Step 5: Install FireGPG in Firefox

Once you have done all that you need to install FireGPG into Firefox. Go to this link and click the link to download it to your computer. From here it should coach you through the process.

Restart Firefox, and now you have new buttons in your compose view for encrypting and signing messages. Now you can discuss your nefarious plans in private!
<p>Sounds good, but I don't care if the government/hackers reads my emails. </p>
<p>If you're OK with other people reading your emails, you can basically replace &quot;reads my emails&quot; with &quot;empties my bank account&quot; or &quot;steals my identity&quot;.</p>
<p>You would if you were communicating with marketplace vendors.</p>
<p>If you're buying illegals on the darknet then yeah mabye, unless you have a prison wish.</p>
<p>For purchasing Illegals on the darknet, yeah.</p>
<p>all I want is my email</p>
<p>&quot;The two keys work together so that you need both to decrypt anything.&quot;<br>I believe this is wrong. You should only need the private key to decrypt, which is also what is shown in your diagram.<br>Unless you are referring to signing, which does have an decryption step using the public key at the receiver.</p>
whenever i try to upload an instructable it says &quot;verufy your email&quot;how in the world do i do that?
<p>what bin did you rescue that computer from?</p>
Hasn't been cracked? C'mon, a cipher cracking util run on the fastest desktop PC would take about 22,000 years to decipher. On the other hand, the NSA's "BrainChild" supercomputer can solve it in about 20 minutes. So, it really depends on who you are trying to hide information from...
Actually, agents from the Secret Service themselves are admitting that if something is encrypted with PGP, it's pretty much impossible even for them to crack (mentioned in <a rel="nofollow" href="http://www.cbsnews.com/stories/2008/02/07/tech/main3804858.shtml?source=RSSattr=HOME_3804858">this article</a>). The NSA may be able to crack it, but I've seen no published cases on this. It seems like if someone encrypts with PGP, anyone (including the government) wanting to decrypt the info tries to just find ways to swipe the key from somewhere, instead of a &quot;brute force&quot; method.<br/>
For all we know, they could already have cracked it a long time ago, and they already read everything encrypted or not. They just aren't telling us to give us a false sense of security.
<p>thanks to Snowden we know they haven't :) http://www.theverge.com/2014/12/28/7458159/encryption-standards-the-nsa-cant-crack-pgp-tor-otr-snowden</p>
The thing is, with enough time anything can be cracked but without knowing how long the original passphrase was it's pretty hard to do anything. My passphrase is in the neighborhood of 16+ characters which means they would have to make a list of all the possible strings that are 16 characters long, 17 characters long, etc until they cracked it. Without knowing that my passphrase is 16 characters at least though, you'd have to run through all the 1 character, 2 character, 3 character, 4 character, etc. passwords possible and finally be able to crack the passphrase. It'd take a wicked long time but eventually anything can be bruteforced. Just me $.02
If you were a suspect for a crime, they would probably just install malware on your computer, steal your password and not have to brute force anything. Or they can force you to reveal your passwords with torture or sever criminal penalties.
l2crypto https://class.coursera.org/crypto-preview/lecture/index <br> <br>Its all about reducing your odds. The best method for decrypting hashes is rainbow tables but that was solved by adding salt to the hash's. Private Public key crypto is much more complex by requiring multiple factors required to decrypt ans since gpg is an opensource crypto its been reviewed publically by many its very difficult to decrypt anything gpg related without two things your private key and your passphrase. You'd really have to try hard to replicate either of these things.
<p>In addition to keep the message private when it is transmitted between the sender and the receiver, does GPG keep the message encrypted in each party's mailbox? If not the case then how can I have my message stored in my Gmail mailbox in a way that even for Google couldn't read it?</p>
It is discontinued. http://getfiregpg.org/s/gmailstatut
But I thought that gmail automatically appends your IP address. Therefore, "big brother" can easily trace any encrypted message back to your computer and, with or without a search warrant, even via a "black bag job", find out what you typed even before it was encrypted. There is no easy, reliable method of ensuring that anything is confidential anymore.
If u use TOR to surf gmail, u essencially cant be traced<br>
psssst......voice down
FWIW, I use a combination of a Truecrypt (Windows/OSX/Linux) encrypted volume to store a Keepass (Windows) database to maintain my passwords. There are similar password managers to Keepass for OSX and Linux. This means I only ever have to know one (very strong) password, all my other passwords are generated using Keepass, and are typically 30 random characters (including non alpha-numeric characters) or whatever the maximum number and type allowed by the particular system. This means I don't know my own Gmail password, and because the password database is double encrypted (Truecrypt volume + Keepass db) with AES, I can safely keep it on my USB flash drive, and not be worried if I lose it. The other nice thing about Keepass is you can attach files, so I also have my PGP keys stored in there as well. Yes, it's putting all your eggs in one basket, but it's a redundant, strong and secure basket!
But aren't you hooped if you lose the usb key? You'd never be able to open your email again.
Ah...yes, you are correct, but there was one other tool I didn't mention as I didn't want to get too geeky :) I also use a version control system - Subversion - which I use to store (amongst other things) the Keepass database on. This means I can have a (working) copy of the encrypted keepass file in multiple areas, on my usb key, on my home pc, etc. and I use Subversion to keep these up to date. Subversion by default does not transfer or store securely, there are ways around this, but it's not necessary since my Keepass db is encrypted with AES.
hmm... an 'ible on secure subversion perhaps?<br>or just an explanation...
So, does this mean that your USB stick holds, in addition to your keepass db in a truecrypt volume, stand-alone &amp; multi-platform versions of both keepass and truecrypt?&nbsp; Otherwise, wouldn't you only be able to access your passwords (and gmail) if you're on a computer with all that already installed?<br /> <br /> And maybe you throw a couple firefox plugins on there while you're at it?<br />
I think it's discontinued.
Really glad for this helpful and useful guide. I'm using a PC and I'm sure many others are too. Can we get a guide for using GPG on our boxes? Thanx.
Here is a guide to use GPG on a PC!<br /> <br /> <a href="http://www.encrypt-the-planet.com/freeemailencryption.htm" rel="nofollow">http://www.encrypt-the-planet.com/freeemailencryption.htm</a>
Thanks for that link Lampoon. If I install Gpg4win as the website says, can I send it to someone on a Mac to decrypt it or would I need to install a different product or encryption engine? <br /> Also does this also encrypt images, attachments or do I need to do something separate for that? <br />
It isn't much different... Find the GPG software for your operating system;<br/>(see <a rel="nofollow" href="http://gnupg.org)">http://gnupg.org)</a><br/>install the software (instructions on the GnuPG site)<br/>install the Firefox plug-in<br/>create your key-pair<br/>send your public key to your friends and/or conspiratos<br/>keep your pass phrase Long and Private<br/><br/>that is about it. <br/><br/>When your friends send their keys open it with GPG or save it to a file and double-click to install<br/>
The easy way to Encrypt your gmail is this:<br/><br/>WHen you are on your gmail account, in the address bar, where it says http, type an S after http. now its encrypted.<br/><br/>so it would look like this<br/><br/><a rel="nofollow" href="https://mail.google.com">https://mail.google.com</a><br/>
Hey, yeah, chumby32 (below) has it right. There are two kinds of encryption at work here. Using httpS will encrypt the connection between your web browser and gmail's servers. This is good! It means nobody on the network can see what you are looking at or typing while you are logged in to gmail. This is especially good if you are checking your email from somewhere public like a cafe. However, once the email leaves your outbox it is still sent in the clear over the internet (through intermediate email servers, routers, etc.) until it reaches its destination. This means it is possibly stored on other servers too. All of the computers that handle the message en route see your email plain as day, and it could be read by anyone with access.<br /> <br /> PGP uses encryption slightly differently - it scrambles the actual contents of your message. This means that when you scramble a message all of the intermediate servers transmit the scrambled version as well. The only person (hopefully!) that can see the unscrambled message is the recipient at the end who decodes it using their key.<br /> <br /> Don't get me wrong - HTTPS is good and you should use it! But it only encrypts your current connection, not all of your emails.<br /> <br /> I believe there is a setting inside your gmail preferences to always turn on HTTPS.<br />

