BrainDump
  Home arrow BrainDump arrow Page 3 - PGP and GPG: Email for the Practical Paranoid
Dev Shed Forums  
Administration  
AJAX  
Apache  
BrainDump  
DHTML  
Flash  
Java  
JavaScript  
Multimedia  
MySQL  
Oracle  
Perl  
PHP  
Practices  
Python  
Reviews  
Security  
Smartphone Development  
Style-Sheets  
Web Services  
XML  
Zend  
Zope  
Mobile Linux  
App Generation ROI  
IBM® developerWorks  
Forums Sitemap  
E-Commerce Hosting  
Linux Web Hosting  
Managed Hosting  
Small Business Hosting  
VPS Hosting  
Weekly Newsletter

 
Developer Updates  
Free Website Content 
 RSS  Articles
 RSS  Forums
 RSS  All Feeds
Write For Us Get Paid  
Request Media Kit
Contact Us  
Site Map  
Privacy Policy  
Support  
 USERNAME
 
 PASSWORD
 
 
  >>> SIGN UP!  
  Lost Password? 
BRAINDUMP

PGP and GPG: Email for the Practical Paranoid
By: Quantum Skyline
  • Search For More Articles!
  • Disclaimer
  • Author Terms
  • Rating: starstarstarstarstar / 3
    2007-05-30


    Table of Contents:
  • PGP and GPG: Email for the Practical Paranoid
  • A Textbook on Email
  • Details of Instruction
  • Conclusion

  • Rate this Article: Poor Best 
      ADD THIS ARTICLE TO:
      error-file:tidyout.log Del.ici.ous error-file:tidyout.log Digg
      error-file:tidyout.log Blink error-file:tidyout.log Simpy
      error-file:tidyout.log Google error-file:tidyout.log Spurl
      error-file:tidyout.log Y! MyWeb error-file:tidyout.log Furl
    Email Me Similar Content When Posted
    Add Developer Shed Article Feed To Your Site
    Email Article To Friend
    Print Version Of Article
    PDF Version Of Article

     
     
    ADVERTISEMENT


    PGP and GPG: Email for the Practical Paranoid - Details of Instruction
    ( Page 3 of 4 )

     

    When describing how to use PGP or GPG, Lucas tries hard to ensure that the reader is comfortable working with the tools.  PGP & GPG is laced with screen shots of how to use any of the programs, or, in the case of GPG from the command line, textual descriptions of commands and their output.  It is also encouraging to see that Lucas provided instructions on how to use GPG on Linux.  There is a large amount of text spent on step-by-step instructions on everything from installation to digitally signing email and managing identities.  The instructions are complete, and are written in such a manner that a regular user with limited command line experience could actually perform the tasks described.  Lucas' writing style is quite inviting, and he tends to insert some humor in areas of the book that would be quite dry otherwise.  When explaining the output from command line GPG, Lucas highlights parts of the output and illustrates what they mean.  This goes a long way towards making the use of the command line less intimidating for the reader, and complements the appendices.

    However, while Lucas provides a large number of screen shots, PGP & GPG  is almost completely devoid of pictures or diagrams.  For example, it would be nice to have some diagrams in the chapters regarding the encoding, encryption, and signing of email so that the reader has a visual representation of how s/he is changing his or her email when using OpenPGP.  PGP & GPG is the first book from No Starch Press that I have read and as a result, I'm not sure if it is representative of a particular style that No Starch Press is trying to use in its books or if this is indicative of Lucas' style of writing.  He does make use of inset text and footnotes to give the reader some details that may be tangential or extra background information.

    Lucas highly stresses certain things during the course of PGP & GPG.  When he finds a topic that he wants to drive home, he repeats it throughout the course of the book so that the reader is left with the impression that a particular issue is important and always needs to be thought of when working with OpenPGP.  For example, Lucas emphasizes the use of key expiration dates, and absolutely insists on keeping backups of private keys and revocation certificates.  To further illustrate his points, he repeats his explanation as to why he believes these topics to be important by showing the potential consequences and their significance.  In a book like this, these explanations are as important as the concepts themselves, because they allow the reader to understand why Lucas is taking a hard stance on a particular topic.

    Chapter 11, "Other OpenPGP Considerations", is the chapter mentioned earlier that talks about caveats when using OpenPGP.  This chapter is a must read, and dispels the majority of my worries that a reader might take the usage of OpenPGP as a panacea when it comes to email security.  In this chapter, Lucas states that while OpenPGP is good, simple misuse can have a large effect on its effectiveness.  Also, Lucas introduces "rubber hose cryptography" and shows that humans are the weakest link in systems like this.  He also provides suggestions on how to manage keys when working in teams and when using shared systems in plain and simple terms.



     
     
    >>> More BrainDump Articles          >>> More By Quantum Skyline
     

       

    BRAINDUMP ARTICLES

    - Demystifying SELinux on Kernel 2.6
    - Yahoo and Microsoft Create Ad Partnership
    - The Advantages of Obscure Open Source Browse...
    - Dell Announces CSI-style Digital Forensics S...
    - Milepost GCC Speeds Open-Source Development
    - Learn These 10 Programming Languages
    - Tomcat Capacity Planning
    - Internal and External Performance Tuning wit...
    - Tomcat Benchmark Procedure
    - Benchmarking Tomcat Performance
    - Tomcat Performance Tuning
    - Wubi: Windows-based Ubuntu Installer
    - Configuring and Optimizing Your I/O Scheduler
    - Linux I/O Schedulers
    - Advising the Linux Kernel on File I/O





    © 2003-2009 by Developer Shed. All rights reserved. DS Cluster 1 Hosted by Hostway
    Stay green...Green IT