Menu
Open-source project promises easy-to-use encryption for email, instant messaging and more

Open-source project promises easy-to-use encryption for email, instant messaging and more

Pretty Easy Privacy system aims to make encryption of written online communication accessible to masses

A software development project launched Monday aims to create free tools that simplify the encryption of online forms of communication like email, instant messaging, SMS and more by solving the complexity associated with the exchange and management of encryption keys.

Called "Pretty Easy Privacy" (PEP), the project's goal is to integrate the technology with existing communication tools on different desktop and mobile platforms. The development team launched a preview PEP implementation Monday for the Microsoft Outlook email client, but plans to build similar products to encrypt communications in Android, iOS, Firefox OS, Thunderbird, Apple Mail, Jabber, IRC (Internet Relay Chat), WhatsApp, Facebook Messenger, Snapchat and Twitter.

The PEP developers launched a crowdfunding campaign on Indiegogo to raise funds that would allow them to set up a foundation to support the project and speed up the development of the various implementations for different platforms.

While most PEP software will be released under the GNU General Public License version 3 and will be free to use, the team will also develop business products that will be commercialized through a new Luxembourg-based company called PEP Security.

The PEP engine relies on existing open-source technologies like GnuPG, an implementation of the OpenPGP encryption standard; GNUnet, a framework for decentralized, peer-to-peer networking; and NetPGP, an OpenPGP implementation for platforms like iOS, where GnuPG is not supported. However, its primary goal is to provide "no hassle" privacy through a "zero-touch" user experience, according to its developers.

On installation PEP automatically generates encryption keys for the user or imports them from a local PGP client. It is also able to discover the keys for the user's communication partners if they uploaded them on public keyservers or already sent signed emails in the past. This means PEP will start encrypting communications straight away with some users and works even if the other side doesn't use PEP, but other PGP, S/MIME or CMS implementations.

"The PEP engine is doing exactly what a hacker does when he or she is using PGP: create a good keypair with reliable algorithms, handle it safely, manage public keys of other people, and operate the crypto solution in the best known way to keep it safe," said Volker Birk, a German software architect and one of the project's founders, in a blog post.

The PEP plug-in for Outlook uses color-coded trust indicators for email contacts. The default one is grey and signifies that encrypted communication is not yet possible with the selected contact. When the recipient's keys are known and already in the keystore, the trust indicator switches to yellow, which means encrypted communication is possible, but potentially vulnerable to man-in-the-middle attacks.

In order to achieve the highest level of protection, signaled by a green indicator, the two parties need to exchange PEP-generated "safe words" over the phone. Once this handshake is confirmed, the communication is protected against all known attacks, the PEP developers said on the project's Indiegogo page.

The technology does not rely on centralized infrastructure and uses peer-to-peer technology for anonymous transport. When both parties use it, it's not just the content of messages that get encrypted, but metadata like the subject line in the case of emails.

The current goal of the crowdfunding campaign is to raise $50,000, which will help with the development of the PEP implementation for Android. However, more funds will be needed to speed up support for different platforms, communication tools and encryption protocols.


Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags PEP Securityonline safetysecurityencryptionindiegogoprivacy

Featured

Slideshows

Sizing up the NZ security spectrum - Where's the channel sweet spot?

Sizing up the NZ security spectrum - Where's the channel sweet spot?

From new extortion schemes, outside threats and rising cyber attacks, the art of securing the enterprise has seldom been so complex or challenging. With distance no longer a viable defence, Kiwi businesses are fighting to stay ahead of the security curve. In total, 28 per cent of local businesses faced a cyber attack last year, with the number in New Zealand set to rise in 2017. Yet amidst the sensationalism, media headlines and ongoing high profile breaches, confusion floods the channel, as partners seek strategic methods to combat rising sophistication from attackers. In sizing up the security spectrum, this Reseller News roundtable - in association with F5 Networks, Kaspersky Lab, Tech Data, Sophos and SonicWall - assessed where the channel sweet spot is within the New Zealand channel. Photos by Maria Stefina.

Sizing up the NZ security spectrum - Where's the channel sweet spot?
Kiwi channel comes together for another round of After Hours

Kiwi channel comes together for another round of After Hours

The channel came together for another round of After Hours, with a bumper crowd of distributors, vendors and partners descending on The Jefferson in Auckland. Photos by Maria Stefina.​

Kiwi channel comes together for another round of After Hours
Consegna comes to town with AWS cloud offerings launch in Auckland

Consegna comes to town with AWS cloud offerings launch in Auckland

Emerging start-up Consegna has officially launched its cloud offerings in the New Zealand market, through a kick-off event held at Seafarers Building in Auckland.​ Founded in June 2016, the Auckland-based business is backed by AWS and supported by a global team of cloud specialists, leveraging global managed services partnerships with Rackspace locally.

Consegna comes to town with AWS cloud offerings launch in Auckland
Show Comments