I'm with you. I've had mutt set up to use PGP for ages. I've configured a half-dozen or more other MUAs to use PGP/GPG. If I've got an MUA that doesn't support PGP, I can do ASCII armor encryption and decryption easily.
That's you and me, the geek set.
The Google guy I mentioned: he's just as versed. And yet, felt he should give me grief.
If you've got a Linux desktop, odds are that the tools you need are integrated. Congratulations, that's ... about 0.5-3% of all desktops depending on whose numbers you trust and/or like.
And an increasing number of users are now on smartphones and tablets. Yes, I've got K9Mail, but I've received no, and sent very few, encrypted emails.
In corporate environments, you get the tools you've got on a standard desktop and that's it. I've had a hell of a time convincing engineering and dev teams to create and use PGP/GPG keys and/or use SSH key authentication rather than passwords. I've been at shops recently which still use rsh (and had the pleasure of giving the solution to a user creating large numbers of client sessions: oh, yeah, SSH doesn't have the 512 max outbound connections limit that RSH does due to its privileged port use). Sigh.
Key distribution is a huge part of the problem. In large part it's what PGP Corp (now part of Symantec) addressed with its appliance solutions: a box that creates, signs, manages, and automatically applies keys for users. I don't exist, and yet I've got a key published (and embedded in my G+ profile coverphoto). Oh, what the heck, let's add it to my HN profile.
As you note: webmail, mobile, smartphone, and Windows are all problematic. But more than that: people don't fundamentally understand the technology they use (part of a much larger rant and topic), and this stuff confuses them utterly.
I'm with you. I've had mutt set up to use PGP for ages. I've configured a half-dozen or more other MUAs to use PGP/GPG. If I've got an MUA that doesn't support PGP, I can do ASCII armor encryption and decryption easily.
That's you and me, the geek set.
The Google guy I mentioned: he's just as versed. And yet, felt he should give me grief.
If you've got a Linux desktop, odds are that the tools you need are integrated. Congratulations, that's ... about 0.5-3% of all desktops depending on whose numbers you trust and/or like.
And an increasing number of users are now on smartphones and tablets. Yes, I've got K9Mail, but I've received no, and sent very few, encrypted emails.
In corporate environments, you get the tools you've got on a standard desktop and that's it. I've had a hell of a time convincing engineering and dev teams to create and use PGP/GPG keys and/or use SSH key authentication rather than passwords. I've been at shops recently which still use rsh (and had the pleasure of giving the solution to a user creating large numbers of client sessions: oh, yeah, SSH doesn't have the 512 max outbound connections limit that RSH does due to its privileged port use). Sigh.
Key distribution is a huge part of the problem. In large part it's what PGP Corp (now part of Symantec) addressed with its appliance solutions: a box that creates, signs, manages, and automatically applies keys for users. I don't exist, and yet I've got a key published (and embedded in my G+ profile coverphoto). Oh, what the heck, let's add it to my HN profile.
As you note: webmail, mobile, smartphone, and Windows are all problematic. But more than that: people don't fundamentally understand the technology they use (part of a much larger rant and topic), and this stuff confuses them utterly.