This is a deeply ironic reply - is it intended to be? There's almost no words there that would gel into comprehension in any way for average Joe and Jill.
I don't want this to come across the wrong way - but are you a Linux engineer/admin? I think when someone has deeply understood deeply technical things for a very long time, they lose touch with just how arcane their knowledge is and how much of a real expert they are - skyscrapers above the ordinary level of knowledge. This state leads them to think that what is obvious to them can't be hard for others to understand.
You must have a very low opinion of average Joe/Jill, to not expect them to understand "When you send an email there is no proof that it came from you."
I really don't see what's so hard about the first paragraph, which is the only one intended to be understood by a layperson. Even though the concept of "signing" has a long-established and well-known non-digital meaning, which nearly everyone will understand, the paragraph still goes out of its way to define it. Seems pretty idiot proof to me.
It's actually much worse than you expect. Most email clients don't show the email address of the sender; they show the display name. If you get an email from "The President <l33thacker101@evil.h4x0rz.club>", most users will see that the email comes "The President." And l33thacker101@evil.h4x0rz.club could get a valid signature for her domain, because she obviously controls it, and people would see that the email from "The President" really did come from "The President."
There are many problems with email. The ability for l33thacker101@evil.h4x0rz.club to claim to be innocent.grandma@grandmas.knitting.club is not at the top of the list.
Why do so many email clients do this? In my opinion, it only makes things more confusing. It's especially irritating when a contact has multiple email addresses (work/personal) and it's not obvious which is which.
And you must not work in tech support. But all this is irrelevant for the most part because aside from understanding WHY it's useful and important, there's the fact that most people are using web clients, and trying to, say, sign or verify a message in GMail is pretty much an unclimbable mountain for the vast majority of people.
Heck, even on desktop clients it's a pain in the ass. Ever tried to create, install, and use an S/MIME certificate in a major desktop client, like Outlook or Apple Mail? It's ridiculous. An obscure mix of trying to use the right browser, export the certificate in the right format, sometimes even convert it on the command line, use the right mail client extension, etc.
So it's the tools that are the main problem.
Until S/MIME or similar is built into major webmail clients, and certificate creation and installation is simple on the desktop, it's never going to happen.
"What do you mean there's no proof it came from me, it says <name>@gmail.com right there in the sender address! What do you mean the sender address can be spoofed? Headers? What's that."
...and then you tell them that it's exactly like someone writing a fake return address on a piece of mail before sending it to you, and they understand, because as stated above, this is conceptually very simple. You don't need to talk about "headers" at all - I don't know why you're bringing them up.
Exactly. And now imagine you manage in some way to explain average user that he cannot trust email sender. Then explain him that if email is signed then it is OK. He will most probably answer "why the hell now should I trust email sender !? There is just a dumb icon saying the email is signed. I do not trust it !!!". Which would just be the most sane reaction actually
It's not a case of not understanding, it's a case of not believing. If you're talking to a lay person that trusts you, they may raise such an objection, but they'll believe you once you reply "that can be, and often is, faked".
Belief is a thorny issue when trying to communicate to the masses, though.
I don't know if you're replying to the wrong person, but I'm not arguing we shouldn't use anything. I'm answering 'will they understand' and my opinion is 'no'.
haha, I don't think you understand. If I told my dad "There is no proof that an email that came from me, came from me." He's going to say... "but it came from <myname>@gmail.com"
That's what you don't seem to comprehend. Yes, for you this seems obvious. But really, to the average Joe/Jill, this idea that you could get an email from the address you expect but it has been spoofed is gibberish.
And you really think you couldn't explain that to him? There's a large difference between what people intuitively expect and what they can understand if told about it. Envelope analogies can go surprisingly far. (Assuming they believe you. If they think you can't be trusted about such things, then that's a problem of course)
This is hilarious. Do you have parents and/or grandparents?
Have you not had to repeatedly explain the simplest things over and over again? User names and passwords are hard enough, and you're expecting most people to understand email signing?
> There's almost no words there that would gel into comprehension in any way for average Joe and Jill.
Hardly. The first paragraph is easy to understand -- you tell them that "there's no proof it came from you" and that "its easy to fake emails" and that signing the emails digitally helps prevent that. Everyone can understand "there's no proof it comes from you" and "fake emails" follows on from that. Everyone knows what a physical signature is and how it helps identify that something was written by you and can imagine the concept of a digital one, even if they have no idea about the mechanics of one.
That goes a long way to describe at least why you would want to digitally sign emails, even if it doesn't tell you anything about how it works.
Interesting subject. I am now considering whether to do a video set "JT learns X", where a qualified developer (me) takes a subject I know nothing about, and video my learning, and see all the "well, this makes no sense" -> "how could I even have misunderstood that, it's so simple" moments.
Would that be of interest to anyone other than myself?
Putting a stress on the "qualified developer" part would critical. We are so used to not understanding things (new frameworks every week, new code base to grok, stuff we wrote 3 weeks ago that is just spaghetti), that I think it won't be representative of how most people would enter a subject.
I saw this when looking at other people learning languages, where some of them had a "I don't understand anything" reaction and just stop there, because it's just not a normal situation to them ('growing up' was part of securing that comfort zone for a lot of people)
From a UX perspective, it is exactly the same as a verified user on Twitter or whatever. Some people get a blue tick by their name in their emails.
Also if someone who normally sends you a signed message sends you an unsigned one, a security warning is displayed and / or the message is automatically directed straight to the spam folder.
No. Do it OpenSSH style. At first every identity is unknown. Then you get a mail signed by a key tied to an identity (on whatever keybase), then as you email each other your trust grows.
Sure, maybe you're trusting a scammer more and more, but at least when you get a new email from a scammer that's trusted by millions (let's say by more than one EV cert signed the key that signed the email), then it's pretty sure you're just being scammed by Apple to further their regular bottom line.
I think that depends on how you explain it. It's hard for people to understand problems in environments they're unused to.
For example, ask someone the following question. You have cards with letters on one side and numbers on the other. Cards with vowels must have odd numbers on the reverse. If you have cards [A B C 1 2 3], which cards do you need to turn over to check that the rule is followed?
It's easier for people to understand when you rephrase the question as: we're serving sodas and beers to restaurant patrons of various ages. If I have [Beer Soda Water age40 age10 age30], which patrons/drinks do I need to check? People will have a much easier time answering [Beer age10] than [A 2].
I would try explaining it to people with a real world analogy: did the mail-bombs [0] to Soros, Obama, Clinton, and CNN come from Debbie Wasserman Schultz? People can write anything in the return address and mail a package from a public mailbox. Email acts the same way by default. Do you think non-IT people will have trouble understanding that analogy? (or that the analogy doesn't represent the situation correctly?)
The first paragraph clearly glosses over a lot of details, and a bit more explanation would be required for practical use, but "almost no words there that would gel into comprehension", really?
You don't need people to understand why digital signatures work to explain to them what they do.
Joe and Jill are fairly efficient in keeping their scopes narrow on usability.
So, if signing were properly featured, then the failing emails would get burried in Spam folder, even more, the email client could block the 'Click here so I could screw you' links in such emails, and more choices how to integrate it in common user's flow.
However, the other question is rather if the email signing would still serve the purpose in case when the system/server gets compromized, keys stolen. Did any major company paid off fully what's due for losing away scores of users' private details?
The errosion of trust may be more detrimental to Joes and Jills outhere.
These are the people who get stuck on a piece of software because a modal dialog is displayed, but they don't acknowledge it and keep trying to click on the controls in the background.
The absolutely terrible concept of a modal dialog is a different topic, but it is quite common nonetheless.
I don't want this to come across the wrong way - but are you a Linux engineer/admin? I think when someone has deeply understood deeply technical things for a very long time, they lose touch with just how arcane their knowledge is and how much of a real expert they are - skyscrapers above the ordinary level of knowledge. This state leads them to think that what is obvious to them can't be hard for others to understand.