PGP encryption for web browsers: BSI project improves open source software Mailvelope
Summary
In 2019 the German Federal Office for Information Security (BSI) presented the results of a funded project that improved the Mailvelope browser extension for PGP-encrypted email. New features included the ability for website operators to encrypt contact forms end to end, with keys retrieved via the Web Key Directory. An audit by SEC Consult found and closed four holes in Mailvelope and three in the OpenPGP.js library.
Ideas
- Browser extensions bring PGP to existing webmail services.
- Encrypted contact forms protect messages already in the sender’s browser.
- The Web Key Directory finds public keys automatically via HTTPS.
- Critical actions now explicitly require a user action.
Insights
- With encryption, usability decides actual use.
- Publicly funded audits strengthen open source tools that many people depend on.
- Cryptography in the browser trades a little security for considerably better usability.
Facts
- The project had been running since January 2018 and was carried out by Mailvelope GmbH and Intevation.
- The BSI named doctors and banks in particular as areas of use.
References
Critique
- The assessment of low adoption in medical practices is based on a few conversations by the editorial team.
Recommendations
- Publish your PGP key via Web Key Directory under your own domain.
- Use end-to-end encryption for forms with sensitive data such as health information.
Links to the original source and the Web Archive open in a new tab.