About usability of security software
About usability of security software
Posted Sep 8, 2020 8:47 UTC (Tue) by ber (subscriber, #2142)In reply to: GnuPG 2.2.23 released, fixing a critical security flaw by cyperpunks
Parent article: GnuPG 2.2.23 released, fixing a critical security flaw
As for the usability: if approaches like the web key directory (https://wiki.gnupg.org/WKD) are used, it is possible to have a much improved user experience which retains many security properties while acting automatic in most situations. Of course more clients, like email clients, need to support it, just like email providers. At the rate of the adoption, you can see the market pressure (low, many people are unwilling to pay more for security in this area).
But there is also a general catch with security (not just in IT): In case of attacks there must be a possibility for humans to defend their assets and to take decisions depending on their security needs. There is no way around this aspect involving thinking and some training. All software products can only support it so much by being informative as good as they can.
Regards,
Bernhard
(Who is part of the GnuPG/Gpg4win team and has been involved designing WKD a few years ago.)
