Open-source project promises easy-to-use encryption for email, instant messaging and more

Pretty Easy Privacy system aims to make encryption of written online communication accessible to masses

A software development project launched Monday aims to create free tools that simplify the encryption of online forms of communication like email, instant messaging, SMS and more by solving the complexity associated with the exchange and management of encryption keys.

Called "Pretty Easy Privacy" (PEP), the project's goal is to integrate the technology with existing communication tools on different desktop and mobile platforms. The development team launched a preview PEP implementation Monday for the Microsoft Outlook email client, but plans to build similar products to encrypt communications in Android, iOS, Firefox OS, Thunderbird, Apple Mail, Jabber, IRC (Internet Relay Chat), WhatsApp, Facebook Messenger, Snapchat and Twitter.

The PEP developers launched a crowdfunding campaign on Indiegogo to raise funds that would allow them to set up a foundation to support the project and speed up the development of the various implementations for different platforms.

While most PEP software will be released under the GNU General Public License version 3 and will be free to use, the team will also develop business products that will be commercialized through a new Luxembourg-based company called PEP Security.

The PEP engine relies on existing open-source technologies like GnuPG, an implementation of the OpenPGP encryption standard; GNUnet, a framework for decentralized, peer-to-peer networking; and NetPGP, an OpenPGP implementation for platforms like iOS, where GnuPG is not supported. However, its primary goal is to provide "no hassle" privacy through a "zero-touch" user experience, according to its developers.

On installation PEP automatically generates encryption keys for the user or imports them from a local PGP client. It is also able to discover the keys for the user's communication partners if they uploaded them on public keyservers or already sent signed emails in the past. This means PEP will start encrypting communications straight away with some users and works even if the other side doesn't use PEP, but other PGP, S/MIME or CMS implementations.

"The PEP engine is doing exactly what a hacker does when he or she is using PGP: create a good keypair with reliable algorithms, handle it safely, manage public keys of other people, and operate the crypto solution in the best known way to keep it safe," said Volker Birk, a German software architect and one of the project's founders, in a blog post.

The PEP plug-in for Outlook uses color-coded trust indicators for email contacts. The default one is grey and signifies that encrypted communication is not yet possible with the selected contact. When the recipient's keys are known and already in the keystore, the trust indicator switches to yellow, which means encrypted communication is possible, but potentially vulnerable to man-in-the-middle attacks.

In order to achieve the highest level of protection, signaled by a green indicator, the two parties need to exchange PEP-generated "safe words" over the phone. Once this handshake is confirmed, the communication is protected against all known attacks, the PEP developers said on the project's Indiegogo page.

The technology does not rely on centralized infrastructure and uses peer-to-peer technology for anonymous transport. When both parties use it, it's not just the content of messages that get encrypted, but metadata like the subject line in the case of emails.

The current goal of the crowdfunding campaign is to raise $50,000, which will help with the development of the PEP implementation for Android. However, more funds will be needed to speed up support for different platforms, communication tools and encryption protocols.

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags PEP Securityonline safetysecurityencryptionindiegogoprivacy

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Cool Tech

Crucial Ballistix Elite 32GB Kit (4 x 8GB) DDR4-3000 UDIMM

Learn more >

Gadgets & Things

Lexar® Professional 1000x microSDHC™/microSDXC™ UHS-II cards

Learn more >

Family Friendly

Lexar® JumpDrive® S57 USB 3.0 flash drive 

Learn more >

Stocking Stuffer

Plox Star Wars Death Star Levitating Bluetooth Speaker

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

GGG Evaluation Team

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Steph Mundell

LIFEBOOK UH574

The Fujitsu LifeBook UH574 allowed for great mobility without being obnoxiously heavy or clunky. Its twelve hours of battery life did not disappoint.

Andrew Mitsi

STYLISTIC Q702

The screen was particularly good. It is bright and visible from most angles, however heat is an issue, particularly around the Windows button on the front, and on the back where the battery housing is located.

Simon Harriott

STYLISTIC Q702

My first impression after unboxing the Q702 is that it is a nice looking unit. Styling is somewhat minimalist but very effective. The tablet part, once detached, has a nice weight, and no buttons or switches are located in awkward or intrusive positions.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?