be traced back to you? Before you can encrypt anything, you need to make sure that you open a Gmail account that by no means can be traced back to you. This means that you have to be liberal about giving them your real name and address when you sign up. You should also always use a TOR server.
kolrobie7 years ago
You could use customizegoogle addon for firefox to remove the ads and make all the mail pages https (they are only https at the beginning of the sign on part). It's a neat idea, but I don't have that many personal emails to make use of it.
razordu307 years ago
Great Instructable!

I do this myself and it can be fun; when I was trying to learn more about it the resources were relatively limited, so this instructable is great for anyone else interested in it.

The only thing annoying thing about encrypting is that you can't search for items anymore. This was a hassle when my friend and I were using encrypted messages to talk about meeting up, and I was trying to find which email had the address and phone number.

*decrypt* "No..." *decrypt* "Grrr..." *decrypt* "For the love of..."

The firefox plugin works GREAT, though, and it's pretty neat to see absolutely no ads around your Gmail (since it's context-based, google has no ads relevant to ciphered text)
« Previous41-72 of 72